=== SSSD 1.11.1 ===

The SSSD team is proud to announce the release of version 1.11.1 of
the System Security Services Daemon.

As always, the source is available from https://fedorahosted.org/sssd

RPM packages will be made available for Fedora 19, 20 and rawhide shortly.

== Feedback ==

Please provide comments, bugs and other feedback via the sssd-devel
or sssd-users mailing lists:

== Highlights ==
 * This release contains mainly bug fixes in the Active Directory provider
   and setups where the SSSD is running on an IPA server instance. In
  - Several cases where offline authentication did not work correctly for
    users from Active Directory domains were fixed
  - Fixed a resolver bug that caused the SSSD to only look up AAAA records
    for trusted Active Directory servers
  - SSSD is now able to resolve users from trusted AD domains using their
    POSIX attributes
 * The simple access provider now allows the administrator to specify
   users or groups from trusted domains in the access or deny lists
 * Handling of Kerberos credential caches was made simpler and more robust

== Packaging Changes ==
 * A new subpackage sssd-common-pac was added to work around a packaging
   bug. Previous SSSD versions would own the PAC responder by both the
   IPA and AD providers, which is not permitted by the Fedora packaging

== Tickets Fixed ==
    Enable printf format string checking in function debug_fn
    Implement heuristics to use Global Catalog servers from local DNS
    domain first
    sss_debuglevel did not increase verbosity in sssd_pac.log
    [RFE] simple access provider: support subdomain users and groups
    Cached credentials aren't working with sssd-ad UPN logins
    sssd-ad unable to resolve names in other domains possibly UPN related
    ad: invalid handling of Domain Users group for subdomain user
    Carry on if detecting the flat name fails
    Initial enumeration in the AD provider does not work
    The present sssd-ad is unable to pull RFC2307 attributes from all
    domains in a forest
    sssd fails to retrieve netgroups with multiple CN attributes
    Fix expand_ccname_template libkrb5 style expansion and add tests
    SSSD subdomains provider does not resolve SRV records correctly when
    DNS name of the server is different from domain/realm name of IPA
    install in IPA server mode
    When in IPA server mode, SSSD should map trusted forest subdomains to
    root domain realm
    man sssd-sudo: improve description of necessary configuration
    The multicast check is wrong in the sudo source code getting the host info
    getpwuid and getgrgid do not use the negative cache
    Document that server side password policies always takes precedence
    sssd should write capaths for IPA trusted forests' subdomains

== Detailed Changelog ==
