FreeIPA 4.10.2#

The FreeIPA team would like to announce FreeIPA 4.10.2 release!

Highlights in 4.10.2#

  • 5444: [RFE] Support Resource based kerberos constrained delegation

  • 9287: [RFE] makeapi should validate the generated API doc vs stored doc

  • 9294: Enable the certificate pruning job in PKI

    Removing (pruning) expired certificates is supported when Random Serial Numbers are enabled. One cannot upgrade from sequential serial numbers to random. This feature is enabled using the ipa-acme-manage(1) command.

  • 9331: Better handling of the command line and web UI cert search and/or list features

    cert-find performance was improved dramatically when a large number of certificates are returned by changing the method IPA uses internally to parse results from the CA.

  • 9354: Implement resource-based constrained delegation

    FreeIPA provides initial implementation of resource-based constrained delegation (RBCD) for Kerberos services. RBCD and other Kerberos delegation services described in the design document: The initial implementation works for FreeIPA services, work on supporting cross-realm RBCD continues.

  • 9373: Make sign_authdata() generate extended KDC signature

    FreeIPA KDCs will automatically start requiring two new Kebreros ticket signatures when the whole realm is running on MIT Kerberos 1.21 or later. On older MIT Kerberos versions, the lack of the new ticket signature will be tolerated to allow gradual upgrades. More details are available at In addition, a ‘full PAC’ signature type was added to MIT Kerberos 1.21. FreeIPA will support the new signature when running against newer MIT Kerberos version. For older versions, please see This new PAC signature will be required by default by Active Directory in July 2023 for S4U requests, and opt-out will no longer be possible after October 2023. We recommend upgrading to newer versions of FreeIPA-based distributions to avoid interoperability break.

Known Issues#

  • 9298: [Tracker] Nightly test failure (updates-testing) in

    With Certbot update to 2.0.0, Certbot defaults to ECDSA certificate private keys for all new certificates. PKI ACME cert profile supports only rsa private keys, meaning that the key type needs to be forced to rsa when requesting an ACME certificate, using certbot –key-type rsa […]

Bug fixes#

FreeIPA 4.10.2 is a stabilization release for the features delivered as a part of 4.10 version series.

There are more than 60 bug-fixes since FreeIPA 4.10.1 release. Details of the bug-fixes can be seen in the list of resolved tickets below.


Resolved tickets#

Detailed changelog since 4.10.1#

