Bug 54635 - Update OpenLDAP to 2.5.11 or later
Update OpenLDAP to 2.5.11 or later
Status: NEW
Product: UCS
Classification: Unclassified
Component: LDAP
UCS 5.0
Other Linux
: P5 normal (vote)
: ---
Assigned To: UCS maintainers
UCS maintainers
https://lists.opensuse.org/archives/l...
:
: 52306 (view as bug list)
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-04-04 22:17 CEST by Arvid Requate
Modified: 2022-12-08 17:05 CET (History)
0 users

See Also:
What kind of report is it?: Development Internal
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional): Security
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Arvid Requate univentionstaff 2022-04-04 22:17:08 CEST
We should update OpenLDAP. Bookworm currently has 2.5.11 upstream has 2.6.1.
Comment 1 Arvid Requate univentionstaff 2022-04-04 22:29:11 CEST
I had a look at the required changes and adjusted our patches to obtain a source package that could be built successfully. I've committed my temporary results here:

r19562 | 2.5.11+dfsg-1-update-poc  (Patches adjusted to upstream)


There are more things to do. From the changelog:

* "The ppolicy schema has been merged into the slapo-ppolicy(5) module."

I.e. /etc/ldap/schema/ppolicy.schema is not installed any longer, so the slapd.conf
needs to be adjusted to take that into consideration prior to the update, otherwise
slapd fails start during package update (in particular during database dump+restore),
leaving a dysfunctional system that needs manual intervention.
Comment 2 Arvid Requate univentionstaff 2022-04-06 15:42:06 CEST
Looks like we can avoid dump+restore of the slapd-mdb backend:

https://www.mail-archive.com/openldap-technical@openldap.org/msg26119.html
Comment 3 Philipp Hahn univentionstaff 2022-12-08 17:05:42 CET
*** Bug 52306 has been marked as a duplicate of this bug. ***