-
Story
-
Resolution: Unresolved
-
Undefined
-
None
-
ipa-4.12.2-19.el10
-
Important
-
rhel-sst-idm-ipa
-
rhel-sst-idm-ipa
-
ssg_idm
-
12
-
18
-
3
-
QE ack, Dev ack
-
False
-
-
Yes
-
None
-
Fail
-
Automated
-
Unspecified Release Note Type - Unknown
-
Unspecified
-
Unspecified
-
Unspecified
-
None
Goal
- For RHEL 10+ we have to use OpenSSL provider API as OpenSSL engine API is deprecated. This concerns BIND loading of the SoftHSM token holding DNSSEC keys
Acceptance criteria
A list of verification conditions, successful functional tests, or expected outcomes in order to declare this story/task successfully completed.
- Use OpenSSL provider with BIND for RHEL10.1
- DNS: detect when OpenSSL engine should be removed on upgrade
- ipa-dnskeysyncd: use systemd-tmpfiles to handle tokens
- update BIND-related dependencies
- Make IPAAbstractVersion available to all platforms