SSSD 2.8.2 Release Notes

  • SSSD can be configured not to perform a DNS search during DNS name resolution. This behavior is governed by the new dns_resolver_use_search_list. This parameter can be used in the domain section. Default value is true - that means that SSSD follows the system settings.

  • --enable-files-domain configure option is deprecated and will be removed in one of the next versions of SSSD.

  • sssctl analyze tool doesn’t require anymore to be run under root.

  • New mapping template for serial number, subject key id, SID, certificate hashes and DN components are added to libsss_certmap.

  • #5390 - sssd failing to register dynamic DNS addresses against an AD server due to unnecessary DNS search

  • #6383 - sssd is not waiting for

  • #6403 - Add new Active Directory related certificate mapping templates

  • #6404 - [RFE] Add digest mapping feature from pam_pkcs11 in SSSD

  • #6451 - UPN check cannot be disabled explicitly but requires krb5_validate = false’ as a work-around

  • #6479 - Smart Card auth does not work with p11_uri (with-smartcard-required)

