SUSE-RU-2026:3191-1: moderate: Recommended update for adcli

SLE-UPDATES null at suse.de
Wed Jul 22 20:57:01 UTC 2026


# Recommended update for adcli

Announcement ID: SUSE-RU-2026:3191-1  
Release Date: 2026-07-22T14:08:43Z  
Rating: moderate  
References:

  * bsc#1183870
  * jsc#PED-13768
  * jsc#PED-16503

  
Affected Products:

  * Basesystem Module 15-SP7
  * openSUSE Leap 15.6
  * SUSE Linux Enterprise Desktop 15 SP7
  * SUSE Linux Enterprise Real Time 15 SP7
  * SUSE Linux Enterprise Server 15 SP6
  * SUSE Linux Enterprise Server 15 SP6 LTSS
  * SUSE Linux Enterprise Server 15 SP7
  * SUSE Linux Enterprise Server for SAP Applications 15 SP6
  * SUSE Linux Enterprise Server for SAP Applications 15 SP7

  
  
An update that contains two features and has one fix can now be installed.

## Description:

This update for adcli fixes the following issues:

Update to 0.9.3.1; (jsc#PED-13768);

  * enroll: check if AD accepts new password
  * enroll: allow to add SPNs to manages service accounts
  * enroll: add new SPNs from AD to keytab during update
  * conn: use 10s timeout for connect()
  * enroll: restore SELinux file context of keytab files
  * enroll: remove USE_DES_KEY_ONLY during join
  * entry: check user and group names for illegal characters
  * tools: add --recursive option to delete-computer
  * tools: testjoin, use realm from keytab as domain name
  * enroll: use realm form the HOST$ entry in the keytab
  * Tests: initial framework and tests for adcli based on sssd-test-framework
  * krb5: add adcli_krb5_get_error_message()
  * Various fixes for issues found by static code scanners
  * enroll: Populate Samba's secrets database using offline domain join

Update to 0.9.2:

  * adenroll: set password via LDAP instead Kerberos
  * disco: fall back to LDAPS if CLDAP ping was not successful
  * tools: replace getpass()
  * adenroll: write SID before secret to Samba's db
  * doc: add clarification to add-member command on doc/adcli.xml
  * tools: Set umask before calling mkdtemp()
  * Avoid undefined behaviour in short option parsing
  * library: include endian.h for le32toh
  * man: Fix typos and use consistent upper case for some keywords
  * configure: check for ns_get16 and ns_get32 as well
  * Add setattr and delattr options
  * entry: add passwd-user sub-command
  * Add dont-expire-password option

Update to 0.9.1:

  * tools: add show-computer command
  * add description option to join and update
  * Use GSS-SPNEGO if available
  * add option use-ldaps
  * tools: disable SSSD's locator plugin
  * doc: explain required AD permissions
  * computer: add create-msa sub-command
  * Add account-disable option
  * fix coredump in discovery (boo#1183870)

Update to 0.9.0:

  * doc: add missing samba_data_tool_path.xml(.in) to EXTRA_DIST
  * doc: explain how to force password reset
  * Do not use arcfour-hmac-md5 when discovering the salt
  * Fix for issue found by Coverity
  * adenroll: use only enctypes permitted by Kerberos config
  * adenroll: add adcli_enroll_get_permitted_keytab_enctypes with tests
  * adconn: add adcli_conn_set_krb5_context
  * adenroll: make sure only allowed enctypes are used in FIPS mode
  * tools: computer - remove errx from parse_option

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Linux Enterprise Server 15 SP6 LTSS  
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3191=1

  * Basesystem Module 15-SP7  
    zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3191=1

  * SUSE Linux Enterprise Server for SAP Applications 15 SP6  
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3191=1

  * openSUSE Leap 15.6  
    zypper in -t patch SUSE-2026-3191=1

## Package List:

  * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
    * adcli-debuginfo-0.9.3.1-150600.22.8.1
    * adcli-0.9.3.1-150600.22.8.1
    * adcli-debugsource-0.9.3.1-150600.22.8.1
    * adcli-doc-0.9.3.1-150600.22.8.1
  * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
    * adcli-debuginfo-0.9.3.1-150600.22.8.1
    * adcli-0.9.3.1-150600.22.8.1
    * adcli-debugsource-0.9.3.1-150600.22.8.1
    * adcli-doc-0.9.3.1-150600.22.8.1
  * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
    * adcli-debuginfo-0.9.3.1-150600.22.8.1
    * adcli-0.9.3.1-150600.22.8.1
    * adcli-debugsource-0.9.3.1-150600.22.8.1
    * adcli-doc-0.9.3.1-150600.22.8.1
  * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
    * adcli-doc-0.9.3.1-150600.22.8.1
    * adcli-0.9.3.1-150600.22.8.1
    * adcli-debugsource-0.9.3.1-150600.22.8.1
    * adcli-debuginfo-0.9.3.1-150600.22.8.1

## References:

  * https://bugzilla.suse.com/show_bug.cgi?id=1183870
  * https://jira.suse.com/browse/PED-13768
  * https://jira.suse.com/browse/PED-16503

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-updates/attachments/20260722/caa3d6ff/attachment.htm>


More information about the sle-updates mailing list