SSSD 2.4.0 Release Notes

  • libnss support was dropped, SSSD now supports only openssl cryptography

  • Session recording can now exclude specific users or groups when scope is set to all (see exclude_users and exclude_groups options)

  • Active Directory provider now sends CLDAP pings over UDP protocol to Domain Controllers in parallel to determine site and forest to speed up server discovery

  • python2 bindings are disable by default, use --with-python2-bindings to build it

  • Default value of client_idle_timeout changed from 60 to 300 seconds for KCM, this allows more time for user interaction (e.g. during kinit)

  • Added exclude_users and exclude_groups option to session_recording section, this allows to exclude user or groups from session recording when scope is set to all

  • Added ldap_library_debug_level option to enable debug messages from libldap

  • Added dyndns_auth_ptr to set authentication mechanism for PTR DNS records update

  • Added ad_allow_remote_domain_local_groups to be compatible with other solutions

  • #1030 - Excessive dependencies on libsss_certmap

  • #1041 - Deprecate and eventually get rid of support of NSS as a crypto backend

  • #3743 - RFE: Improve AD site discovery process

  • #3987 - “domains” description in pam_sss(8) is misleading

  • #4569 - IFP: org.freedesktop.sssd.infopipe.GetUserGroups does not take SYSDB_PRIMARY_GROUP_GIDNUM into account

  • #4733 - Access after free during kcm shutdown with a non-empty queue

  • #4743 - [RFE] Add “enabled” option to domain section

  • #4829 - KCM: Increase the default client idle timeout, consider decreasing the timeout on busy servers

  • #4840 - gpo: use correct base dn

  • #5002 - p11_child::do_ocsp() function implementation is not FIPS140 compliant

  • #5061 - [RFE] Add a new mode for ad_gpo_implicit_deny

  • #5089 - Enable exclusions in the sssd-session-recording configuration

  • #5097 - please migrate to the new Fedora translation platform

  • #5215 - SSSD uses only TCP/IP stream to send CLDAP request

  • #5256 - getent networks ip is not working

  • #5259 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf

  • #5261 - Secondary LDAP group go missing from ‘id’ command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1

  • #5274 - dyndns: asym auth for nsupdate

  • #5278 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema

  • #5290 - krb5_child denies ssh users when pki device detected

  • #5295 - Crash in ad_get_account_domain_search()

  • #5314 - Attribute ‘ldap_sasl_realm’ is not allowed in section ‘domain/’. Check for typos.

  • #5325 - correction in sssd.conf man page

  • #5330 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase)

  • #5333 - sssd-kcm does not store TGT with ssh login using GSSAPI

  • #5338 - [RFE] sssd-ldap man page modification for parameter “ldap_referrals”

  • #5346 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains

