Edge Rewrite
// request.cf · coarse context

A page that knows where it met you.

Only coarse request metadata is shown. This demo does not display or persist visitor IP addresses.

Country
US
Cloudflare location
CMH
Connection
HTTP/2
Language
Not provided

Ray ID: a4218532e851de81

Jump to content

FreeIPA

From Wikipedia, the free encyclopedia
FreeIPA
DeveloperRed Hat
Stable release
4.13.4 / September 7, 2026; 21 days ago (2026-09-07)
Written inC[1] and Python[2]
Operating systemLinux / Unix
TypeIdentity management
LicenseGNU General Public License
Websitewww.freeipa.org Edit this on Wikidata
Repository

FreeIPA is a free and open-source identity management system sponsored by Red Hat.[3] It is the upstream project for Red Hat Enterprise Linux Identity Management and provides a centralized system for managing identity, policy, and audit (IPA) information across Linux and Unix networks.[4]

FreeIPA is built by integrating a number of existing free and open-source components, including Fedora Linux, the 389 Directory Server, MIT Kerberos, the Network Time Protocol, DNS, the Dogtag Certificate System, and the System Security Services Daemon (SSSD).[5] Each component remains a separate upstream project under its own license, while FreeIPA's integration layer — including its command-line, web, and programmatic (XML-RPC and JSON-RPC) management interfaces and Python software development kit — is distributed under the GNU General Public License version 3.[5] Since version 3.0.0, FreeIPA has used Samba to establish cross-forest trusts with Microsoft Active Directory, allowing it to interoperate with Windows, macOS, and other Unix-based clients.[6]

As of September 2026, the current stable release is FreeIPA 4.13.4, issued to fix two security vulnerabilities, one of which allowed an unauthenticated attacker to obtain administrator privileges.[7]

Overview

[edit]

FreeIPA aims to provide a centrally-managed identity, policy, and audit (IPA) system.[8] It uses a combination of Fedora Linux, 389 Directory Server, MIT Kerberos, NTP, DNS, the Dogtag certificate system, SSSD and other free/open-source components. FreeIPA includes extensible management interfaces (CLI, Web UI, XMLRPC and JSONRPC API) and Python SDK for the integrated CA, and BIND with a custom plugin for the integrated DNS server. Each of the major components of FreeIPA operates as a preexisting free/open-source project. The bundling of these components into a single manageable suite with a comprehensive management interface is GPLv3, but that does not change the licenses of the components.[9]

Since version 3.0.0, FreeIPA uses Samba to integrate with Microsoft's Active Directory by way of Cross Forest Trusts. FreeIPA provides support for Linux, Unix-based, Windows and Mac OS X computers.[10][11]

Security vulnerabilities

[edit]

In September 2026, the FreeIPA project released version 4.13.4 to address two vulnerabilities disclosed by Red Hat.[7]

CVE-2026-76578 affected the self-managed one-time-password (OTP) token access control instruction (ACI) in the underlying 389 Directory Server. Because the ACI did not restrict which attributes could accompany a new token entry, an unauthenticated LDAP client using an anonymous bind could create an entry that also carried a forged Kerberos principal, allowing that principal to be added to the administrators group and granting the attacker genuine FreeIPA administrator rights.[12][13] The National Vulnerability Database scored the flaw 9.8 out of 10 (Critical).[13]

CVE-2026-79678 was a separate, lower-severity issue (CVSS 8.1) in the idp-add command. Caller-supplied --organization and --base-url values were passed into a Python eval() call before the corresponding LDAP authorization check ran, allowing any authenticated IPA principal to read the server process's environment variables or trigger a denial of service through memory exhaustion. Red Hat noted that the pattern used blocked arbitrary code execution.[7][12]

Both issues were fixed upstream in FreeIPA 4.13.4, released 7 September 2026.[7]

Software components

[edit]
Component Details
Fedora Linux Linux operating system
389 Directory Server LDAP implementation
MIT's Kerberos 5 authentication and single sign-on
ntpd network time protocol
Apache HTTP Server Web UI and management framework
Python management framework
DogTag PKI certificate authority
[edit]
Plugin Description
Fleet Commander Desktop configuration tool that works alongside Cockpit and SSSD to store customized profile templates into FreeIPA's LDAP database. Broadly comparable to Windows GPOs.

See also

[edit]

References

[edit]
  1. ↑ C Coding Style - Free IPA
  2. ↑ Python Coding Style - Free IPA
  3. ↑ "Red Hat Identity Manager: Part 1 – Overview and Getting started". Red Hat Developer. Retrieved 2026-09-28.
  4. ↑ Negus, Christopher; Foster-Johnson, Eric (2011). Fedora Bible 2011 Edition: Featuring Fedora Linux 14. Indianapolis: John Wiley & Sons. ISBN 9781118085738. Retrieved 2016-09-01.
  5. 1 2 "GPL License – Top 10 Questions Answered". Mend. 2023-06-08. Retrieved 2023-09-18.
  6. ↑ "Active Directory trust setup". FreeIPA Project. Retrieved 2023-09-22.
  7. 1 2 3 4 "FreeIPA 4.13.4". FreeIPA Project. Retrieved 2026-09-28.
  8. ↑ Negus, Christopher; Foster-Johnson, Eric (2011). Fedora Bible 2011 Edition: Featuring Fedora Linux 14. Indianapolis: John Wiley & Sons. ISBN 9781118085738. Retrieved 2016-09-01. The "IPA" part of FreeIPA stands for identity (identifying and authenticating users and machines), policy (settings for access control of applications and machines), and audit (methods for collecting and auditing security events, logs, and user activities).
  9. ↑ "GPL License - Top 10 Questions Answered". Mend. 8 June 2023. Retrieved 2023-09-18.
  10. ↑ M, Ahmer (15 September 2022). "How to install FreeIPA Server on Rocky Linux 9". CentLinux. Retrieved 2023-09-18.
  11. ↑ "Active_Directory_trust_setup — FreeIPA documentation". www.freeipa.org. Retrieved 2023-09-22.
  12. 1 2 "FreeIPA Flaw Chain Lets Anonymous Users Become Admins in Default Installs". The Hacker News. 2026-09-08. Retrieved 2026-09-28.
  13. 1 2 "ALT-PU-2026-14885". ALT Linux Team. Retrieved 2026-09-28.
[edit]