Bug 54635 - Update OpenLDAP to 2.5.11 or later
Summary: Update OpenLDAP to 2.5.11 or later
Status: NEW
Alias: None
Product: UCS
Classification: Unclassified
Component: LDAP
Version: UCS 5.0
Hardware: Other Linux
: P5 normal
Target Milestone: ---
Assignee: UCS maintainers
QA Contact: UCS maintainers
URL: https://lists.opensuse.org/archives/l...
Keywords:
: 52306 (view as bug list)
Depends on:
Blocks:
 
Reported: 2022-04-04 22:17 CEST by Arvid Requate
Modified: 2022-12-08 17:05 CET (History)
0 users

See Also:
What kind of report is it?: Development Internal
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional): Security
Customer ID:
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Arvid Requate univentionstaff 2022-04-04 22:17:08 CEST
We should update OpenLDAP. Bookworm currently has 2.5.11 upstream has 2.6.1.
Comment 1 Arvid Requate univentionstaff 2022-04-04 22:29:11 CEST
I had a look at the required changes and adjusted our patches to obtain a source package that could be built successfully. I've committed my temporary results here:

r19562 | 2.5.11+dfsg-1-update-poc  (Patches adjusted to upstream)


There are more things to do. From the changelog:

* "The ppolicy schema has been merged into the slapo-ppolicy(5) module."

I.e. /etc/ldap/schema/ppolicy.schema is not installed any longer, so the slapd.conf
needs to be adjusted to take that into consideration prior to the update, otherwise
slapd fails start during package update (in particular during database dump+restore),
leaving a dysfunctional system that needs manual intervention.
Comment 2 Arvid Requate univentionstaff 2022-04-06 15:42:06 CEST
Looks like we can avoid dump+restore of the slapd-mdb backend:

https://www.mail-archive.com/openldap-technical@openldap.org/msg26119.html
Comment 3 Philipp Hahn univentionstaff 2022-12-08 17:05:42 CET
*** Bug 52306 has been marked as a duplicate of this bug. ***