[Freeipa] blueprint Re: [Blueprint servercloud-p-freeipa-tech-preview] FreeIPA Tech Preview

2011-10-26 Thread TImo Aaltonen
Hey For the record, I've created a blueprint [1] and assigned the team to it, but reassigned it to myself for now until it is in a better shape to avoid unnecessary spamming.. I have a FreeIPA server instance running on Fedora 15, and will try to get the client ready for UDS. The goal

[Freeipa] [Bug 259547] Re: [needs-packaging] FreeIPA

2011-11-27 Thread Timo Aaltonen
I've uploaded python-nss and python-krb5 to the archive, certmonger and freeipa itself is left for the freeipa-client to work. The server needs further work. ** Changed in: ubuntu Status: Confirmed = In Progress ** Changed in: ubuntu Assignee: (unassigned) = Timo Aaltonen (tjaalton

[Freeipa] [Bug 899327] Re: auto-generated patch in debian/patches

2012-01-02 Thread Timo Aaltonen
: (unassigned) = Timo Aaltonen (tjaalton) -- You received this bug notification because you are a member of FreeIPA, which is subscribed to python-krbv in Ubuntu. https://bugs.launchpad.net/bugs/899327 Title: auto-generated patch in debian/patches Status in “certmonger” package in Ubuntu: In Progress

[Freeipa] [Bug 935352] Re: osutil version 2.0.2-1~ubuntu2 FTBFS on amd64 in precise

2012-03-26 Thread Timo Aaltonen
osutil got removed from the archive, as it's not needed anymore. ** Changed in: osutil (Ubuntu Precise) Status: New = Fix Released -- You received this bug notification because you are a member of FreeIPA, which is subscribed to osutil in Ubuntu. https://bugs.launchpad.net/bugs/935352

Re: [Freeipa] ipa-client-install error

2012-05-06 Thread Timo Aaltonen
04.05.2012 21:27, Baoli Ma kirjoitti: Hi freeipa team members: I tried to join a Ubuntu12.04 to my freeipa domain, I got the following errors: 2012-05-01 08:38:59,093 DEBUG Init ldap with: ldap://ds.mydomain.com:389 2012-05-01 08:38:59,121 ERROR LDAP Error: Connect error: A TLS packet

[Freeipa] [Bug 997990] Re: fail joining to a freeipa server with ipa-client-install

2012-05-11 Thread Timo Aaltonen
Yes, this is likely a bug in NSS on the server. You can make it work by enabling SSL v3 on the server: - shut dirsrv down - edit /etc/dirsrv/slapd-FOO/dse.ldif: - search for 'nsSSL3:', change the value to 'on' - save the file - start dirsrv the next time ipa-client-install should work. --

[Freeipa] [Bug 997990] Re: fail joining to a freeipa server with ipa-client-install

2012-05-14 Thread Timo Aaltonen
ah, if you mean the comment would run.. it's just informational. SSSD is already enabled, and pam is otherwise configured, but there's no pam- auth-update config for pam_mkhomedir.. probably should just change the text, or drop it. -- You received this bug notification because you are a member

[Freeipa] [Bug 1025864] Re: ipa-getkeytab doesn't work

2012-07-18 Thread Timo Aaltonen
thanks for testing, I'll look at it after my vacation. ** Changed in: freeipa (Ubuntu) Assignee: (unassigned) = Timo Aaltonen (tjaalton) -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs

[Freeipa] [Bug 1104954] Re: CVE-2012-5484: ipa-client security vunerability

2013-01-25 Thread Timo Aaltonen
i'll deal with it soon. ** Changed in: freeipa (Ubuntu) Status: Incomplete = Confirmed ** Changed in: freeipa (Ubuntu) Assignee: (unassigned) = Timo Aaltonen (tjaalton) -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa

[Freeipa] [Bug 1104954] Re: CVE-2012-5484: ipa-client security vunerability

2013-02-10 Thread Timo Aaltonen
** Also affects: freeipa (Ubuntu Precise) Importance: Undecided Status: New -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1104954 Title: CVE-2012-5484: ipa-client security

[Freeipa] [Bug 1104954] Re: CVE-2012-5484: ipa-client security vunerability

2013-02-10 Thread Timo Aaltonen
I've pushed a new version of the package to raring and the freeipa ppa (precise): https://launchpad.net/~freeipa/+archive/ppa please test ** Changed in: freeipa (Ubuntu Precise) Importance: Undecided = Medium ** Changed in: freeipa (Ubuntu Precise) Status: New = In Progress -- You

[Freeipa] [Bug 1024765] Re: ipa-client-install failes at certutil stage because /etc/pki doesn't exist

2013-02-20 Thread Timo Aaltonen
uploaded a new nss to the freeipa ppa that adds support for nssdb: https://launchpad.net/~freeipa/+archive/ppa only for precise, guess that's what people are testing with.. so please test if it works with ipa-client-install. ** Changed in: nss (Ubuntu) Status: In Progress = Incomplete

[Freeipa] [Bug 1025765] Re: pam-auth-update call is missing from platform/debian.py

2013-03-07 Thread Timo Aaltonen
the other bug has been fixed in sssd, closing this as invalid since I don't think it makes sense for freeipa to run pam-auth-update. ** Changed in: freeipa (Ubuntu) Status: Incomplete = Invalid -- You received this bug notification because you are a member of FreeIPA, which is subscribed

[Freeipa] [Bug 997990] Re: fail joining to a freeipa server with ipa-client-install

2013-05-22 Thread Timo Aaltonen
Please try with current updates, gnutls26 in particular has received updates that might have fixed this in the process, and I can't reproduce this on raring. ** Changed in: freeipa (Ubuntu) Status: Confirmed = Incomplete -- You received this bug notification because you are a member of

[Freeipa] [Bug 1282818] Re: 14.04 freeipa ipa-client-install fails

2014-04-04 Thread Timo Aaltonen
nah that's fine, I'll fix that too! and yes I think mkhomedir was the motivation to keep it but disabled, can't remember anymore -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1282818 Title:

[Freeipa] [Bug 1282818] Re: 14.04 freeipa ipa-client-install fails

2014-04-04 Thread Timo Aaltonen
ok that's reassuring to hear, maybe something wrong on my side then.. -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1282818 Title: 14.04 freeipa ipa-client-install fails Status in “freeipa”

[Freeipa] [Bug 1282818] Re: 14.04 freeipa ipa-client-install fails

2014-04-10 Thread Timo Aaltonen
also, mkhomedir can't be Default like on your example config, so https://bugs.launchpad.net/ubuntu/+source/pam/+bug/1192719 needs to be fixed before --mkhomedir option works -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu.

[Freeipa] [Bug 1287428] Re: apt-get install freeipa-client partially runs installer

2014-04-14 Thread Timo Aaltonen
the default conf has been dropped from the package ** Changed in: freeipa (Ubuntu) Status: New = Fix Released -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1287428 Title: apt-get

[Freeipa] [Bug 1309655] Re: freeipa-client-install points to wrong ntp.conf file

2014-04-19 Thread Timo Aaltonen
= Triaged ** Changed in: freeipa (Ubuntu) Assignee: (unassigned) = Timo Aaltonen (tjaalton) -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1309655 Title: freeipa-client-install points to wrong

[Freeipa] [Bug 1336869] Re: mkhomedir option not working on ipa-client-install

2014-07-03 Thread Timo Aaltonen
yes, see https://bugs.launchpad.net/ubuntu/+source/pam/+bug/557013 (fixed in utopic) https://bugs.launchpad.net/ubuntu/+source/pam/+bug/1192719 ** Changed in: freeipa (Ubuntu) Importance: Undecided = Medium ** Changed in: freeipa (Ubuntu) Status: New = Triaged -- You received this

[Freeipa] [Bug 1309655] Re: freeipa-client-install points to wrong ntp.conf file

2014-08-05 Thread Timo Aaltonen
soon is relative, but it's fixed on utopic now, next is filing the paperwork for trusty SRU ** Also affects: freeipa (Ubuntu Trusty) Importance: Undecided Status: New ** Changed in: freeipa (Ubuntu Trusty) Status: New = In Progress -- You received this bug notification because

[Freeipa] [Bug 1309655] Re: freeipa-client-install points to wrong ntp.conf file

2014-08-06 Thread Timo Aaltonen
** Description changed: - On a fresh 14.04-server install freeipa-client-install does not write to - the correct ntpd conf file. Using + [Impact] + On a fresh 14.04-server install freeipa-client-install does not write to the correct ntpd conf file. Also, it needs --force-ntpd option to overcome

[Freeipa] FreeIPA 4.0.4 now in Debian unstable!

2014-10-26 Thread Timo Aaltonen
Hi! Sooo.. as a followup to last weeks announcement about Dogtag 10.2 getting in Debian, today marks the day that FreeIPA finally made it to the distro! And unless release critical bugs are found it'll migrate to the testing branch after spending 10 days on unstable, just in time

[Freeipa] [Bug 1446874] Re: FreeIPA 4.0.5 on Trusty

2015-04-23 Thread Timo Aaltonen
yes, uploaded a package which only builds the client -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1446874 Title: FreeIPA 4.0.5 on Trusty Status in freeipa package in Ubuntu: Won't Fix

[Freeipa] [Bug 1492219] Re: ipa-client-install crashes when /usr/bin/nsupdate isn't installed

2015-09-04 Thread Timo Aaltonen
that's weird, since freeipa-client already depends on dnsutils which provides nsupdate.. ** Changed in: freeipa (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu.

[Freeipa] [Bug 1449304] Re: ipa-replica-prepare fails

2015-09-24 Thread Timo Aaltonen
changed the title, gpg-agent addition is handled in bug 1492184 FYI, it'll be 4.3 that should support replica installation with GSSAPI ** Summary changed: - ipa-replica-prepare fails due to gnupg-agent missing + ipa-replica-prepare fails ** Changed in: freeipa (Ubuntu) Importance: Undecided

[Freeipa] [Bug 1449304] Re: ipa-replica-prepare fails

2015-12-19 Thread Timo Aaltonen
still needs bind 9.10.x in order to get past 4.1 -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1449304 Title: ipa-replica-prepare fails Status in freeipa package in Ubuntu: Triaged Status

[Freeipa] [Bug 1543230] Re: After installing freeipa-server-trust-ad ipa tries to start smb.service which doesn't exist

2016-03-02 Thread Timo Aaltonen
https://fedorahosted.org/freeipa/ticket/5687 ** Bug watch added: fedorahosted.org/freeipa/ #5687 https://fedorahosted.org/freeipa/ticket/5687 -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu.

[Freeipa] Ubuntu 16.04 released with FreeIPA 4.3.1

2016-04-21 Thread Timo Aaltonen
Howdy! Ubuntu 16.04 LTS got released today, and it comes with FreeIPA 4.3.1! The biggest feature of this version is that it also supports replication by client promotion to replica master. IPA on Debian/Ubuntu has been a single-master thing until now.. FreeIPA is in the

[Freeipa] [Bug 1509484] Re: certmonger processes turn into zombies on start

2016-04-18 Thread Timo Aaltonen
What does 'getcert list-cas' say? I guess the zombies were due to ipa- client-install bugs or such, and could be you need to fix things manually... -- You received this bug notification because you are a member of FreeIPA, which is subscribed to certmonger in Ubuntu.

Re: [Freeipa] Missing armhf python-ipalib

2016-04-19 Thread Timo Aaltonen
19.04.2016, 14:41, Nicklas Björk kirjoitti: > On 2016-04-19 12:15, Timo Aaltonen wrote: >> 19.04.2016, 11:28, Nicklas Björk kirjoitti: >>> Hi FreeIPA team, >>> >>> I was experimenting with the armhf packages, trying to get the FreeIPA >>> cli

[Freeipa] [Bug 1509484] Re: certmonger processes turn into zombies on start

2016-04-18 Thread Timo Aaltonen
this should be fixed in xenial.. ** Changed in: certmonger (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of FreeIPA, which is subscribed to certmonger in Ubuntu. https://bugs.launchpad.net/bugs/1509484 Title: certmonger

[Freeipa] [Bug 1600634] Re: ipa-server-install: On non-x86, errors enabling compatibility plugin for dirsrv

2016-07-11 Thread Timo Aaltonen
right, it was expected that sooner or later someone used 389 on !x86 :/ the libarch patch should cover all the others too ** Also affects: 389-ds-base (Ubuntu) Importance: Undecided Status: New ** Changed in: 389-ds-base (Ubuntu) Status: New => Triaged -- You received this

[Freeipa] [Bug 1664453] Re: autopkgtests failing with systemd-232

2017-02-14 Thread Timo Aaltonen
it has no chance of working before tomcat 8.5 is purged from proposed(*), so I'd hold on making any changes before that happens * https://bugs.launchpad.net/bugs/1662654 -- You received this bug notification because you are a member of FreeIPA, which is subscribed to dogtag-pki in Ubuntu.

[Freeipa] [Bug 1657134] Re: ipa-replica-install fails: "an internal error has occurred" on Remote master - DBusException: org.freedesktop.DBus.Error.ServiceUnknown: The name org.freeipa.server was not

2017-01-17 Thread Timo Aaltonen
I see that the rpm packages reload these on postinst, so that needs to be done here too.. ** Changed in: freeipa (Ubuntu) Status: Incomplete => Triaged -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu.

[Freeipa] [Bug 1657134] Re: ipa-replica-install fails: "an internal error has occurred" on Remote master - DBusException: org.freedesktop.DBus.Error.ServiceUnknown: The name org.freeipa.server was not

2017-01-19 Thread Timo Aaltonen
this is actually better handled in oddjob by adding a dpkg trigger to reload the daemon when config files are installed in /etc/oddjobd.conf.d ** Package changed: freeipa (Ubuntu) => oddjob (Ubuntu) -- You received this bug notification because you are a member of FreeIPA, which is subscribed

Re: [Freeipa] [Freeipa-users] Ubuntu 16.04 released with FreeIPA 4.3.1

2016-08-30 Thread Timo Aaltonen
On 29.08.2016 10:34, Timo Aaltonen wrote: > On 21.04.2016 22:01, Timo Aaltonen wrote: >> >> ps. Debian unstable will have 4.3.1 once the package has gone through >> the NEW queue because the packaging got split in certain ways > > No it did not, because the ftpmaste

[Freeipa] [Bug 1600634] Re: ipa-server-install: On non-x86, errors enabling compatibility plugin for dirsrv

2016-09-23 Thread Timo Aaltonen
file a new bug -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1600634 Title: ipa-server-install: On non-x86, errors enabling compatibility plugin for dirsrv Status in 389-ds-base package

[Freeipa] [Bug 1628884] Re: ipa-otpd@1-32385-0.service: Failed at step EXEC spawning /usr/lib/ipa-otpd: No such file or directory

2016-09-29 Thread Timo Aaltonen
** Changed in: freeipa (Ubuntu) Status: New => Triaged -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1628884 Title: ipa-otpd@1-32385-0.service: Failed at step EXEC spawning

[Freeipa] [Bug 1627371] Re: Timing problems with FreeIPA installation

2016-09-25 Thread Timo Aaltonen
this is likely caused by tomcat instances using initd rather than systemd I'm not sure about adding timeouts to freeipa for this, because RPi doesn't have much RAM either.. the VM's that I've used for testing have all had at least 1.5GB ** Also affects: dogtag-pki (Ubuntu) Importance:

Re: [Freeipa] help

2016-11-07 Thread Timo Aaltonen
On 08.11.2016 09:38, 郑磊 wrote: > I see. But my work environment is Ubuntu and available version of > freeipa is 4.3.x. I want to maintain freeipa on the Ubuntu system. I > have already applied to join the freeipa@lists.launchpad.net team in > https://launchpad.net/~freeipa/+members#proposed,

Re: [Freeipa] help

2016-11-07 Thread Timo Aaltonen
On 07.11.2016 03:24, 郑磊 wrote: > Hello Everyone, > I'm using FreeIPA on Ubuntu, and having a test and research with the > function of FreeIPA. At the same time, I have carried on the Chinese > translation to the web interface, also added own log module in web > interface, which can record our

Re: [Freeipa] Help removing me from this list

2016-11-08 Thread Timo Aaltonen
On 08.11.2016 12:14, Adilson Oliveira wrote: > Hello > > I no longer have a launchpad account but I am still receiving emails > from this list. Does anyone have the means to remove me from it? https://launchpad.net/~agoliveira seems to be doing well, so you just need to revive the password? I

[Freeipa] [Bug 1645201] Re: ipa-client-automount fails

2016-11-28 Thread Timo Aaltonen
yeah, service mapping was wrong on ipaplatform/debian/services.py ** Changed in: freeipa (Ubuntu) Status: New => In Progress -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1645201

[Freeipa] [Bug 1336869] Re: mkhomedir option not working on ipa-client-install

2016-10-10 Thread Timo Aaltonen
feel free to help with 1192719 -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1336869 Title: mkhomedir option not working on ipa-client-install Status in freeipa package in Ubuntu: Triaged

[Freeipa] [Bug 1656236] Re: OpenSans TTF fonts missing

2017-01-14 Thread Timo Aaltonen
right, but the ui still works with the fallback font so it's harmless ** Changed in: freeipa (Ubuntu) Importance: Undecided => Wishlist ** Changed in: freeipa (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of FreeIPA, which is

[Freeipa] [Bug 1630911] Re: freeipa-client has a hard dependency on "ntp" which is not wanted in lxd environment

2017-01-14 Thread Timo Aaltonen
client install expects ntpd to be present upstream is discussing whether ntp should be configured at all, since it's usually already configured by the distro -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu.

[Freeipa] [Bug 1640732] Re: krb5-otp package not being installed when ipa-server-install

2017-01-14 Thread Timo Aaltonen
** Changed in: freeipa (Ubuntu) Status: New => Fix Committed -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1640732 Title: krb5-otp package not being installed when ipa-server-install

[Freeipa] [Bug 1643244] Re: --mkhomedir seems to not work (through oddjob) in 16.04

2017-01-14 Thread Timo Aaltonen
*** This bug is a duplicate of bug 1336869 *** https://bugs.launchpad.net/bugs/1336869 ** This bug has been marked a duplicate of bug 1336869 mkhomedir option not working on ipa-client-install -- You received this bug notification because you are a member of FreeIPA, which is subscribed

[Freeipa] [Bug 1630911] Re: freeipa-client has a hard dependency on "ntp" which is not wanted in lxd environment

2017-01-14 Thread Timo Aaltonen
alright, so it does install even without.. anyway, it's a no-brainer to demote as Recommends so I'll just do that -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1630911 Title: freeipa-client

[Freeipa] [Bug 1653245] Re: python-ipalib is missing authconfig

2017-01-12 Thread Timo Aaltonen
that's the one, and here's the commit https://anonscm.debian.org/git/pkg-freeipa/freeipa.git/commit/?h=master- next=d1b501999f999df5b7b3b5574e820a1e57c8281e -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu.

[Freeipa] [Bug 1653245] Re: python-ipalib is missing authconfig

2016-12-30 Thread Timo Aaltonen
this is fixed in git ** Changed in: freeipa (Ubuntu) Status: New => Fix Committed -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1653245 Title: python-ipalib is missing authconfig

[Freeipa] [Bug 1677139] Re: pkcs11 setup needs fixes for SoftHSM 2.2

2017-04-19 Thread Timo Aaltonen
** Summary changed: - softhsm 2.2.0 is broken + pkcs11 setup needs fixes for SoftHSM 2.2 ** Description changed: - The current version of softhsm in zesty, 2.2.0, is broken: + [Impact] - https://github.com/opendnssec/SoftHSMv2/issues/298 + https://pagure.io/freeipa/issue/6692 - even basic

[Freeipa] [Bug 1635568] Re: freeipa-client - Can't enroll a client if server has external CA certs in addition to self signed CA cert

2017-03-07 Thread Timo Aaltonen
if you have /etc/ipa/ca.crt, try removing it and ipa-client-install again -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1635568 Title: freeipa-client - Can't enroll a client if server has

[Freeipa] [Bug 1677139] Re: softhsm 2.2.0 is broken

2017-04-19 Thread Timo Aaltonen
the patch for freeipa works ** Package changed: softhsm2 (Ubuntu) => freeipa (Ubuntu) -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1677139 Title: pkcs11 setup needs fixes for SoftHSM 2.2

[Freeipa] [Bug 1677139] Re: pkcs11 setup needs fixes for SoftHSM 2.2

2017-04-21 Thread Timo Aaltonen
yes that's another bug: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860722 ** Bug watch added: Debian Bug tracker #860722 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860722 -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa

[Freeipa] [Bug 1693154] Re: ipa-client-install fails: kinit: Included profile directory could not be read while initializing Kerberos 5 library

2017-05-24 Thread Timo Aaltonen
the client install creates /etc/krb5.conf with "includedir /etc/krb5.conf.d/" while creating that directory should be done by krb5-config, it was fixed in sid/artful by freeipa-client 4.4.4-1. mit-krb5 will add the directory after stretch is released SRU for zesty would be in order, though **

[Freeipa] [Bug 1691655] Re: pki-base postinst creates corrupt /etc/pki/pki.version

2017-05-18 Thread Timo Aaltonen
Now that 10.3.5+12-4 is synced, yes. But I heard about another upgrade bug which I'll check first, and reupload this along with other fixes if needed. -- You received this bug notification because you are a member of FreeIPA, which is subscribed to dogtag-pki in Ubuntu.

[Freeipa] [Bug 1685115] Re: opendnssec 2.0 broke FreeIPA DNSSEC setup

2017-06-10 Thread Timo Aaltonen
I'll monitor this issue ** Changed in: freeipa (Ubuntu Artful) Assignee: Dimitri John Ledkov (xnox) => Timo Aaltonen (tjaalton) -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1685

[Freeipa] [Bug 1677139] Re: pkcs11 setup needs fixes for SoftHSM 2.2

2017-06-10 Thread Timo Aaltonen
I'll deal with this ** Changed in: freeipa (Ubuntu Artful) Assignee: Dimitri John Ledkov (xnox) => Timo Aaltonen (tjaalton) -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1677139 Ti

[Freeipa] [Bug 1693154] Re: ipa-client-install fails: kinit: Included profile directory could not be read while initializing Kerberos 5 library

2017-06-14 Thread Timo Aaltonen
resent (probably fresh install) ** Changed in: freeipa (Ubuntu Zesty) Status: New => In Progress ** Changed in: freeipa (Ubuntu Zesty) Assignee: (unassigned) => Timo Aaltonen (tjaalton) -- You received this bug notification because you are a member of FreeIPA, which is su

[Freeipa] [Bug 1716842] Re: dogtag-pki needs porting work for tomcat8

2017-09-20 Thread Timo Aaltonen
It built against old tomcat 8.0.x, but tomcat 8.5 got synced and dogtag (& tomcatjss) fail to build with it. I've packaged tomcat8.0 as a separate source package and it's in the archive now. Next I'll modify tomcatjss & dogtag-pki to use it. Tomcat8.0 will be removed before 18.04 releases, which

[Freeipa] [Bug 1706872] Re: FreeIPA Client on Ubuntu 14.04 can't be enrolled to IPA Server having third party SSL

2017-09-21 Thread Timo Aaltonen
yeah 3.3.4 in 14.04 is old by today's standard.. I don't support that anymore, so either backport the client from 16.04 or upgrade to it.. closing as fixed since it's working in 16.04 ** Changed in: freeipa (Ubuntu) Status: New => Fix Released -- You received this bug notification

[Freeipa] [Bug 1656236] Re: OpenSans TTF fonts missing

2017-09-21 Thread Timo Aaltonen
looks like fonts-open-sans is now included in debian, I'll add a dep to freeipa -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1656236 Title: OpenSans TTF fonts missing Status in freeipa

[Freeipa] [Bug 1703836] Re: ipa-dnskeysyncd expects XML ods-enforcer no longer outputs xml

2017-10-09 Thread Timo Aaltonen
artful has 2.1.3 ** Changed in: opendnssec (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1703836 Title: ipa-dnskeysyncd expects XML ods-enforcer

[Freeipa] [Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl

2018-05-07 Thread Timo Aaltonen
I mean the dns setup is known to be broken, I don't know why it gets an empty zone from ldap and reported it upstream but the next step would be to debug with gdb and I didn't get anywhere with it yet.. -- You received this bug notification because you are a member of FreeIPA, which is

[Freeipa] [Bug 1769631] Re: freeipa-server installation/configuration problem on s390x

2018-05-07 Thread Timo Aaltonen
what do you have in /usr/lib/s390x-linux-gnu/sasl2 ? -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1769631 Title: freeipa-server installation/configuration problem on s390x Status in Ubuntu

[Freeipa] [Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl

2018-05-08 Thread Timo Aaltonen
you need to prime it with the environment: SOFTHSM2_CONF=/etc/ipa/dnssec/softhsm2.conf KRB5_KTNAME=/etc/bind/named.keytab gdb --args named-pkcs11 -g -u bind then the problem is that there are no debug symbols for named-pkcs11, not even in bind9-dbgsym and I've no idea why.. -- You received

[Freeipa] [Bug 1765616] Re: freeipa server install fails - RuntimeError: CA configuration failed.

2018-04-27 Thread Timo Aaltonen
** Changed in: freeipa (Ubuntu) Status: Incomplete => Invalid -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1765616 Title: freeipa server install fails - RuntimeError: CA

[Freeipa] [Bug 1765616] Re: freeipa server install fails - RuntimeError: CA configuration failed.

2018-05-08 Thread Timo Aaltonen
no, a task for bionic is open and a version still waiting in proposed, it just needs to be fixed in the devel series first -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1765616 Title:

[Freeipa] [Bug 1765616] Re: freeipa server install fails - RuntimeError: CA configuration failed.

2018-05-08 Thread Timo Aaltonen
..waiting on the queue, not in proposed yet -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1765616 Title: freeipa server install fails - RuntimeError: CA configuration failed. Status in

[Freeipa] [Bug 1769631] Re: freeipa-server installation/configuration problem on s390x

2018-05-08 Thread Timo Aaltonen
ok that looks normal, and 389 should do the right thing now but something is still missing and I don't know what.. but the bug isn't in freeipa itself so moving it over to 389 for now if you have a way to test SASL/GSSAPI on the architecture that'd be good ** Package changed: freeipa (Ubuntu) =>

[Freeipa] [Bug 1765616] Re: tomcat more or less broken -- java compat issues

2018-05-08 Thread Timo Aaltonen
** Summary changed: - freeipa server install fails - RuntimeError: CA configuration failed. + tomcat more or less broken -- java compat issues ** No longer affects: freeipa (Ubuntu Bionic) ** No longer affects: freeipa (Ubuntu) -- You received this bug notification because you are a member

[Freeipa] [Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl

2018-05-08 Thread Timo Aaltonen
lucky you Reading symbols from /usr/sbin/named-pkcs11...(no debugging symbols found)...done. I have all the dbgsym packages installed.. -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1769440

[Freeipa] [Bug 1765616] Re: freeipa server install fails - RuntimeError: CA configuration failed.

2018-05-05 Thread Timo Aaltonen
the restarts are caused by certmonger requests.. I've added a (very gross) 'sleep 80' to that stage which at least made it pass reliably on my qemu host, but looks like that's not enough. I'll ask upstream why it creates so many requests these days.. -- You received this bug notification because

[Freeipa] [Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl

2018-05-06 Thread Timo Aaltonen
must be a race condition again, I can't reproduce it here -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1769440 Title: freeipa server install fails - Configuring the web interface, setting

[Freeipa] [Bug 1772205] Re: freeipa install does not correctly setup krb5-admin-server

2018-05-20 Thread Timo Aaltonen
ok, turns out this was filed against the debian package two years ago, by me: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=819017 we'll see what the outcome is ** Bug watch added: Debian Bug tracker #819017 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=819017 -- You received this

[Freeipa] [Bug 1772205] Re: freeipa install does not correctly setup krb5-admin-server

2018-05-20 Thread Timo Aaltonen
indeed, I'll comment that part of the admin conf template out.. it should start after that? ** Changed in: freeipa (Ubuntu) Status: New => Confirmed ** Changed in: freeipa (Ubuntu) Assignee: (unassigned) => Timo Aaltonen (tjaalton) -- You received this bug notification becau

[Freeipa] [Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl

2018-05-20 Thread Timo Aaltonen
interesting, maybe there's something wrong with bind9 build.. -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1769440 Title: freeipa server install fails - Configuring the web interface,

[Freeipa] [Bug 1772405] Re: freeipa dns install does not correctly configure reverse zones due to systemd-resolved

2018-05-21 Thread Timo Aaltonen
Fedora doesn't enable systemd-resolved, which is probably why this hasn't been hit before. It was proposed but apparently shot down. ** Also affects: systemd (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of FreeIPA, which is

[Freeipa] [Bug 1772411] Re: opendnssec-common has an invalid config file

2018-05-21 Thread Timo Aaltonen
wrong package ** Package changed: freeipa (Ubuntu) => opendnssec (Ubuntu) -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772411 Title: opendnssec-common has an invalid config file Status

[Freeipa] [Bug 1772447] Re: freeipa installation - directory /var/lib/krb5kdc is not accessible by Apache

2018-05-21 Thread Timo Aaltonen
ok, it's rpcserver.py.. probably need to put these in /var/lib/ipa/certs -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772447 Title: freeipa installation - directory /var/lib/krb5kdc is not

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-21 Thread Timo Aaltonen
dogtag 10.6.1 is uploaded to https://launchpad.net/~freeipa/+archive/ubuntu/staging now, not built yet -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772450 Title: freeipa server -- problems

[Freeipa] [Bug 1772921] Re: freeipa web ui -- incorrect configuration for awesome fonts

2018-05-23 Thread Timo Aaltonen
oh man.. fixed in ~ppa2 -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772921 Title: freeipa web ui -- incorrect configuration for awesome fonts Status in freeipa package in Ubuntu: In

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-23 Thread Timo Aaltonen
and a new dogtag to depend on it and add the necessary links -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772450 Title: freeipa server -- problems with certificates Status in freeipa

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-23 Thread Timo Aaltonen
interesting.. I'll push libjboss-annotations-1.2-api-java to the staging ppa to see how far you get with it -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772450 Title: freeipa server --

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-23 Thread Timo Aaltonen
it's getting invalid xml from somewhere.. -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772450 Title: freeipa server -- problems with certificates Status in freeipa package in Ubuntu:

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-23 Thread Timo Aaltonen
adding debug=true to /etc/ipa/default.conf and restarting apache gives debug output in apache error.log, and looks like it gets gzipped data from dogtag (which is fine) but somehow either the header is missing or it can't deflate it. -- You received this bug notification because you are a member

[Freeipa] [Bug 1772745] [NEW] Dogtag needs jboss-annotations-1.2-api

2018-05-22 Thread Timo Aaltonen
Public bug reported: [Impact] Dogtag needs this jar or running for instance 'pki cert-find' will end with WARN: RESTEASY002145: NoClassDefFoundError: Unable to load builtin provider org.jboss.resteasy.plugins.providers.InputStreamProvider from

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-24 Thread Timo Aaltonen
It's related to mod_deflate somehow, probably missing some configuration. Dropping "'Accept-Encoding': 'gzip, deflate'," from plugins/dogtag.py works around this issue, but is not the solution. -- You received this bug notification because you are a member of FreeIPA, which is subscribed to

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-24 Thread Timo Aaltonen
note that on Fedora dogtag/tomcat does not return gzipped data although it's accepted on the ipa side, so could be that this bug would manifest there too in the same situation -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu.

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-24 Thread Timo Aaltonen
after disabling mod_deflate it works, but since it's an essential module it's probably best to just patch plugins/dogtag.py for now. -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772450

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-24 Thread Timo Aaltonen
~ppa3 on the way to the ppa -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772450 Title: freeipa server -- problems with certificates Status in freeipa package in Ubuntu: Confirmed Bug

[Freeipa] [Bug 1772205] Re: freeipa install does not correctly setup krb5-admin-server

2018-05-23 Thread Timo Aaltonen
fixed in git ** Changed in: freeipa (Ubuntu) Importance: Undecided => High ** Changed in: freeipa (Ubuntu) Status: Confirmed => In Progress -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu.

[Freeipa] [Bug 1772447] Re: freeipa installation - directory /var/lib/krb5kdc is not accessible by Apache

2018-05-23 Thread Timo Aaltonen
fixed in git ** Changed in: freeipa (Ubuntu) Importance: Undecided => High ** Changed in: freeipa (Ubuntu) Status: New => In Progress -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu.

[Freeipa] [Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl

2018-05-23 Thread Timo Aaltonen
no, bind9 needs to be fixed instead, the way it's build got revamped in 9.11.3+dfsg-1 and I believe that's what broke it.. ** Also affects: bind9 (Ubuntu) Importance: Undecided Status: New ** Changed in: bind9 (Ubuntu) Status: New => Triaged ** Summary changed: - freeipa

[Freeipa] [Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run

2018-05-23 Thread Timo Aaltonen
** Changed in: freeipa (Ubuntu) Importance: Undecided => High -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1769440 Title: freeipa server install fails - named-pkcs11 fails to run Status

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-23 Thread Timo Aaltonen
pre2 uploaded to ppa:freeipa/staging I also uploaded tomcat8 there with a fixed (lower) version than what's in the updates ppa.. will take a while until these have been built -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu.

[Freeipa] [Bug 1772205] Re: freeipa install does not correctly setup krb5-admin-server

2018-05-23 Thread Timo Aaltonen
** Changed in: freeipa (Ubuntu) Assignee: Timo Aaltonen (tjaalton) => (unassigned) -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772205 Title: freeipa install does not correctly se

[Freeipa] [Bug 1769485] Re: freeipa install server fails - cannot start apache server with SSL

2018-05-21 Thread Timo Aaltonen
if you edit ipa-httpd-pwdreader to set HOSTNAME=`hostname -f` before it's called, does it work? -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1769485 Title: freeipa install server fails -

  1   2   3   >