shield
Recommended update for adcli
SUSE-SLE-Module-Basesystem-15-SP7-2026-3191
This update for adcli fixes the following issues: Update to 0.9.3.1; (jsc#PED-13768); * enroll: check if AD accepts new password * enroll: allow to add SPNs to manages service accounts * enroll: add new SPNs from AD to keytab during update * conn: use 10s timeout for connect() * enroll: restore SELinux file context of keytab files * enroll: remove USE_DES_KEY_ONLY during join * entry: check user and group names for illegal characters * tools: add --recursive option to delete-computer * tools: testjoin, use realm from keytab as domain name * enroll: use realm form the HOST$ entry in the keytab * Tests: initial framework and tests for adcli based on sssd-test-framework * krb5: add adcli_krb5_get_error_message() * Various fixes for issues found by static code scanners * enroll: Populate Samba's secrets database using offline domain join Update to 0.9.2: * adenroll: set password via LDAP instead Kerberos * disco: fall back to LDAPS if CLDAP ping was not successful * tools: replace getpass() * adenroll: write SID before secret to Samba's db * doc: add clarification to add-member command on doc/adcli.xml * tools: Set umask before calling mkdtemp() * Avoid undefined behaviour in short option parsing * library: include endian.h for le32toh * man: Fix typos and use consistent upper case for some keywords * configure: check for ns_get16 and ns_get32 as well * Add setattr and delattr options * entry: add passwd-user sub-command * Add dont-expire-password option Update to 0.9.1: * tools: add show-computer command * add description option to join and update * Use GSS-SPNEGO if available * add option use-ldaps * tools: disable SSSD's locator plugin * doc: explain required AD permissions * computer: add create-msa sub-command * Add account-disable option * fix coredump in discovery (boo#1183870) Update to 0.9.0: * doc: add missing samba_data_tool_path.xml(.in) to EXTRA_DIST * doc: explain how to force password reset * Do not use arcfour-hmac-md5 when discovering the salt * Fix for issue found by Coverity * adenroll: use only enctypes permitted by Kerberos config * adenroll: add adcli_enroll_get_permitted_keytab_enctypes with tests * adconn: add adcli_conn_set_krb5_context * adenroll: make sure only allowed enctypes are used in FIPS mode * tools: computer - remove errx from parse_option
-
Release DateJul 22 2026
-
References
-
Typerecommended
-
Severitymoderate
cloud_download Downloads
Basesystem Module 15.7 aarch64
-
Packages
Basesystem Module 15.7 ppc64le
-
Packages
Basesystem Module 15.7 s390x
-
Packages
Basesystem Module 15.7 x86_64
-
Packages