For Fedora 41+ and RHEL 10+ we have to use OpenSSL provider API as OpenSSL engine API is deprecated. This concerns BIND loading of the SoftHSM token holding DNSSEC keys.
Metadata Update from @abbra: - Issue assigned to abbra
PR: https://github.com/freeipa/freeipa/pull/7589
Currently passes all upstream test suites except DNSSEC operations. The latter requires custom bind 9.18 version backporting OpenSSL provider support from bind 9.20+. @pemensik will look into that, hopefully.
bind 9.20+ is currently not supported for the reason that bind-dyndb-ldap is not buildable against it yet.
Metadata Update from @frenaud: - Custom field rhbz adjusted to https://issues.redhat.com/browse/RHEL-65650
Metadata Update from @frenaud: - Issue tagged with: test-failure
master:
ipa-4-12:
Metadata Update from @frenaud: - Issue close_status updated to: fixed - Issue status updated to: Closed (was: Open)