SUSE Manager Proxy 5.0 and SUSE Manager Retail Branch Server 5.0

Release Notes
2025-11-27 12:18:51 +0400
Table of Contents

  * Version revision history
  * About SUSE Manager Proxy 5.0
      + Containerization
  * System requirements
  * SUSE Manager Proxy distribution
  * Installation and setup
      + Virtual Machine images for SUSE Manager Proxy 5.0
  * Upgrade from previous version
  * SUSE Manager Server versions
  * Major changes since SUSE Manager Proxy 5.0 GA
      + Features and changes
          o Version 5.0.6
              # SUSE Linux Enterprise Server 15 SP6 LTSS
          o Version 5.0.5.1
              # Important Security Update
          o Version 5.0.5
          o Version 5.0.4
              # Host OS Support Expanded to Include SLES 15 SP6
          o Version 5.0.3
          o Version 5.0.2.1
              # Updated Images for SUSE Manager 5.0
          o Version 5.0.2
          o Version 5.0.1
              # SUSE Manager Proxy BYOS image
              # mgrpxy support config
      + Patches
          o Version 5.0.6
          o Version 5.0.5.1
          o Version 5.0.5
          o Version 5.0.4
          o Version 5.0.3
          o Version 5.0.2
          o Version 5.0.1
  * Major Changes Since SUSE Manager Proxy 4.3
      + Base system changed
      + Salt 3006.0
      + mgr-bootstrap tool removed from the Proxy
      + Dropped features
          o Traditional Stack has been removed
      + Deprecated features
  * Known issues
  * Keep Informed
  * Providing feedback
  * Resources
  * Legal Notices
  * Colophon

5.0.6

This SUSE product includes materials licensed to SUSE under the GNU General
Public License (GPL). The GPL requires that SUSE makes available certain source
code that corresponds to the GPL-licensed material. The source code is
available for download.

For up to three years after SUSE's distribution of the SUSE product, SUSE will
mail a copy of the source code upon request. Requests should be sent by e-mail
or as otherwise instructed here. SUSE may charge a fee to recover reasonable
costs of distribution.

Version revision history

  * December 2025: 5.0.6 release

  * October 2025: 5.0.5.1 release

  * July 2025: 5.0.5 release

  * June 18th 2025: 5.0.4.1 release

  * April 2025: 5.0.4 release

  * February 18th 2025: 5.0.3 release

  * December 16th 2024: 5.0.2.1 release

  * November 18th 2024: 5.0.2 release

  * September 17th 2024: 5.0.1 release

  * 16th July, 2024: 5.0 GA

About SUSE Manager Proxy 5.0

SUSE Manager Proxy offers mirroring proxy support tailored for large and
distributed environments.

The Proxy operates transparently, appearing as a managed client to the SUSE
Manager Server and as a server to the managed clients.

Managed clients communicate exclusively with the Proxy, which then relays
requests to the SUSE Manager Server.

All software packages that pass through the SUSE Manager Proxy are cached,
allowing subsequent client requests for these packages to be resolved directly
from the cache.

Containerization

SUSE Manager 5.0 represents a significant evolution with its delivery in
containers, offering enhanced modularity and efficiency. In version 4.3, the
SUSE Manager Proxy and Retail Branch Server were containerized. However, with
this release, the SUSE Manager Server is now delivered in containers.

This shift allows for improved portability, simplifying deployment and
management in modern container-centric environments. By containerizing the
Server, flexibility is increased and it becomes easier to adapt to various
infrastructure setups. This is the first step toward further modularization,
preparing SUSE Manager Server for resilience and scalability. Future versions
of SUSE Manager are expected to continue this journey.

Containerization streamlines deployment and management processes, resulting in
better resilience and improved infrastructure availability. These changes
reflect a commitment to delivering a more adaptable and efficient solution for
managing different environments.

These enhancements are expected to greatly benefit users, providing them with a
more flexible and efficient SUSE Manager.

System requirements

The SUSE Manager Proxy was previously available for x86_64 architecture only,
but now it supports AArch64 architecture as well.

It is advisable to have a minimum of 8 GB of RAM and approximately 50 GB of
disk space per distribution or channel. Additional disk space should be
considered for storing images for retail terminals.

For more details on system requirements, see the Installation Guide on https://
documentation.suse.com/suma/5.0/.

SUSE Manager Proxy distribution

SUSE Manager Server, Proxy, and Retail Branch Server will be packaged in
containers, accessible through the SUSE Registry.

The SUSE Manager Retail Branch Server and SUSE Manager Proxy extensions are
both built on top of SLE Micro, equipped with the necessary tools to manage
Retail Branch Server and Proxy, respectively.

Installation and setup

To install SUSE Manager Proxy 5.0 , you should use the mgrpxy tool provided as
part of the SUSE Manager Proxy extension on top of SLE Micro 5.5.

For more details on installing and configuring SUSE Manager Proxy 5.0, see the
Installation Guide on https://documentation.suse.com/suma/5.0/en/suse-manager/
installation-and-upgrade/container-deployment/suma/proxy-deployment-suma.html

Important Only the containerized versions of SUSE Manager Proxy and Retail
          Branch server will be available for SUSE Manager 5.0.

Virtual Machine images for SUSE Manager Proxy 5.0

SUSE Manager 5.0 will come with virtual machine images tailored for KVM and
VMware. These Proxy images will support x86_64 and now also ARM64 (AArch64)
architectures.

These virtual machine images provide pre-configured environments that can be
quickly deployed in KVM and VMware environments, saving time and effort in
setting up virtual machines from scratch.

Using these images is the recommended and supported method for deploying new
instances of SUSE Manager Server on these platforms.

For detailed instructions, see the Deploy as a Virtual Machine section in the
official documentation.

Upgrade from previous version

In version 4.3, we provide support for both containerized and regular proxies.
However, there's no direct in-place migration path from SUSE Manager Proxy 4.3
to SUSE Manager 5.0 Proxy . In this case, you'll need to set up a new Proxy and
transition your clients to the new Proxy.

For detailed guidance on upgrading, please refer to the Upgrade Guide available
at https://documentation.suse.com/suma/5.0/en/suse-manager/
installation-and-upgrade/proxy-intro.html

          Currently, it is not straightforward to re-use the old Proxy's FQDN.
Important Users must create a new Proxy and then move the Minions to the new
          Proxy through the SUSE Manager UI or using the API.

SUSE Manager Server versions

SUSE Manager Proxy 5.0 is compatible only with SUSE Manager 5.0 Server.

However, SUSE Manager Proxy 4.3 is backward compatible and can still function
with SUSE Manager 5.0 Server. So, there's no immediate need to migrate all
proxies if it's not feasible.

The product is designed for optimal performance when used in a scenario where
all components ? SUSE Manager Server, SUSE Manager Proxy, and Retail Branch
Server ? are of the same version. It's generally advised to avoid using mixed
versions long-term in production environments.

Major changes since SUSE Manager Proxy 5.0 GA

Features and changes

          With the next version, SUSE Manager will be rebranded and renamed to
          SUSE Multi-Linux Manager. This new name better reflects the product's
Important capabilities and emphasizes its operating system-agnostic nature,
          showcasing its ability to manage multiple Linux distributions. You
          may have already noticed the new name being used in some places.

Version 5.0.6

SUSE Linux Enterprise Server 15 SP6 LTSS

SUSE Linux Enterprise Server 15 SP6 will transition to LTSS on 1 January 2026.
LTSS channels have been enabled in SUSE Multi-Linux Manager 5.0, allowing users
with LTSS subscriptions to continue managing their systems.

     Since SUSE Multi-Linux Manager 5.0 is supported on SUSE Linux Enterprise
     Server 15 SP6 as the host, if you have been running SUSE Multi-Linux
Note Manager 5.0 on SUSE Linux Enterprise Server 15 SP6, you must either switch
     to SUSE Linux Enterprise Server 15 SP6 LTSS or migrate to SUSE Multi-Linux
     Manager 5.1 in order to continue receiving updates after the LTSS
     transition.

Version 5.0.5.1

Important Security Update

This update addresses a high-severity CVE. We highly recommend upgrading your
SUSE Manager proxy instances as soon as possible to ensure they remain secure.
The following CVE is included in this release:

  * CVE-2025-53880 - bsc#1246277 - Sanitize path in sync-proxy script

Version 5.0.5

Bugfix release

Version 5.0.4

Host OS Support Expanded to Include SLES 15 SP6

SLE Micro 5.5 was initially selected as the host operating system for SUSE
Manager 5.0 due to its modern architecture and suitability for containerized
environments, with the goal of enabling it on more operating systems in the
future.

Soon after, based on valuable feedback from users, it became clear that there
was a demand to run Multi-Linux Manager on more traditional operating systems
like SLES, even before the release of 5.1.

Therefore, SUSE Manager 5.0 will now be also supported when running on SUSE
Linux Enterprise Server 15 SP6 as a host operating system. This applies to the
Server, Proxy, and Retail Branch Server components.

This change provides more flexibility and lowers the barrier for existing users
transitioning to SUSE Manager 5.0.

     Images that bundle the operating system with SUSE Manager 5.0, including
Note those used in cloud environments, will continue to be based on SLE Micro.
     If you prefer to use SLES 15 SP6, you can do so by manually installing
     SUSE Manager on top of it.

     When running SUSE Manager 5.0 on top of SLE Micro 5.5, no separate
Note subscription is required for the operating system. However, for SLES 15
     SP6, users must bring their own subscription (BYOS).

For more information, see Deploy Server on SUSE Linux Enterprise Server 15 SP6
for the server and Deploy Proxy on SUSE Linux Enterprise Server 15 SP6 for the
proxy.

Version 5.0.3

Bugfix release

Version 5.0.2.1

Updated Images for SUSE Manager 5.0

SUSE Manager 5.0 offers custom images for virtual machines and bare-metal
deployments, supporting multiple architectures and formats. We are now
refreshing these images to incorporate SUSE Manager version 5.0.2. The updated
images will feature the latest available version of SUSE Manager along with
various improvements and fixes.

Version 5.0.2

Bugfix release

Version 5.0.1

SUSE Manager Proxy BYOS image

With this update, we are excited to announce the availability of
Bring-your-own-subscription (BYOS) images on Amazon Cloud and Microsoft Azure.
This new option complement our existing on-premises deployment model, giving
you more flexibility in how you use SUSE Manager Proxy.

mgrpxy support config

With this update, the mgrpxy tool has been enhanced to include a support config
command that collects all relevant logs.

Patches

The SUSE Patch Finder is a simple online service to view released patches.

Version 5.0.6

branch-network-formula:

  * Update to version 1.0.0

      + Update branding name

      + Support containerized branch server

  * Update to version 0.1.1728559936.c16d4fb

python-susemanager-retail:

  * Update to version 1.2.0

      + Enable supported formulas on containerized branch server.

  * Update to version 1.1.0:

      + Fix delta size maxint by using string (bsc#1247951)

      + Handle containerized branch server (bsc#1222128)

rhnlib:

  * Version 5.0.6-0

      + Fix syntax error in changelog

      + Use more secure defusedxml parser (bsc#1227577)

spacecmd:

  * Version 5.0.14-0

      + Fix syntax error in changelog

      + Fix installation of python lib files on Ubuntu 24.04 (bsc#1246586)

      + Make caching code Py 2.7 compatible

      + Use JSON instead of pickle for spacecmd cache (bsc#1227579)

      + Python 2.7 cannot re-raise exceptions

      + Make spacecmd to work with Python 3.12 and higher

      + Call print statements properly in Python 3

spacewalk-admin:

  * Version 5.0.12-0

      + Fix syntax error in changelog

      + Correctly handles http proxy empty passwords (bsc#1249502)

spacewalk-backend:

  * Version 5.0.16-0

      + Fix parameter error when syncing product repositories in ISS v1 (bsc#
        1244724)

      + Fix syntax error in changelog

      + Fix PREPENDED_DIR error when importing pkgs

      + Reposync: prevent excessive logging for patches that are skipped (bsc#
        1250239)

      + Reposync: show message about filtering failed packages only when there
        are failing packages

      + Prevent exceptions getting CFG values when running mgr-inter-sync (bsc#
        1248403)

      + Use libsolv for version comparison for reposync with --latest (bsc#
        1248799)

spacewalk-certs-tools:

  * Version 5.0.11-0

      + Correct PROFILE_NAME variable definition in bootstrap script (bsc#
        1246035)

      + Fix syntax error in changelog

      + Add flag to bootstrap script ot generate machine_id for Uyuni

spacewalk-client-tools:

  * Version 5.0.11-0

      + Fix syntax error in changelog

spacewalk-config:

  * Version 5.0.8-0

      + Fix syntax error in changelog

      + Do not generate listing for /os-images (bsc#1247544)

spacewalk-proxy:

  * Version 5.0.7-0

      + Fix syntax error in changelog

      + Limit maximum proxy workers to 150 (bsc#1244552)

spacewalk-proxy-docs:

  * Version 5.0.2-0

      + Fix syntax error in changelog

spacewalk-proxy-html:

  * Version 5.0.2-0

      + Fix syntax error in changelog

spacewalk-proxy-installer:

  * Version 5.0.2-0

      + Fix syntax error in changelog

spacewalk-setup:

  * Version 5.0.8-0

      + Fix syntax error in changelog

      + Use a dedicated path for Cobbler settings (bsc#1244027)

      + Fix problem syncing custom modules to Salt Master (bsc#1251796)

spacewalk-utils:

  * Version 5.0.8-0

      + Fix syntax error in changelog

      + Use a dedicated path for Cobbler settings (bsc#1244027)

spacewalk-web:

  * Version 5.0.25-0

      + Update translation strings

  * Version 5.0.24-0

      + Bump the WebUI version to 5.0.6

  * Version 5.0.23-0

      + Wrap events output instead of long side scroll (bsc#1250342)

      + Improve error message handling for duplicate filter name.

      + Fix broken CVE links in CVE audit page.

      + Checked options immediately enable linked password policy fields. (bsc#
        1244430)

      + Fix tooltip text for Create button on Maintenance page.

      + Add the last checked in column back to the system lists (bsc#1248411)

      + Drop unused build requirements

      + Build now requires at least Node.js 22

      + Drop legacy dependencies (bsc#1247983)

      + Update web UI dependencies

      + Build no longer requires susemanager-frontend-libs (bsc#1247983)

      + Ensure the UI works with an unknown VHM provider

      + Fix syntax error in changelog

      + Fix URL to salt formular documentation (bsc#1248741)

      + Fix recently registered systems filter (bsc#1243183)

      + Fix parsing errors in organization credentials list (bsc#1246436)

      + Fix systems list CSV download to align with UI filtering (bsc#1248409)

      + Fix physical systems list (bsc#1248661)

susemanager:

  * Version 5.0.14-0

      + Added missing bootrap repository definition for OES 24.4 (bsc#1241013)

      + Add logrotate to Ubuntu bootstrap repositories

      + Add bootstrap repo definition for SUSE Linux Micro 6.2

      + Configure default official update server domain

      + Fix syntax error in changelog

susemanager-sls:

  * Version 5.0.19-0

      + Adjust sls files for python311-kiwi (bsc#1251864)

  * Version 5.0.18-0

      + Automatically deploy IBM GPG keys to SUSE minions (bsc#1246421)

      + Provide token through a query parameter instead of relying on a plugin
        for DNF version supporting it (bsc#1241307)

      + Move jmx configuration to a persisting folder (bsc#1244219)

      + Succeed liberate product migration also when reinstall packages is
        disabled (bsc#1248804)

      + Fix reebot needed detection of transaction update systems

      + Add all image types supported by kiwi (bsc#1246663)

      + Collect CPU architecture specific data on hardware profile update (jsc#
        SUMA-406)

susemanager-sync-data:

  * Version 5.0.14-0

      + Add SUSE Linux Enterprise Server 15 SP6 LTSS channel families

susemanager-tftpsync:

  * Version 5.0.2-0

      + Use TLS in sync_post_tftpd_proxies (bsc#1243679)

      + Refuse files with shell characters (bsc#1243768)

      + Use a dedicated path for Cobbler settings (bsc#1244027)

uyuni-tools:

  * Version 0.1.37-0

      + Handle CA files with symlinks during migration (bsc#1251044)

      + Add a lowercase version of --logLevel (bsc#1243611)

      + Adjust traefik exposed configuration for chart v27+ (bsc#1247721)

      + Stop executing scripts in temporary folder (bsc#1243704)

      + Convert the traefik install time to local time (bsc#1251138)

      + Run smdba and reindex only during migration (bsc#1244534)

      + Support config: collect podman inspect for hub container (bsc#1245099)

      + Add --registry-host, --registry-user and --registry-password to pull
        images from an authenticate registry

      + Deprecate --registry in favour of --registry-host

      + Use new dedicated path for Cobbler settings (bsc#1244027)

      + Migrate custom auto installation snippets (bsc#1246320)

      + Add SLE15SP7 to buildin productmap

      + Fix loading product map from mgradm configuration file (bsc#1246068)

      + Fix channel override for distro copy

      + Do not use sudo when running as a root user (bsc#1246882)

      + Do not require backups to be at the same location for restoring (bsc#
        1246906)

      + Check for restorecon presence before calling (bsc#1246925)

      + Automatically get up-to-date systemid file on salt based proxy hosts (
        bsc#1246789)

      + Fix recomputing proxy images when installing a ptf or test (bsc#1246553
        )

      + Add migration for server monitoring configuration (bsc#1247688)

Version 5.0.5.1

susemanager-tftpsync-recv:

  * Version 5.0.3-0:

      + CVE-2025-53880: Sanitize path in sync-proxy script (bsc#1246277)

rhnlib:

  * Version 5.0.5-0

      + Use more secure defusedxml parser (bsc#1227577)

spacewalk-backend:

  * Version 5.0.15-0

      + Use more secure defusedxml parser (bsc#1227577)

spacewalk-web:

  * Version 5.0.22-0

      + Bump the WebUI version to 5.0.5.1

proxy-helm:

  * Version 5.0.16:

      + Chart rebuilt to the newest version with updated dependencies

proxy-httpd-image:

  * Version 5.0.14:

      + Image rebuilt to the newest version with updated dependencies

proxy-salt-broker-image:

  * Version 5.0.14:

      + Image rebuilt to the newest version with updated dependencies

proxy-squid-image:

  * Version 5.0.14:

      + Image rebuilt to the newest version with updated dependencies

proxy-ssh-image:

  * version 5.0.14:

      + Image rebuilt to the newest version with updated dependencies

proxy-tftpd-image:

  * Version 5.0.14:

      + Image rebuilt to the newest version with updated dependencies

Version 5.0.5

saltboot-formula:

  * Update to version 0.1.1750679229.f368550

      + Support local boot to deployed kernel even when version does not match
        pillar boot version (bsc#1238514)

  * Update to version 0.1.1728559936.c16d4fb

spacecmd:

  * Version 5.0.13-0

      + Improve translation update process

      + Update translation strings

spacewalk-admin:

  * Version 5.0.11-0

      + Support environment variables in rhn-config-satellite (bsc#1242148)

      + mgr-monitoring-ctl: avoid possible UnicodeDecoreError due to non-ascii
        characters (bsc#1242030)

spacewalk-backend:

  * Version 5.0.14-0

      + CVE-2025-46809: Do not expose HTTP Proxy password when breaking URL
        format (bsc#1245005)

      + Enhance permissions for reposync zypper cache

  * Version 5.0.13-0

      + Use localhost instead of getfqdn as server_url (bsc#1238320)

      + Do not log debug messages as errors (bsc#1240124)

      + Improve translation update process

      + Fix fetching the mirrorlist with a CA bundle which includes only the
        intermediate CAs. This is the case for RHUI CA bundles (bsc#1243241).

      + Make reposync allow commas as part of HTTP Proxy password (bsc#1243460)

      + Remove bootloader linux and initrd files from spacewalk-debug

      + Fix zstd-compressed comps file reposync use case (bsc#1243821)

      + Use libzypp's Curl2 backend during reposync (bsc#1245222)

spacewalk-certs-tools:

  * Version 5.0.10-0

      + Add the possibility to use env variables for ACTIVATION_KEYS and
        ORG_GPG_KEY

      + Add the possibility to use env variable for HOSTNAME

spacewalk-client-tools:

  * Version 5.0.10-0

      + Improve translation update process

      + Update translation strings

spacewalk-config:

  * Version 5.0.7-0

      + Allow passing env variables to rhn-config-satellite (bsc#1242148)

      + Disable directory listing (bsc#1241094)

spacewalk-proxy:

  * Version 5.0.6-0

      + Disable directory listing (bsc#1241094)

spacewalk-utils:

  * Version 5.0.7-0

      + Fix SSL error when connecting to localhost in the container (bsc#
        1240023)

      + Fix spacewalk-hostname-rename with containers (bsc#1229825)

spacewalk-web:

  * Version 5.0.21-0

      + Fix button alignment in filter modal (bsc#1240160)

      + Adjust modal height for small screens

      + Update brand name in Admin proxy page

      + Fix setup wizard organization credentials list subscriptions not
        showing correctly the first time (bsc#1243765)

      + Fix: Filters of type Product Temporary Fix cannot be created bsc#
        1238922

      + Better handling of system list filtering (bsc#1242004)

      + CVE-2025-23392: Filter user input in systems list page (bsc#1239826)

      + CVE-2025-23393: Filter user input in systems list page (bsc#1240386)

      + Fix NPM dependency license aggregation bug

      + Fix layout issues on Ansible pages

      + Fix sticky toolbar hiding notification messages on packages page (bsc#
        1239621)

      + Fix layout issues in product page (bsc#1240131)

      + Ensure browser cache is busted when newer assets are available (bsc#
        1240984)

      + Update web UI dependencies

      + Improve translation update process

      + Fix: better react state handling (bcs#1241140)

      + Fix the date picker in CLM filter creation (bsc#1237710)

      + Fix content visibility issues on the Action Chains page (bsc#1239558,
        bsc#1239559)

      + Fix datetime picker opening unexpectedly (bsc#1237710)

      + Bump the WebUI version to 5.0.5

susemanager:

  * Version 5.0.13-0

      + Use a persisting folder for custom modules to import in
        mgr-create-bootstrap-repo (bsc#1242135)

      + Improve translation update process

      + Fix creating bootstrap repositories for products which have only a base
        channel (bsc#1239747)

susemanager-build-keys:

  * Changed keys to use SHA256 UIDs instead of SHA1. (bsc#1237294 bsc#1236779
    jsc#PED-12321)

  * rename: build-alp-09d9ea69-645b99ce.asc to build-alp-09d9ea69.asc

  * rename: gpg-pubkey-3fa1d6ce-63c9481c.asc to gpg-pubkey-3fa1d6ce.asc

  * addjust: suse_ptf_key_2023.asc, suse_ptf_key.asc

susemanager-sls:

  * Version 5.0.14-0

      + Read CWD for remote commands from pillar (bsc#1238173)

      + Adjust SLS files for SUSE Linux Enterprise 15SP7 and other systems
        running higher Python versions

      + Add container based kiwi10 build system

      + Optimize SAP module to prevent high IO workload (bsc#1241455)

      + Move Prometheus PostgreSQL exporter configuration to the persisting
        volume /etc/sysconfig (bsc#1239903)

susemanager-sync-data:

  * Version 5.0.13-0

      + Fix typo in OES 24.4 product definition

uyuni-common-libs:

  * Version 5.0.7-0

      + Fix decompress function for the zst format (bsc#1243821)

uyuni-storage-setup:

  * Version 5.0.4-0

      + Ensure selinuxenabled exists before executing it (bsc#1241060)

uyuni-tools:

  * Version 0.1.31-0

      + Add the info message about End User License Agreement

      + Don't migrate py2*-compat-salt.conf files (bsc#1240626)

      + Check for restorecon before using it (bsc#1240698)

      + Adjust the distro path in cobbler files after migration (bsc#1238929)

      + Add mgradm support ptf podman --pullPolicy flag (bsc#1236877)

      + Support: don't dump files in bound folders (bsc#1243297)

      + Cleanup host supportconfig files (bsc#1242174)

      + During migration, check if backup already exists (bsc#1243105)

      + Remove SHM size limits from all containers (bsc#1243274)

      + Don't migrate /etc/apache2/vhosts.d/cobbler.conf

      + Fix migration --prepare for autoinstallable distributions (bsc#1243802)

      + Skip instalation if the server is already set up (bsc#1238849)

      + Bump the default image tag to 5.0.5

Version 5.0.4

spacecmd:

  * Version 5.0.12-0

      + Allow translation to wrap strings as weblate forces it

      + Show Source String change for translations spacewalk-backend:

  * Version 5.0.12-0

      + Allow translation to wrap strings as weblate forces it

      + Show Source String change for translations

      + Make ISSv1 timezone independent (bsc#1221505)

      + Allow spacewalk-repo-sync filtering using NEVRA instead of package name
        only (bsc#1234226)

      + Fix AttributeError: ENABLE_NVREA for reposyncing (bsc#1226273)

      + Fix wrong timestamp when importing packages with rhnpush (bsc#1235970)

      + Implement module to get configuration values from the database

      + Cast float pkg metadata to int (gh#uyuni-project/uyuni#9613)

      + New password policy implemented, removal of old defaults

      + Improve Debian reposync logging (bsc#1227859)

spacewalk-web:

  * Version 5.0.17-0

      + Add a column to the CVE auditing result table to show the data source
        (OVAL or channels) used for auditing the system

      + Increase complexity for generated passwords (bsc#1231983)

      + Simplify HTTP proxy setup in setup wizard (bsc#1235527)

      + Layout improvements for the login page and error page

      + Allow translation to wrap strings as weblate forces it

      + Show Source String change for translations

      + Adjusted login page theme to align with branding

      + Password policy restrictions and functions first release

uyuni-tools:

  * version 0.1.29-0

      + Revert use of :z flag on server volumes (bsc#1235861)

      + Escape lang_package macro properly

      + Relabel proxy config files on SELinux (bsc#1235658)

      + Bump the default image tag to 5.0.4

proxy-helm:

  * Version 5.0.12:

      + Image rebuilt to the newest version with updated dependencies

proxy-httpd-image:

  * Version 5.0.10:

      + Fixed wrong IP address set on susemanager-tftpsync-recv.conf

      + Image rebuilt to the newest version with updated dependencies

proxy-salt-broker-image:

  * Version 5.0.10:

      + Image rebuilt to the newest version with updated dependencies

proxy-squid-image:

  * Version 5.0.10:

      + Set maximal cache time for metadata to 5 minutes

      + Image rebuilt to the newest version with updated dependencies

proxy-ssh-image:

  * version 5.0.10:

      + Image rebuilt to the newest version with updated dependencies

proxy-tftpd-image:

  * Version 5.0.10:

      + Fixed possible collisions replacing FQDNs for proxies (bsc#1236601)

      + Replaced server hostname in chained proxy tftp container (bsc#1236166)

      + Image rebuilt to the newest version with updated dependencies

Version 5.0.3

saltboot-formula:

  * Update to version 0.1.1728559936.c16d4fb

      + Add MAC based terminal naming option (jsc#SUMA-314)

  * Update to version 0.1.1723628891.ffb1da5

      + Rework request stop function to avoid unnecessary warnings(bsc#1212985)

spacecmd:

  * Version 5.0.11-0

      + Update translation strings

spacewalk-backend:

  * Version 5.0.11-0

      + Rename table suseProductSCCRepository to the more meaningful name
        suseChannelTemplate (bsc#1234994)

      + Add dependency to libzypp to support new token style

      + Fix mgr-sign-metadata-ctl check-channels when checking for signatures
        in repomd metadata (bsc#1233884)

      + Set default rpm package summary if it's missing (bsc#1232530)

      + Detect and update errata when not all repository packages are linked (
        bsc#1227644)

spacewalk-proxy:

  * Version 5.0.5-0

      + Add IPv6 support for salt-broker (bsc#1227827)

      + Make salt-broker reconnecting if master IP has changed (bsc#1228182)

      + Make salt-broker less dependant on spacewalk libs

      + Make socket opt setting more strict and verbose (bsc#1229286)

spacewalk-setup:

  * Version 5.0.7-0

      + Remove now unneeded hostname calls (bsc#1231255)

spacewalk-utils:

  * Version 5.0.6-0

      + Force login to spacecmd from spacewalk-hostname-rename (bsc#1229848)

      + Remove unmaintained snapshot and export tools from package
        spacewalk-utils-extras

      + Remove tools from spacewalk-utils-extra and move them to Uyuni contrib
        repository

spacewalk-web:

  * Version 5.0.16-0

      + Fixed misleading error while waiting for SCC credentials
        synchronisation (bsc#1227374)

      + Add safeguard against CVE-2024-21528

      + Update numerous page layouts

      + Upgrade DOMPurify to fix CVE-2024-45801

      + Ensure icon fonts are loaded correctly on buttons (bsc#1231378)

      + Update shared Javascript dependencies

      + Reduce Bundle size for the web UI

      + Update web UI build tooling

      + Update the Web UI version

      + Introduce numeric search field in table filters

      + Add notification for users with disabled SCC data forwarding (jsc#
        SUMA-431)

uyuni-tools:

  * Version 0.1.28-0

      + Persist search server indexes (bsc#1231759)

      + Add registry.suse.com login to mgradm upgrade podman list (bsc#1234123)

      + Only raise an error if cloudguestregistryauth fails for PAYG (bsc#
        1233630)

      + Consider the configuration file to detect the coco or Hub API images
        should be pulled (bsc#1229104)

      + Only add java.hostname on migrated server if not present

      + Add --registry back to mgrpxy (bsc#1233202)

      + Ignore coco and Hub images when applying PTF if they are not available
        (bsc#1229079)

      + Sync deletes files during migration (bsc#1233660)

      + Run systemctl daemon-reload after changing the container image config (
        bsc#1233279)

      + coco-replicas-upgrade

      + IsInstalled function fix

      + Bump the default image tag to 5.0.3

      + Use the uyuni network for all podman containers (bsc#1232817)

  * Version 0.1.27.0

      + Bump the default image tag to 5.0.2

  * Version 0.1.26-0

      + Ignore all zypper caches during migration (bsc#1232769)

      + Use the uyuni network for all podman containers (bsc#1232817)

proxy-httpd-image:

  * Version 5.0.9

      + Update for next release

proxy-salt-broker-image:

  * Version 5.0.9

      + Update for next release

proxy-squid-image:

  * Version 5.0.9

      + Update for next release

proxy-ssh-image:

  * Version 5.0.9

      + Update for next release

proxy-tftpd-image:

  * Version 5.0.9

      + Update for next release

Version 5.0.2

python-susemanager-retail:

  * Update to version 1.0.1722253762.9f01ce8

      + Fix delta creation on containerized server (bsc#1226369)

saltboot-formula:

  * Update to version 0.1.1723628891.ffb1da5

      + Rework request stop function to avoid unnecessary warnings (bsc#1212985
        )

spacecmd:

  * Version 5.0.10-0

      + Speed up softwarechannel_removepackages (bsc#1227606)

      + Fix error in 'kickstart_delete' when using wildcards(bsc#1227578)

      + Spacecmd bootstrap now works with specified port (bsc#1229437)

      + Fix sls backup creation as directory with spacecmd (bsc#1230745)

spacewalk-backend:

  * Version 5.0.10-0

      + Ignore 'buildorder' parsing errors when parsing entries in module
        metadata (bsc#1230274)

      + Provide http_headers also to Debian repository syncer

      + Make spacewalk-data-fsck aware of orphaned RPMs (bsc#1227882)

      + reposync: import GPG keys to RPM DB individually (bsc#1217003)

      + Add log string to the journal when services are stopped because of
        insufficient disk space

spacewalk-certs-tools:

  * Version 5.0.8-0

      + Fix parsing Authority Key Identifier when keyid is not prefixed (bsc#
        1229079)

spacewalk-proxy:

  * Version 5.0.4-0

      + Set proxy authtoken FQDN based on config file (bsc#1230255)

      + Allow execute of ssh-keygen command on the Proxy to cleanup SSH
        known_hosts (bsc#1228345)

spacewalk-setup:

  * Version 5.0.6-0

      + Collect spacewalk-setup-cobbler return code (bsc#1226847)

spacewalk-utils:

  * Version 5.0.5-0

      + Add repositories for Ubuntu 24.04 LTS

      + Drop unsupported tool spacewalk-final-archive as it is broken and may
        disclose sensitive information (bsc#1228945)

      + Move taskotop tool to spacewalk-utils package

spacewalk-web:

  * Version 5.0.13-0

      + Fix Find Targets button behavior for the feature Salt > Remote Commands
        page

      + Fix the missing background color for the pending status badge and show/
        hide the response badge component.

      + Fix stretched button issue in Audit Search and Subscription Matching
        pages

      + Fix alert layout in formula catalog

      + Fix sticky header infinite scroll

      + Fix layout mismatch in patches management

      + Fix column alignment on repository and system pages

      + Integrate UI debugging stories

      + Fix Extra Packages column in systems list (bsc#1228980)

      + Update the WebUI version

uyuni-tools:

  * Version 0.1.25.0

      + Don't migrate enabled systemd services, recreate them (bsc#1232575)

  * Version 0.1.24-0

      + CVE-2024-22037: Use podman secret to store the database credentials (
        bsc#1231497)

      + Redact JSESSIONID and pxt-session-cookie values from logs and console
        output (bsc#1231568)

  * Version 0.1.23-0

      + Ensure namespace is defined in all kubernetes commands

      + Use SCC credentials to authenticate against registry.suse.com for
        kubernetes (bsc#1231157)

      + Fix namespace usage on mgrctl cp command

  * Version 0.1.22-0

      + Set projectId also for test packages/images

      + mgradm migration should not pull Confidential Computing and Hub image
        is replicas == 0 (bsc#1229432, bsc#1230136)

      + Do not allow SUSE Manager downgrade

      + Prevent completion issue when /var/log/uyuni-tools.log is missing

      + Fix proxy shared volume flag

      + During migration, exclude mgr-sync configuration file (bsc#1228685)

      + Migrate from PostgreSQL 14 to PostgreSQL 16 pg_hba.conf and
        postgresql.conf files (bsc#1231206)

      + During migration, handle empty autoinstallation path (bsc#1230285)

      + During migration, handle symlinks (bsc#1230288)

      + During migration, trust the remote sender's file list (bsc#1228424)

      + Use SCC flags during podman pull

      + Restore SELinux permission after migration (bsc#1229501)

      + Share volumes between containers (bsc#1223142)

      + Save supportconfig in current directory (bsc#1226759)

      + Fix error code handling on reinstallation (bsc#1230139)

      + Fix creating first user and organization

      + Add missing variable quotes for install vars (bsc#1229108)

      + Add API login and logout calls to allow persistent login

proxy-httpd-image:

  * Version 5.0.8

      + Store Proxy FQDN in rhn.conf for auth token use (bsc#1230255)

proxy-salt-broker-image:

  * Version 5.0.8

      + Update for next release

proxy-squid-image:

  * Version 5.0.8

      + Update for next release

proxy-ssh-image:

  * Version 5.0.8

      + Update for next release

proxy-tftpd-image:

  * Version 5.0.8

      + Update for next release

Version 5.0.1

spacecmd:

  * Version 5.0.9-0

      + Update translation strings

spacewalk-backend:

  * Version 5.0.9-0

      + Support more NEVRA types when importing module metadata

      + yum_src: use proper name variable name for subprocess.TimeoutExpired

      + Check and populate PTF attributes at the time of importing packages (
        bsc#1225619)

      + reposync: introduce timeout when syncing DEB channels (bsc#1225960)

      + Refresh channel newest packages after importing Appstreams metadata

spacewalk-certs-tools:

  * Version 5.0.7-0

      + Support multiple certificates for root-ca-file and server-cert-file

spacewalk-client-tools:

  * Version 5.0.7-0

      + Update translation strings

spacewalk-web:

  * Version 5.0.12-0

      + Update the WebUI version

  * Version 5.0.11-0

      + Fix btn-info style in new theme

      + Fix missing margin in CVE audit list on cve page

      + Fix broken layout of system formulas configuration page

      + Fix table filters for description, first character dropdown and toggle
        button.

      + Fix channel selection using SSM (bsc#1226917)

      + Fix broken layout in monitoring page

      + Fix missing margin between inline radio buttons

      + Fix OpenSCAP search page layout

      + Remove Bare metal systems tab from General Configuration page

      + Update setup wizard UI

      + Remove reboot from uptodate state, introduce reboot and rebootifneeded
        states

      + Fix space between radio button and label in forms

      + Fix layout of SSM subpages in updated theme

      + Fix broken layout of build image page

      + Fix layout of advanced package search page

      + Fix badege color in salt key table

      + Fix hidden section issue in Monitoring and General Configuration pages

      + Fix double padding in recurring actions table

      + Fix missing top border in table footer

      + Fix broken layout of system highstate page

      + Fix input alignment and style issues on schedule creation page

      + Fix datetime selection when using maintenance windows (bsc#1228036)

      + Configure AppStreams via Activation Keys

susemanager-build-keys:

  * Vesion 15.5.1

      + extended 2048 bit SUSE SLE 12, 15 GA-SP5 key until 2028 (bsc#1229339)

          o gpg-pubkey-39db7c82-66c5d91a.asc

uyuni-storage-setup:

  * Version 5.0.1-0

      + Provide uyuni-storage-setup-proxy

uyuni-tools:

  * Version 0.1.21-0

      + mgrpxy: Fix typo on Systemd template

  * Version 0.1.20-0

      + Update the push tag to 5.0.1

      + mgrpxy: expose port on IPv6 network (bsc#1227951)

  * Version 0.1.19-0

      + Skip updating Tomcat remote debug if conf file is not present

  * Version 0.1.18-0

      + Setup Confidential Computing container during migration (bsc#1227588)

      + Add the /etc/uyuni/uyuni-tools.yaml path to the config help

      + Split systemd config files to not loose configuration at upgrade (bsc#
        1227718)

      + Use the same logic for image computation in mgradm and mgrpxy (bsc#
        1228026)

      + Allow building with different Helm and container default registry paths
        (bsc#1226191)

      + Fix recursion in mgradm upgrade podman list --help

      + Setup hub xmlrpc API service in migration to Podman (bsc#1227588)

      + Setup disabled hub xmlrpc API service in all cases (bsc#1227584)

      + Clean the inspection code to make it faster

      + Properly detect IPv6 enabled on Podman network (bsc#1224349)

      + Fix the log file path generation

      + Write scripts output to uyuni-tools.log file

      + Add uyuni-hubxml-rpc to the list of values in mgradm scale --help

      + Use path in mgradm support sql file input (bsc#1227505)

      + On Ubuntu build with go1.21 instead of go1.20

      + Enforce Cobbler setup (bsc#1226847)

      + Expose port on IPv6 network (bsc#1227951)

      + show output of podman image search --list-tags command

      + Implement mgrpxy support config command

      + During migration, ignore /etc/sysconfig/tomcat and /etc/tomcat/
        tomcat.conf (bsc#1228183)

      + During migration, remove java.annotation,com.sun.xml.bind and
        UseConcMarkSweepGC settings

      + Disable node exporter port for Kubernetes

      + Fix start, stop and restart in Kubernetes

      + Increase start timeout in Kubernetes

      + Fix traefik query

      + Fix password entry usability (bsc#1226437)

      + Add --prepare option to migrate command

      + Fix random error during installation of CA certificate (bsc#1227245)

      + Clarify and fix distro name guessing when not provided (bsc#1226284)

      + Replace not working Fatal error by plain error return (bsc#1220136)

      + Allow server installation with preexisting storage volumes

      + Do not report error when purging mounted volume (bsc#1225349)

      + Preserve PAGER settings from the host for interactive sql usage (bsc#
        1226914)

      + Add mgrpxy command to clear the Squid cache

      + Use local images for Confidential Computing and Hub containers (bsc#
        1227586)

init-image:

  * Version 5.0.8

      + Update for next release

proxy-helm:

  * Version 5.0.8

      + Update for next release

proxy-httpd-image:

  * Version 5.0.7

      + Update for next release

proxy-salt-broker-image:

  * Version 5.0.7

      + Update for next release

proxy-squid-image:

  * Version 5.0.7

      + Update for next release

proxy-ssh-image:

  * Version 5.0.7

      + Update for next release

proxy-tftpd-image:

  * Version 5.0.7

      + Update for next release

Major Changes Since SUSE Manager Proxy 4.3

Base system changed

SUSE Manager 4.3 was built on SUSE Linux Enterprise 15 SP4, but for SUSE
Manager 5.0, we've shifted to SUSE Linux Enterprise Micro 5.5 as the base
system. This change was made because SLE Micro is better suited for container
workloads and has a longer lifecycle. Additionally, the SLE Micro subscription
for the Proxy will now be included in the SUSE Manager subscription,
eliminating the need for customers to purchase the underlying OS subscription
separately.

Salt 3006.0

For SUSE Manager 5.0, we're sticking with version 3006.0. The reason behind
this decision is that it's a long-term support (LTS) version. Our plan is to
upgrade to the next LTS version, which will be 3008.0 when it will be
available. We won't be transitioning to short-term support (STS) versions.

Throughout this process, we'll ensure that all critical bug fixes, including
CVEs, L3 fixes, and essential features needed for SUSE Manager, are provided
and addressed.

mgr-bootstrap tool removed from the Proxy

The mgr-bootstrap tool has been taken out from the Proxy and will be removed
from the Server as well in future. Overall, several tools on both the Server
and Proxy will be phased out in favor of the API or integrated into mgrpxy/
mgradm.

If users wish to create a bootstrap script to register against the Proxy, they
can do so using the following command from the Server container:

mgr-boostrap --hostname $proxyfqdn

Dropped features

Traditional Stack has been removed

Starting with the SUSE Manager 4.3 release, the traditional stack was marked as
deprecated. Now, with the release of SUSE Manager 5.0, we are completely
removing support for the traditional stack. This means that we will not support
traditional clients and proxies based on traditional stack anymore.

For additional details on migrating traditional clients to Salt clients, please
refer to Migrate traditional clients to Salt clients.

Deprecated features

None

Known issues

None

Keep Informed

You can stay up-to-date regarding information about SUSE Manager and SUSE
products:

  * Check the newest SUSE Manager 5.0 release notes

  * Read the SUSE Blog

  * Use the SUSE Best Practices for SUSE Manager

  * Join the upstream Uyuni community and monthly community meetings

  * Join the channels users and devel at Gitter to chat with upstream
    community.

Providing feedback

If you encounter a bug in any SUSE product, please report it through your SUSE
Customer Service or Sales representatives

Resources

Latest product documentation: https://documentation.suse.com/suma/5.0/.

Technical product information for SUSE Manager: https://www.suse.com/products/
suse-manager/

These release notes are available online: https://www.suse.com/releasenotes/

Visit https://www.suse.com for the latest Linux product news from SUSE.

Visit https://www.suse.com/source-code/ for additional information on the
source code of SUSE Linux Enterprise products.

Legal Notices

SUSE Software Solutions Germany GmbH
Frankenstra?e 146
D-90461 N?rnberg
Tel: +49 (0)911 740 53 - 0
Email: feedback@suse.com

SUSE makes no representations or warranties with regard to the contents or use
of this documentation, and specifically disclaims any express or implied
warranties of merchantability or fitness for any particular purpose. Further,
SUSE reserves the right to revise this publication and to make changes to its
content, at any time, without the obligation to notify any person or entity of
such revisions or changes.

Further, SUSE makes no representations or warranties with regard to any
software, and specifically disclaims any express or implied warranties of
merchantability or fitness for any particular purpose. Further, SUSE reserves
the right to make changes to any and all parts of SUSE software, at any time,
without any obligation to notify any person or entity of such changes.

Any products or technical information provided under this Agreement may be
subject to U.S. export controls and the trade laws of other countries. You
agree to comply with all export control regulations and to obtain any required
licenses or classifications to export, re-export, or import deliverables. You
agree not to export or re-export to entities on the current U.S. export
exclusion lists or to any embargoed or terrorist countries as specified in U.S.
export laws. You agree to not use deliverables for prohibited nuclear, missile,
or chemical/biological weaponry end uses. Please refer to the SUSE Legal
information page for more information on exporting SUSE software. SUSE assumes
no responsibility for your failure to obtain any necessary export approvals.

Copyright ? 2012-2024 SUSE LLC.

This release notes document is licensed under a Creative Commons
Attribution-NoDerivatives 4.0 International License (CC-BY-ND-4.0). You should
have received a copy of the license along with this document. If not, see
https://creativecommons.org/licenses/by-nd/4.0/.

SUSE has intellectual property rights relating to technology embodied in the
product that is described in this document. In particular, and without
limitation, these intellectual property rights may include one or more of the
U.S. patents listed at https://www.suse.com/company/legal/ and one or more
additional patents or pending patent applications in the U.S. and other
countries.

For SUSE trademarks, see SUSE Trademark and Service Mark list (https://
www.suse.com/company/legal/). All third-party trademarks are the property of
their respective owners.

Colophon

Thank you for using SUSE Manager Proxy and/or SUSE Manager Retail Branch Server
in your business.

Your SUSE Manager Team.

Last updated 2025-11-27 12:18:51 +0400
