Provides support for enabling DNS over TLS in the IPA integrated DNS
server.
Provides
Requires
License
GPL-3.0-or-later
Changelog
* Mon Aug 24 2026 David Hanina <dhanina@redhat.com> - 4.13.3-1
- Resolves: RHEL-245629 CVE-2026-19550 ipa: FreeIPA: trust-fetch-domains uses trust-read ACI to gate a privileged AD trust refresh, allowing unauthorized LDAP writes [rhel-10.3]
- Resolves: RHEL-240899 CVE-2026-13097 ipa: Privilege escalation via krbCanonicalName manipulation due to realm-unaware uniqueness enforcement in FreeIPA LDAP datastore [rhel-10.3]
- Resolves: RHEL-240837 CVE-2026-11861 ipa: FreeIPA: Obtaining TGS with impersonating cname through trust relationships [rhel-10.3]
- Resolves: RHEL-240820 CVE-2026-73197 ipa: FreeIPA: Unauthenticated DoS in `/ipa/migration/migration.py` via Unbounded Request Body Read [rhel-10.3]
- Resolves: RHEL-240797 CVE-2026-73198 ipa: FreeIPA: Unauthenticated DoS in `/ip