FreeIPA
| FreeIPA | |
|---|---|
| Developer | Red Hat |
| Stable release | 4.13.4
/ September 7, 2026 |
| Written in | C[1] and Python[2] |
| Operating system | Linux / Unix |
| Type | Identity management |
| License | GNU General Public License |
| Website | www |
| Repository | |
FreeIPA is a free and open-source identity management system sponsored by Red Hat.[3] It is the upstream project for Red Hat Enterprise Linux Identity Management and provides a centralized system for managing identity, policy, and audit (IPA) information across Linux and Unix networks.[4]
FreeIPA is built by integrating a number of existing free and open-source components, including Fedora Linux, the 389 Directory Server, MIT Kerberos, the Network Time Protocol, DNS, the Dogtag Certificate System, and the System Security Services Daemon (SSSD).[5] Each component remains a separate upstream project under its own license, while FreeIPA's integration layer — including its command-line, web, and programmatic (XML-RPC and JSON-RPC) management interfaces and Python software development kit — is distributed under the GNU General Public License version 3.[5] Since version 3.0.0, FreeIPA has used Samba to establish cross-forest trusts with Microsoft Active Directory, allowing it to interoperate with Windows, macOS, and other Unix-based clients.[6]
As of September 2026, the current stable release is FreeIPA 4.13.4, issued to fix two security vulnerabilities, one of which allowed an unauthenticated attacker to obtain administrator privileges.[7]
Overview
[edit]FreeIPA aims to provide a centrally-managed identity, policy, and audit (IPA) system.[8] It uses a combination of Fedora Linux, 389 Directory Server, MIT Kerberos, NTP, DNS, the Dogtag certificate system, SSSD and other free/open-source components. FreeIPA includes extensible management interfaces (CLI, Web UI, XMLRPC and JSONRPC API) and Python SDK for the integrated CA, and BIND with a custom plugin for the integrated DNS server. Each of the major components of FreeIPA operates as a preexisting free/open-source project. The bundling of these components into a single manageable suite with a comprehensive management interface is GPLv3, but that does not change the licenses of the components.[9]
Since version 3.0.0, FreeIPA uses Samba to integrate with Microsoft's Active Directory by way of Cross Forest Trusts. FreeIPA provides support for Linux, Unix-based, Windows and Mac OS X computers.[10][11]
Security vulnerabilities
[edit]In September 2026, the FreeIPA project released version 4.13.4 to address two vulnerabilities disclosed by Red Hat.[7]
CVE-2026-76578 affected the self-managed one-time-password (OTP) token access control instruction (ACI) in the underlying 389 Directory Server. Because the ACI did not restrict which attributes could accompany a new token entry, an unauthenticated LDAP client using an anonymous bind could create an entry that also carried a forged Kerberos principal, allowing that principal to be added to the administrators group and granting the attacker genuine FreeIPA administrator rights.[12][13] The National Vulnerability Database scored the flaw 9.8 out of 10 (Critical).[13]
CVE-2026-79678 was a separate, lower-severity issue (CVSS 8.1) in the idp-add command. Caller-supplied --organization and --base-url values were passed into a Python eval() call before the corresponding LDAP authorization check ran, allowing any authenticated IPA principal to read the server process's environment variables or trigger a denial of service through memory exhaustion. Red Hat noted that the pattern used blocked arbitrary code execution.[7][12]
Both issues were fixed upstream in FreeIPA 4.13.4, released 7 September 2026.[7]
Software components
[edit]| Component | Details |
|---|---|
| Fedora Linux | Linux operating system |
| 389 Directory Server | LDAP implementation |
| MIT's Kerberos 5 | authentication and single sign-on |
| ntpd | network time protocol |
| Apache HTTP Server | Web UI and management framework |
| Python | management framework |
| DogTag | PKI certificate authority |
Popular plugins
[edit]| Plugin | Description |
|---|---|
| Fleet Commander | Desktop configuration tool that works alongside Cockpit and SSSD to store customized profile templates into FreeIPA's LDAP database. Broadly comparable to Windows GPOs. |
See also
[edit]References
[edit]- ↑ C Coding Style - Free IPA
- ↑ Python Coding Style - Free IPA
- ↑ "Red Hat Identity Manager: Part 1 – Overview and Getting started". Red Hat Developer. Retrieved 2026-09-28.
- ↑ Negus, Christopher; Foster-Johnson, Eric (2011). Fedora Bible 2011 Edition: Featuring Fedora Linux 14. Indianapolis: John Wiley & Sons. ISBN 9781118085738. Retrieved 2016-09-01.
- 1 2 "GPL License – Top 10 Questions Answered". Mend. 2023-06-08. Retrieved 2023-09-18.
- ↑ "Active Directory trust setup". FreeIPA Project. Retrieved 2023-09-22.
- 1 2 3 4 "FreeIPA 4.13.4". FreeIPA Project. Retrieved 2026-09-28.
- ↑ Negus, Christopher; Foster-Johnson, Eric (2011). Fedora Bible 2011 Edition: Featuring Fedora Linux 14. Indianapolis: John Wiley & Sons. ISBN 9781118085738. Retrieved 2016-09-01.
The "IPA" part of FreeIPA stands for identity (identifying and authenticating users and machines), policy (settings for access control of applications and machines), and audit (methods for collecting and auditing security events, logs, and user activities).
- ↑ "GPL License - Top 10 Questions Answered". Mend. 8 June 2023. Retrieved 2023-09-18.
- ↑ M, Ahmer (15 September 2022). "How to install FreeIPA Server on Rocky Linux 9". CentLinux. Retrieved 2023-09-18.
- ↑ "Active_Directory_trust_setup — FreeIPA documentation". www.freeipa.org. Retrieved 2023-09-22.
- 1 2 "FreeIPA Flaw Chain Lets Anonymous Users Become Admins in Default Installs". The Hacker News. 2026-09-08. Retrieved 2026-09-28.
- 1 2 "ALT-PU-2026-14885". ALT Linux Team. Retrieved 2026-09-28.