shield Recommended update for adcli
SUSE-SLE-Module-Basesystem-15-SP7-2026-3191


This update for adcli fixes the following issues: Update to 0.9.3.1; (jsc#PED-13768); * enroll: check if AD accepts new password * enroll: allow to add SPNs to manages service accounts * enroll: add new SPNs from AD to keytab during update * conn: use 10s timeout for connect() * enroll: restore SELinux file context of keytab files * enroll: remove USE_DES_KEY_ONLY during join * entry: check user and group names for illegal characters * tools: add --recursive option to delete-computer * tools: testjoin, use realm from keytab as domain name * enroll: use realm form the HOST$ entry in the keytab * Tests: initial framework and tests for adcli based on sssd-test-framework * krb5: add adcli_krb5_get_error_message() * Various fixes for issues found by static code scanners * enroll: Populate Samba's secrets database using offline domain join Update to 0.9.2: * adenroll: set password via LDAP instead Kerberos * disco: fall back to LDAPS if CLDAP ping was not successful * tools: replace getpass() * adenroll: write SID before secret to Samba's db * doc: add clarification to add-member command on doc/adcli.xml * tools: Set umask before calling mkdtemp() * Avoid undefined behaviour in short option parsing * library: include endian.h for le32toh * man: Fix typos and use consistent upper case for some keywords * configure: check for ns_get16 and ns_get32 as well * Add setattr and delattr options * entry: add passwd-user sub-command * Add dont-expire-password option Update to 0.9.1: * tools: add show-computer command * add description option to join and update * Use GSS-SPNEGO if available * add option use-ldaps * tools: disable SSSD's locator plugin * doc: explain required AD permissions * computer: add create-msa sub-command * Add account-disable option * fix coredump in discovery (boo#1183870) Update to 0.9.0: * doc: add missing samba_data_tool_path.xml(.in) to EXTRA_DIST * doc: explain how to force password reset * Do not use arcfour-hmac-md5 when discovering the salt * Fix for issue found by Coverity * adenroll: use only enctypes permitted by Kerberos config * adenroll: add adcli_enroll_get_permitted_keytab_enctypes with tests * adconn: add adcli_conn_set_krb5_context * adenroll: make sure only allowed enctypes are used in FIPS mode * tools: computer - remove errx from parse_option

  • Release Date
    Jul 22 2026
  • References
    Bugzilla: 1183870
  • Type
    recommended
  • Severity
    moderate

cloud_download Downloads

Basesystem Module 15.7 aarch64
  • Packages
    adcli
    Tool for performing actions on an Active Directory domain
    0.9.3.1-150600.22.8.1 lock rpm lock src
    adcli-doc
    Documentation for adcli
    0.9.3.1-150600.22.8.1 lock rpm
Basesystem Module 15.7 ppc64le
  • Packages
    adcli
    Tool for performing actions on an Active Directory domain
    0.9.3.1-150600.22.8.1 lock rpm lock src
    adcli-doc
    Documentation for adcli
    0.9.3.1-150600.22.8.1 lock rpm
Basesystem Module 15.7 s390x
  • Packages
    adcli
    Tool for performing actions on an Active Directory domain
    0.9.3.1-150600.22.8.1 lock rpm lock src
    adcli-doc
    Documentation for adcli
    0.9.3.1-150600.22.8.1 lock rpm
Basesystem Module 15.7 x86_64
  • Packages
    adcli
    Tool for performing actions on an Active Directory domain
    0.9.3.1-150600.22.8.1 lock rpm lock src
    adcli-doc
    Documentation for adcli
    0.9.3.1-150600.22.8.1 lock rpm