* A flaw was found where authconfig could configure sssd in a way that
treats existing and non-existing logins differently, leaking information
on existence of a user. An attacker with physical or network access to the
machine could enumerate users via a timing attack. (CVE-2017-7488)
--