Oval Definition:oval:com.redhat.rhsa:def:20210860
Revision Date:2021-03-16Version:636
Title:RHSA-2021:0860: ipa security and bug fix update (Moderate)
Description:Red Hat Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments.

Security Fix(es):

  • jquery: Passing HTML containing
  • cannot issue certs with multiple IP addresses corresponding to different hosts (BZ#1846349)

  • CA-less install does not set required permissions on KDC certificate (BZ#1863619)

  • IdM Web UI shows users as disabled (BZ#1884819)

  • Authentication and login times are over several seconds due to unindexed ipaExternalMember (BZ#1892793)

  • improve IPA PKI susbsystem detection by other means than a directory presence, use pki-server subsystem-find (BZ#1895197)

  • IPA WebUI inaccessible after upgrading to RHEL 8.3 - idoverride-memberof.js missing (BZ#1897253)
  • Family:unixClass:patch
    Status:Reference(s):CVE-2020-11023
    RHSA-2021:0860
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • ipa-client is earlier than 0:4.6.8-5.el7_9.4
  • AND ipa-client is signed with Red Hat redhatrelease2 key
  • ipa-client-common is earlier than 0:4.6.8-5.el7_9.4
  • AND ipa-client-common is signed with Red Hat redhatrelease2 key
  • ipa-common is earlier than 0:4.6.8-5.el7_9.4
  • AND ipa-common is signed with Red Hat redhatrelease2 key
  • ipa-python-compat is earlier than 0:4.6.8-5.el7_9.4
  • AND ipa-python-compat is signed with Red Hat redhatrelease2 key
  • ipa-server is earlier than 0:4.6.8-5.el7_9.4
  • AND ipa-server is signed with Red Hat redhatrelease2 key
  • ipa-server-common is earlier than 0:4.6.8-5.el7_9.4
  • AND ipa-server-common is signed with Red Hat redhatrelease2 key
  • ipa-server-dns is earlier than 0:4.6.8-5.el7_9.4
  • AND ipa-server-dns is signed with Red Hat redhatrelease2 key
  • ipa-server-trust-ad is earlier than 0:4.6.8-5.el7_9.4
  • AND ipa-server-trust-ad is signed with Red Hat redhatrelease2 key
  • python2-ipaclient is earlier than 0:4.6.8-5.el7_9.4
  • AND python2-ipaclient is signed with Red Hat redhatrelease2 key
  • python2-ipalib is earlier than 0:4.6.8-5.el7_9.4
  • AND python2-ipalib is signed with Red Hat redhatrelease2 key
  • python2-ipaserver is earlier than 0:4.6.8-5.el7_9.4
  • AND python2-ipaserver is signed with Red Hat redhatrelease2 key
  • BACK