<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:ind-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
<generator>
<oval:product_name>Oracle Errata System</oval:product_name>
<oval:product_version>Oracle Linux</oval:product_version>
<oval:schema_version>5.11</oval:schema_version>
<oval:timestamp>2026-09-24T19:08:26</oval:timestamp>
</generator>
<definitions>
<definition id="oval:com.oracle.elsa:def:202670564" version="501" class="patch">
<metadata>
<title>
ELSA-2026-70564:  ipa security, bug fix, and enhancement update (CRITICAL)
</title>
<affected family="unix">
<platform>Oracle Linux 9</platform>

</affected>
<reference source="elsa" ref_id="ELSA-2026-70564" ref_url="https://linux.oracle.com/errata/ELSA-2026-70564.html"/>
<reference source="CVE" ref_id="CVE-2026-11861" ref_url="https://linux.oracle.com/cve/CVE-2026-11861.html"/>
<reference source="CVE" ref_id="CVE-2026-13097" ref_url="https://linux.oracle.com/cve/CVE-2026-13097.html"/>
<reference source="CVE" ref_id="CVE-2026-18147" ref_url="https://linux.oracle.com/cve/CVE-2026-18147.html"/>
<reference source="CVE" ref_id="CVE-2026-19550" ref_url="https://linux.oracle.com/cve/CVE-2026-19550.html"/>
<reference source="CVE" ref_id="CVE-2026-73197" ref_url="https://linux.oracle.com/cve/CVE-2026-73197.html"/>
<reference source="CVE" ref_id="CVE-2026-73198" ref_url="https://linux.oracle.com/cve/CVE-2026-73198.html"/>
<reference source="CVE" ref_id="CVE-2026-76578" ref_url="https://linux.oracle.com/cve/CVE-2026-76578.html"/>
<reference source="CVE" ref_id="CVE-2026-79678" ref_url="https://linux.oracle.com/cve/CVE-2026-79678.html"/>

<description>
[4.13.4-1.0.1]
- Set IPAPLATFORM=rhel when build on Oracle Linux [Orabug: 29516674]
- Add bind to ipa-server-common Requires [Orabug: 36518596]

[4.13.4-1]
- RHEL-218866 CVE-2026-18147 ipa: FreeIPA/IdM: Cross-Site Scripting vulnerability allows arbitrary code execution via crafted URL [rhel-9.8.z]
- RHEL-245474 CVE-2026-76578 ipa: FreeIPA: unauthenticated LDAP client can obtain administrator credentials via the self-managed-token ACI [rhel-9.8.z]
- RHEL-248206 CVE-2026-79678 ipa: freeipa: idp-add eval() reachable before authorization check allows environment disclosure and denial of service [rhel-9.8.z]
- RHEL-245627 CVE-2026-19550 ipa: FreeIPA: trust-fetch-domains uses trust-read ACI to gate a privileged AD trust refresh, allowing unauthorized LDAP writes [rhel-9.8.z]
- RHEL-240898 CVE-2026-13097 ipa: Privilege escalation via krbCanonicalName manipulation due to realm-unaware uniqueness enforcement in FreeIPA LDAP datastore [rhel-9.8.z]
- RHEL-240830 CVE-2026-11861 ipa: FreeIPA: Obtaining TGS with impersonating cname through trust relationships [rhel-9.8.z]
- RHEL-240815 CVE-2026-73197 ipa: FreeIPA: Unauthenticated DoS in /ipa/migration/migration.py via Unbounded Request Body Read [rhel-9.8.z]
- RHEL-240804 CVE-2026-73198 ipa: FreeIPA: Unauthenticated DoS in /ipa/i18n_messages via Unbounded Request Body Read [rhel-9.8.z]
- RHEL-240767 ipa-migrate tool is renaming host records &amp; host info in automount information [rhel-9.8.z]
- RHEL-238677 ipa-migrate: require Replication Administrator privilege [rhel-9.8.z]
- RHEL-238674 ipa-epn: drop_privileges method is mixing uid and gid [rhel-9.8.z]
- RHEL-238527 ipa env: support only simple * wildcard [rhel-9.8.z]

[4.13.1-3.2]
- Related: RHEL-166865 Include latest fixes in python3-ipatests package [rhel-9.8.z]

[4.13.1-3.1]
- Resolves: RHEL-166865 Include latest fixes in python3-ipatests package [rhel-9.8.z]
- Resolves: RHEL-155037 Pagure #9953: Adding a group with 32Bit Idrange fails. [rhel-9.8.z]
- Resolves: RHEL-153146 IdM password policy Min lifetime is not enforced when high minlife is set [rhel-9.8.z]
- Resolves: RHEL-168047 ipa ca-show ipa --all failing to list RSN version
</description>
<!--
 ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ 
-->
<advisory>
<severity>CRITICAL</severity>
<rights>Copyright 2026 Oracle, Inc.</rights>
<issued date="2026-09-24"/>
<cve cvss3="9.6/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N" href="https://linux.oracle.com/cve/CVE-2026-11861.html" public="20260820">CVE-2026-11861</cve>
<cve cvss3="8.7/CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N" href="https://linux.oracle.com/cve/CVE-2026-13097.html" public="20260820">CVE-2026-13097</cve>
<cve cvss3="8.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" href="https://linux.oracle.com/cve/CVE-2026-18147.html" public="20260909">CVE-2026-18147</cve>
<cve cvss3="8.2/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N" href="https://linux.oracle.com/cve/CVE-2026-19550.html" public="20260811">CVE-2026-19550</cve>
<cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://linux.oracle.com/cve/CVE-2026-73197.html" public="20260820">CVE-2026-73197</cve>
<cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://linux.oracle.com/cve/CVE-2026-73198.html" public="20260820">CVE-2026-73198</cve>
<cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://linux.oracle.com/cve/CVE-2026-76578.html" public="20260907">CVE-2026-76578</cve>
<cve cvss3="8.1/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" href="https://linux.oracle.com/cve/CVE-2026-79678.html" public="20260907">CVE-2026-79678</cve>

<affected_cpe_list>
<cpe>cpe:/a:oracle:linux:9::appstream</cpe>
<cpe>cpe:/a:oracle:linux:9::codeready_builder</cpe>
</affected_cpe_list>
</advisory>
</metadata>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564001" comment="Oracle Linux 9 is installed"/>
<criteria operator="OR">
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564002" comment="Oracle Linux arch is aarch64"/>
<criteria operator="OR">
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564003" comment="ipa-client is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564004" comment="ipa-client is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564005" comment="ipa-client-common is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564006" comment="ipa-client-common is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564007" comment="ipa-client-encrypted-dns is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564008" comment="ipa-client-encrypted-dns is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564009" comment="ipa-client-epn is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564010" comment="ipa-client-epn is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564011" comment="ipa-client-samba is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564012" comment="ipa-client-samba is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564013" comment="ipa-common is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564014" comment="ipa-common is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564015" comment="ipa-selinux is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564016" comment="ipa-selinux is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564017" comment="ipa-selinux-luna is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564018" comment="ipa-selinux-luna is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564019" comment="ipa-selinux-nfast is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564020" comment="ipa-selinux-nfast is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564021" comment="ipa-server is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564022" comment="ipa-server is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564023" comment="ipa-server-common is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564024" comment="ipa-server-common is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564025" comment="ipa-server-dns is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564026" comment="ipa-server-dns is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564027" comment="ipa-server-encrypted-dns is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564028" comment="ipa-server-encrypted-dns is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564029" comment="ipa-server-trust-ad is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564030" comment="ipa-server-trust-ad is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564031" comment="python3-ipaclient is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564032" comment="python3-ipaclient is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564033" comment="python3-ipalib is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564034" comment="python3-ipalib is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564035" comment="python3-ipaserver is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564036" comment="python3-ipaserver is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564037" comment="python3-ipatests is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564038" comment="python3-ipatests is signed with the Oracle Linux 9 key"/>
</criteria>
</criteria>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564039" comment="Oracle Linux arch is x86_64"/>
<criteria operator="OR">
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564003" comment="ipa-client is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564004" comment="ipa-client is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564005" comment="ipa-client-common is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564006" comment="ipa-client-common is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564007" comment="ipa-client-encrypted-dns is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564008" comment="ipa-client-encrypted-dns is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564009" comment="ipa-client-epn is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564010" comment="ipa-client-epn is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564011" comment="ipa-client-samba is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564012" comment="ipa-client-samba is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564013" comment="ipa-common is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564014" comment="ipa-common is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564015" comment="ipa-selinux is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564016" comment="ipa-selinux is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564017" comment="ipa-selinux-luna is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564018" comment="ipa-selinux-luna is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564019" comment="ipa-selinux-nfast is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564020" comment="ipa-selinux-nfast is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564021" comment="ipa-server is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564022" comment="ipa-server is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564023" comment="ipa-server-common is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564024" comment="ipa-server-common is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564025" comment="ipa-server-dns is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564026" comment="ipa-server-dns is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564027" comment="ipa-server-encrypted-dns is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564028" comment="ipa-server-encrypted-dns is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564029" comment="ipa-server-trust-ad is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564030" comment="ipa-server-trust-ad is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564031" comment="python3-ipaclient is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564032" comment="python3-ipaclient is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564033" comment="python3-ipalib is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564034" comment="python3-ipalib is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564035" comment="python3-ipaserver is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564036" comment="python3-ipaserver is signed with the Oracle Linux 9 key"/>
</criteria>
<criteria operator="AND">
<criterion test_ref="oval:com.oracle.elsa:tst:202670564037" comment="python3-ipatests is earlier than 0:4.13.4-1.0.1.el9_8"/>
<criterion test_ref="oval:com.oracle.elsa:tst:202670564038" comment="python3-ipatests is signed with the Oracle Linux 9 key"/>
</criteria>
</criteria>
</criteria>
</criteria>
</criteria>

</definition>
</definitions>
<!--
 ~~~~~~~~~~~~~~~~~~~~~   rpminfo tests   ~~~~~~~~~~~~~~~~~~~~~ 
-->
<tests>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564001"  version="501" comment="Oracle Linux 9 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564001" />
<state state_ref="oval:com.oracle.elsa:ste:202670564002" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564002"  version="501" comment="Oracle Linux arch is aarch64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564001" />
<state state_ref="oval:com.oracle.elsa:ste:202670564003" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564003"  version="501" comment="ipa-client is earlier than 0:4.13.4-1.0.1.el9_8" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564002" />
<state state_ref="oval:com.oracle.elsa:ste:202670564004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564004"  version="501" comment="ipa-client is signed with the Oracle Linux 9 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564002" />
<state state_ref="oval:com.oracle.elsa:ste:202670564001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564005"  version="501" comment="ipa-client-common is earlier than 0:4.13.4-1.0.1.el9_8" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564003" />
<state state_ref="oval:com.oracle.elsa:ste:202670564004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564006"  version="501" comment="ipa-client-common is signed with the Oracle Linux 9 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564003" />
<state state_ref="oval:com.oracle.elsa:ste:202670564001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564007"  version="501" comment="ipa-client-encrypted-dns is earlier than 0:4.13.4-1.0.1.el9_8" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564004" />
<state state_ref="oval:com.oracle.elsa:ste:202670564004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564008"  version="501" comment="ipa-client-encrypted-dns is signed with the Oracle Linux 9 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564004" />
<state state_ref="oval:com.oracle.elsa:ste:202670564001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564009"  version="501" comment="ipa-client-epn is earlier than 0:4.13.4-1.0.1.el9_8" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564005" />
<state state_ref="oval:com.oracle.elsa:ste:202670564004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564010"  version="501" comment="ipa-client-epn is signed with the Oracle Linux 9 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564005" />
<state state_ref="oval:com.oracle.elsa:ste:202670564001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564011"  version="501" comment="ipa-client-samba is earlier than 0:4.13.4-1.0.1.el9_8" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564006" />
<state state_ref="oval:com.oracle.elsa:ste:202670564004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564012"  version="501" comment="ipa-client-samba is signed with the Oracle Linux 9 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564006" />
<state state_ref="oval:com.oracle.elsa:ste:202670564001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564013"  version="501" comment="ipa-common is earlier than 0:4.13.4-1.0.1.el9_8" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564007" />
<state state_ref="oval:com.oracle.elsa:ste:202670564004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564014"  version="501" comment="ipa-common is signed with the Oracle Linux 9 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564007" />
<state state_ref="oval:com.oracle.elsa:ste:202670564001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564015"  version="501" comment="ipa-selinux is earlier than 0:4.13.4-1.0.1.el9_8" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564008" />
<state state_ref="oval:com.oracle.elsa:ste:202670564004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564016"  version="501" comment="ipa-selinux is signed with the Oracle Linux 9 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564008" />
<state state_ref="oval:com.oracle.elsa:ste:202670564001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564017"  version="501" comment="ipa-selinux-luna is earlier than 0:4.13.4-1.0.1.el9_8" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564009" />
<state state_ref="oval:com.oracle.elsa:ste:202670564004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564018"  version="501" comment="ipa-selinux-luna is signed with the Oracle Linux 9 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564009" />
<state state_ref="oval:com.oracle.elsa:ste:202670564001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564019"  version="501" comment="ipa-selinux-nfast is earlier than 0:4.13.4-1.0.1.el9_8" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564010" />
<state state_ref="oval:com.oracle.elsa:ste:202670564004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564020"  version="501" comment="ipa-selinux-nfast is signed with the Oracle Linux 9 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564010" />
<state state_ref="oval:com.oracle.elsa:ste:202670564001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564021"  version="501" comment="ipa-server is earlier than 0:4.13.4-1.0.1.el9_8" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564011" />
<state state_ref="oval:com.oracle.elsa:ste:202670564004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564022"  version="501" comment="ipa-server is signed with the Oracle Linux 9 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564011" />
<state state_ref="oval:com.oracle.elsa:ste:202670564001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564023"  version="501" comment="ipa-server-common is earlier than 0:4.13.4-1.0.1.el9_8" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564012" />
<state state_ref="oval:com.oracle.elsa:ste:202670564004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564024"  version="501" comment="ipa-server-common is signed with the Oracle Linux 9 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564012" />
<state state_ref="oval:com.oracle.elsa:ste:202670564001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564025"  version="501" comment="ipa-server-dns is earlier than 0:4.13.4-1.0.1.el9_8" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564013" />
<state state_ref="oval:com.oracle.elsa:ste:202670564004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564026"  version="501" comment="ipa-server-dns is signed with the Oracle Linux 9 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564013" />
<state state_ref="oval:com.oracle.elsa:ste:202670564001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564027"  version="501" comment="ipa-server-encrypted-dns is earlier than 0:4.13.4-1.0.1.el9_8" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564014" />
<state state_ref="oval:com.oracle.elsa:ste:202670564004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564028"  version="501" comment="ipa-server-encrypted-dns is signed with the Oracle Linux 9 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564014" />
<state state_ref="oval:com.oracle.elsa:ste:202670564001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564029"  version="501" comment="ipa-server-trust-ad is earlier than 0:4.13.4-1.0.1.el9_8" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564015" />
<state state_ref="oval:com.oracle.elsa:ste:202670564004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564030"  version="501" comment="ipa-server-trust-ad is signed with the Oracle Linux 9 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564015" />
<state state_ref="oval:com.oracle.elsa:ste:202670564001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564031"  version="501" comment="python3-ipaclient is earlier than 0:4.13.4-1.0.1.el9_8" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564016" />
<state state_ref="oval:com.oracle.elsa:ste:202670564004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564032"  version="501" comment="python3-ipaclient is signed with the Oracle Linux 9 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564016" />
<state state_ref="oval:com.oracle.elsa:ste:202670564001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564033"  version="501" comment="python3-ipalib is earlier than 0:4.13.4-1.0.1.el9_8" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564017" />
<state state_ref="oval:com.oracle.elsa:ste:202670564004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564034"  version="501" comment="python3-ipalib is signed with the Oracle Linux 9 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564017" />
<state state_ref="oval:com.oracle.elsa:ste:202670564001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564035"  version="501" comment="python3-ipaserver is earlier than 0:4.13.4-1.0.1.el9_8" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564018" />
<state state_ref="oval:com.oracle.elsa:ste:202670564004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564036"  version="501" comment="python3-ipaserver is signed with the Oracle Linux 9 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564018" />
<state state_ref="oval:com.oracle.elsa:ste:202670564001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564037"  version="501" comment="python3-ipatests is earlier than 0:4.13.4-1.0.1.el9_8" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564019" />
<state state_ref="oval:com.oracle.elsa:ste:202670564004" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564038"  version="501" comment="python3-ipatests is signed with the Oracle Linux 9 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564019" />
<state state_ref="oval:com.oracle.elsa:ste:202670564001" />
</rpminfo_test>
<rpminfo_test id="oval:com.oracle.elsa:tst:202670564039"  version="501" comment="Oracle Linux arch is x86_64" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
<object object_ref="oval:com.oracle.elsa:obj:202670564001" />
<state state_ref="oval:com.oracle.elsa:ste:202670564005" />
</rpminfo_test>

</tests>
<!--
 ~~~~~~~~~~~~~~~~~~~~   rpminfo objects   ~~~~~~~~~~~~~~~~~~~~ 
-->
<objects>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:202670564007" version="501">
<name>ipa-common</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:202670564002" version="501">
<name>ipa-client</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:202670564016" version="501">
<name>python3-ipaclient</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:202670564001" version="501">
<name>oraclelinux-release</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:202670564009" version="501">
<name>ipa-selinux-luna</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:202670564014" version="501">
<name>ipa-server-encrypted-dns</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:202670564018" version="501">
<name>python3-ipaserver</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:202670564012" version="501">
<name>ipa-server-common</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:202670564013" version="501">
<name>ipa-server-dns</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:202670564008" version="501">
<name>ipa-selinux</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:202670564011" version="501">
<name>ipa-server</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:202670564019" version="501">
<name>python3-ipatests</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:202670564003" version="501">
<name>ipa-client-common</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:202670564004" version="501">
<name>ipa-client-encrypted-dns</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:202670564010" version="501">
<name>ipa-selinux-nfast</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:202670564017" version="501">
<name>python3-ipalib</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:202670564005" version="501">
<name>ipa-client-epn</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:202670564006" version="501">
<name>ipa-client-samba</name>
</rpminfo_object>
<rpminfo_object xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:obj:202670564015" version="501">
<name>ipa-server-trust-ad</name>
</rpminfo_object>
</objects>
<states>
<!--
 ~~~~~~~~~~~~~~~~~~~~   rpminfo states   ~~~~~~~~~~~~~~~~~~~~~ 
-->
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:ste:202670564001" version="501">
<signature_keyid operation="equals">bc4d06a08d8b756f</signature_keyid>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:ste:202670564002" version="501">
<version operation="pattern match">^9</version>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:ste:202670564003" version="501">
<arch operation="pattern match">aarch64</arch>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:ste:202670564004" version="501">
<evr datatype="evr_string" operation="less than">0:4.13.4-1.0.1.el9_8</evr>
</rpminfo_state>
<rpminfo_state xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.oracle.elsa:ste:202670564005" version="501">
<arch operation="pattern match">x86_64</arch>
</rpminfo_state>

</states>
</oval_definitions>
