[Freeipa-devel] Re: [DRAFT] FreeIPA 4.10.2 Release Notes

2023-04-21 Thread Florence Blanc-Renaud via FreeIPA-devel
Hi Antonio, thanks for the draft. I would move 9298 into the Known issues section. Thanks, flo On Thu, Apr 20, 2023 at 2:30 PM Antonio Torres via FreeIPA-devel < freeipa-devel@lists.fedorahosted.org> wrote: > FreeIPA 4.10.2 release notes draft: >

[Freeipa-devel] Re: [DRAFT] FreeIPA 4.9.12 Release Notes

2023-04-20 Thread Florence Blanc-Renaud via FreeIPA-devel
Hi Antonio, thanks for the draft. I would put the doc related to ticket 9298: *[Tracker] Nightly test failure (updates-testing) in test_acme.py::TestACME::test_certbot_certonly_standalone* in the known issues section. A few tickets are listed as solved but are not (the commits either marked the

[Freeipa-devel] Re: ipa radius proxy

2022-12-20 Thread Florence Blanc-Renaud via FreeIPA-devel
Hi, On Tue, Nov 22, 2022 at 3:34 PM Giuseppe Calo via FreeIPA-devel < freeipa-devel@lists.fedorahosted.org> wrote: > Thanks Alexander, > these are the steps I applied --> > ** > on Radius server: > [root@radius ~]# yum install freeradius freeradius-utils

[Freeipa-devel] Re: additional info: nsslapd-maxdescriptors: invalid value "65536", maximum file descriptors must range from 1 to 8192 (the current process limit). Server will use a setting of 8192.

2022-12-14 Thread Florence Blanc-Renaud via FreeIPA-devel
Hi, On Wed, Dec 14, 2022 at 10:35 AM roy liang via FreeIPA-devel < freeipa-devel@lists.fedorahosted.org> wrote: > my freeipa 4.3 > May I ask, this parameter cannot be increased, this limit refers to where > the limit?Can the system see if it can reach 262140, or is there another > configuration

[Freeipa-devel] Re: [DRAFT] FreeIPA 4.10.1 Release Notes

2022-11-04 Thread Florence Blanc-Renaud via FreeIPA-devel
Hi Antonio, Same comment as for the 4.9.11 RN, many issues are picked by the automation probably because they are mentioned with Related instead of Fixes in the commit msg. Please find my comments below. On Thu, Nov 3, 2022 at 12:04 PM Antonio Torres via FreeIPA-devel <

[Freeipa-devel] Re: FreeIPA Client does not update user info

2022-08-11 Thread Florence Blanc-Renaud via FreeIPA-devel
Hi, On Thu, Aug 11, 2022 at 10:38 AM Lucas Blom via FreeIPA-devel < freeipa-devel@lists.fedorahosted.org> wrote: > Hello, > > I'am a new FreeIPA user and most things are working fine, Welcome to the community! For troubleshooting or help requests, the mailing list freeipa-users

[Freeipa-devel] Re: Preparing for FreeIPA 4.9.0 release candidate

2020-12-01 Thread Florence Blanc-Renaud via FreeIPA-devel
On 11/27/20 12:12 PM, Alexander Bokovoy via FreeIPA-devel wrote: On ke, 18 marras 2020, Alexander Bokovoy via FreeIPA-devel wrote: On ma, 16 marras 2020, Alexander Bokovoy via FreeIPA-devel wrote: On pe, 13 marras 2020, Alexander Bokovoy via FreeIPA-devel wrote: On ke, 11 marras 2020,

[Freeipa-devel] Re: Preparing for freeipa 4.8.5

2020-03-16 Thread Florence Blanc-Renaud via FreeIPA-devel
Hi, thanks for the RNs. We should also mention: - New "ipa-cacert-manage delete" command. The command allows to remove a CA from IPA. flo On 3/14/20 10:06 AM, Alexander Bokovoy via FreeIPA-devel wrote: Hi, with almost all pieces of the tomcat 9.0.31 and openDNSSEC 2.1 puzzle in place, it is

[Freeipa-devel] Re: [Draft] 4.8.2 release notes

2019-11-11 Thread Florence Blanc-Renaud via FreeIPA-devel
LGTM, flo On 11/11/19 2:50 PM, Rob Crittenden via FreeIPA-devel wrote: Alexander Bokovoy via FreeIPA-devel wrote: Hi, below is the draft for the release notes for upcoming FreeIPA 4.8.2 release. I'm intending to release it tomorrow, so please add your comments today. Looks good. rob

[Freeipa-devel] Re: Choosing DNS name for FreeIPA PR-CI, proposing ci.freeipa.org

2019-10-14 Thread Florence Blanc-Renaud via FreeIPA-devel
On 10/14/19 10:40 AM, Petr Vobornik via FreeIPA-devel wrote: Hi list, we'll be migrating a FreeIPA wiki and planet to a different OpenShift. With that FreeIPA PR-CI dashboard which is currently running at URL https://pr-ci-dashboard-freeipa.b9ad.pro-us-east-1.openshiftapps.com will be migrated

[Freeipa-devel] New labels for Nightly tests

2019-06-24 Thread Florence Blanc-Renaud via FreeIPA-devel
Hi, 2 new labels have been added to the list of possible PR labels [1] on the freeipa repository stored in github. They are used for the nightly PRs. CI-infra issue -- added when the nightly PR tests failed because of an infrastructure issue (for instance "Failed to publish

[Freeipa-devel] Nightly tests are Green on master!

2019-04-02 Thread Florence Blanc-Renaud via FreeIPA-devel
Hi, today we reached an important milestone. Maybe you didn't notice but the nightly tests on the master branch are all GREEN today! https://github.com/freeipa/freeipa/pull/2980 A big thank you to all FreeIPA developers for their hard work, and let's make sure to keep 100% test success. flo

[Freeipa-devel] Re: [DESIGN] IPA healthcheck design

2018-12-03 Thread Florence Blanc-Renaud via FreeIPA-devel
On 11/27/18 3:03 PM, Rob Crittenden via FreeIPA-devel wrote: Florence Blanc-Renaud wrote: On 10/24/18 10:49 PM, Rob Crittenden via FreeIPA-devel wrote: I started a design of an IPA healthcheck framework at https://www.freeipa.org/page/V4/Healthcheck Have at it. Note that this concentrates

[Freeipa-devel] Re: [DESIGN] IPA healthcheck design

2018-11-27 Thread Florence Blanc-Renaud via FreeIPA-devel
On 10/24/18 10:49 PM, Rob Crittenden via FreeIPA-devel wrote: I started a design of an IPA healthcheck framework at https://www.freeipa.org/page/V4/Healthcheck Have at it. Note that this concentrates more on how it will work big picture and less on individual checks that may be performed. I'm

[Freeipa-devel] Re: vault implementation vs ACI to read ipaconfigstring

2018-11-14 Thread Florence Blanc-Renaud via FreeIPA-devel
On 11/13/18 10:20 PM, Rob Crittenden via FreeIPA-devel wrote: Petr Vobornik via FreeIPA-devel wrote: On Mon, Nov 12, 2018 at 6:28 PM François Cami via FreeIPA-devel wrote: Hi, While investigating why non-admin users having access to a shared vault got an error that stemmed from them not

[Freeipa-devel] Gating and nightly tests

2018-11-09 Thread Florence Blanc-Renaud via FreeIPA-devel
Hi Developers, Currently our test suite contains 3 different test sets: - gating: executed on each pull request - nightly_master: executed monday, wednesday, friday - nightly_rawhide: not executed Some tests are part of both gating and nightly, but that is an exception. The majority of gating

[Freeipa-devel] Re: Font Awesome icon

2018-11-08 Thread Florence Blanc-Renaud via FreeIPA-devel
Looks good to me. flo On 11/5/18 12:51 PM, Serhii Tsymbaliuk via FreeIPA-devel wrote: Hello, I'm going to create an issue for Font Awesome project to include our icon to the their collection (https://github.com/FortAwesome/Font-Awesome/issues). This two icons will be attached to this issue.

[Freeipa-devel] Re: ipa-replica-install failed with CA_UNREACHABLE -

2018-09-05 Thread Florence Blanc-Renaud via FreeIPA-devel
On 09/05/2018 12:41 PM, Ilie Soltanici via FreeIPA-devel wrote: Hi All, Trying to install a replica for an already running ipa-server but it fails. IPA Main server is already running and properly configured. I'm trying to setup the second server and replicate with the main server. This is the

[Freeipa-devel] Re: [Design draft] Promoting replica to CRL master

2018-06-08 Thread Florence Blanc-Renaud via FreeIPA-devel
On 06/08/2018 10:01 AM, Standa Laznicka via FreeIPA-devel wrote: Flo, thank you for your invaluable comments. I originally did not notice that there was a design draft page for this feature already. Since we all seem to be in agreement about the design I proposed, I updated the original page

[Freeipa-devel] Re: [Design draft] Promoting replica to CRL master

2018-06-07 Thread Florence Blanc-Renaud via FreeIPA-devel
On 06/06/2018 10:24 AM, Standa Laznicka via FreeIPA-devel wrote: Thank you guys for your great comments, I was away for the past few days but you correctly understood all of the motivations of the design and shared them here. I'll add several comments throughout the mails here: On 06/05/2018

[Freeipa-devel] Re: [Design draft] Promoting replica to CRL master

2018-06-05 Thread Florence Blanc-Renaud via FreeIPA-devel
On 06/01/2018 03:08 AM, Fraser Tweedale via FreeIPA-devel wrote: On Thu, May 31, 2018 at 12:10:31PM +0200, Standa Laznicka via FreeIPA-devel wrote: Hello people of the freeipa-devel channel, Let me share a design that proposes a way of automating the way FreeIPA replicas would be promoted to

[Freeipa-devel] Re: Candidate PRs to close

2018-05-04 Thread Florence Blanc-Renaud via FreeIPA-devel
On 05/03/2018 08:59 PM, Rob Crittenden via FreeIPA-devel wrote: There are a lot of old, outdated PRs. I think we need to close them and strive hard to keep the list of PRs very low so for this round, against my usual instincts, I propose we act on the harsher side. Note that I did __not__

[Freeipa-devel] Re: authselect migration

2018-04-24 Thread Florence Blanc-Renaud via FreeIPA-devel
On 04/24/2018 10:55 AM, Alexander Koksharov via FreeIPA-devel wrote: Hello, I would like to test how ipa upgrade to a version which uses authselect instead of authconfig will work. Basic upgrade of a server seems to be working on my test machine. But, I will appreciate if someone can think of

[Freeipa-devel] Re: Realm / Domain change

2018-04-11 Thread Florence Blanc-Renaud via FreeIPA-devel
On 04/11/2018 12:04 AM, RM RM via FreeIPA-devel wrote: Hello, is there a feature to perform a realm / primary domain change? I looked around but couldn't find anything. Given all the complexity with kerberos and other components that would need to be updated, this feature would be really

[Freeipa-devel] Re: Review of authconfig replacement

2018-04-05 Thread Florence Blanc-Renaud via FreeIPA-devel
On 04/04/2018 03:37 PM, Rob Crittenden wrote: Florence Blanc-Renaud via FreeIPA-devel wrote: Hi all, I am currently reviewing the PR for authconfig replacement with authselect (see [1]) but I am not 100% sure of the direction we should aim for (many items were discussed in the mailing list

[Freeipa-devel] Review of authconfig replacement

2018-04-04 Thread Florence Blanc-Renaud via FreeIPA-devel
Hi all, I am currently reviewing the PR for authconfig replacement with authselect (see [1]) but I am not 100% sure of the direction we should aim for (many items were discussed in the mailing list but it's not clear on which an agreement was reached). 1/ Deprecation of --no-sssd option: -

[Freeipa-devel] Re: ipa-replica-install --principal admin --admin-password --setup-ca Traceback

2018-03-13 Thread Florence Blanc-Renaud via FreeIPA-devel
On 03/12/2018 06:09 PM, Amit wrote: Hello Flo, PFA replica-install log. Hi, sorry if I was not clear, but I meant 389-ds access logs, located in /var/log/dirsrv/slapd-DOMxxx/access. The ones from the master and the soon-to-be-replica may provide more information. The customer may also

[Freeipa-devel] Contribute/Code wiki page update

2018-03-12 Thread Florence Blanc-Renaud via FreeIPA-devel
Hi all, I recently updated the Contribute/Code wiki page (https://www.freeipa.org/page/Contribute/Code), especially the sections related to Code Review Process. As developers, we often prefer to deliver code rather than review other people's code, but I really think that the code reviews

[Freeipa-devel] Re: ipa-replica-install --principal admin --admin-password --setup-ca Traceback

2018-03-12 Thread Florence Blanc-Renaud via FreeIPA-devel
On 03/10/2018 12:07 PM, Amit via FreeIPA-devel wrote: Ping!! On 03/09/2018 02:08 PM, Amit wrote: Hello, Any thoughts would be helpful. Thanks On 03/07/2018 02:57 PM, Amit wrote: Hello, This is scenario in customer env. Customer is using fresh machine to install replica. *IPA-Server

[Freeipa-devel] Re: How FreeIPA upstream CI should look like

2018-03-07 Thread Florence Blanc-Renaud via FreeIPA-devel
Hi Petr, thanks for starting this discussion. Please find comments below. On 06/03/2018 20:01, Petr Vobornik via FreeIPA-devel wrote: Hi FreeIPA contributors, first, I apologize for such long mail. in the team, we discuss how upstream CI should look like and what to expect from it. Various

[Freeipa-devel] Re: authconfig replacement design

2018-03-05 Thread Florence Blanc-Renaud via FreeIPA-devel
Hi, re-adding the ML to the thread. On 19/02/2018 10:35, Alexander Koksharov wrote: @Flo, thank you for a comment. I believe that all these commands do use same code in ipaplatform/redhat/tasks.py So, I have to make these tasks execution to be dependant on a tools available. In fact the

[Freeipa-devel] Re: Prerequisites for running 'make fastcheck'

2018-02-28 Thread Florence Blanc-Renaud via FreeIPA-devel
On 02/28/2018 04:36 PM, Christian Heimes via FreeIPA-devel wrote: On 2018-02-28 16:27, Florence Blanc-Renaud via FreeIPA-devel wrote: Hi all, our wiki mentions the new Makefile targets introduced in 4.6.2, namely fasttest fastlint and fastcheck. It is not straightforward to run make fastcheck

[Freeipa-devel] Re: IPA's NTP service

2018-02-26 Thread Florence Blanc-Renaud via FreeIPA-devel
Hi, * During client installation, the installer calls "/usr/bin/timeout ntpd -qgc " in order to synchronize the clock with either a/ one of the servers specified in --ntp-server b/ a NTP server found in the DNS (_ntp._udp in the domain) or c/ the master This command does not configure the NTP

[Freeipa-devel] Re: replica installation without CA

2018-02-20 Thread Florence Blanc-Renaud via FreeIPA-devel
On 02/20/2018 06:05 AM, Amit wrote: Now I am getting this Error: # ipa-replica-install --dirsrv-cert-file /root/rootCA.crt --dirsrv-cert-file /root/dirsrv.crt --dirsrv-cert-file /root/dirsrv.key --dirsrv-pin amit --http-cert-file /root/rootCA.crt --http-cert-file /root/http.crt

[Freeipa-devel] Re: replica installation without CA

2018-02-19 Thread Florence Blanc-Renaud via FreeIPA-devel
On 02/19/2018 11:28 AM, Amit via FreeIPA-devel wrote: Thanks Flo for response. When I am using --pkinit-cert-file to provide rootca cert and key. Still not able to install replica. # ipa-replica-install --pkinit-cert-file /root/rootCA.crt --pkinit-cert-file /root/rootCA.key --pkinit-pin amit

[Freeipa-devel] Re: replica installation without CA

2018-02-19 Thread Florence Blanc-Renaud via FreeIPA-devel
On 02/19/2018 08:28 AM, Amit via FreeIPA-devel wrote: Hello, In installed IPA Server successfully with following command: # ipa-server-install --ca-cert-file /root/ca-hierarchy/rootCA.crt --dirsrv-cert-file /root/ca-hierarchy/dirsrv.crt --dirsrv-cert-file

[Freeipa-devel] Re: authconfig replacement design

2018-02-16 Thread Florence Blanc-Renaud via FreeIPA-devel
On 02/14/2018 09:15 AM, Alexander Koksharov via FreeIPA-devel wrote: Hello, Please take a look on a design page here: https://www.freeipa.org/page/V4/Authselect_migration I would like to ​ ​ hear you critics and suggessions. Thank you -- Alexander

[Freeipa-devel] Re: ipa-server-install reporting "missing basic constraints" for ipa cert while it has X509v3 Basic Constraints:CA:TRUE

2018-02-16 Thread Florence Blanc-Renaud via FreeIPA-devel
On 02/15/2018 03:26 PM, Amit via FreeIPA-devel wrote: Hello, This is process i followed: # ipa-server-install --external-ca /root/ipa.csr. # openssl req -text -noout -verify -in /root/ipa.csr verify OK Certificate Request: Data: Version: 0 (0x0) Subject:

[Freeipa-devel] FreeIPA developement good practices

2018-02-07 Thread Florence Blanc-Renaud via FreeIPA-devel
Hi all, in order to promote good development practices, I would like to write a wiki page stating FreeIPA expectations and helping contributors to remain on track (or extend the Contribute/Code wiki page). The topics include a description explaining our use of the tools (such as github,

[Freeipa-devel] FreeIPA wiki: troubleshooting

2017-11-13 Thread Florence Blanc-Renaud via FreeIPA-devel
Hi all, FreeIPA wiki contains a really long page for Troubleshooting [1], and I would like to re-organize the content a little bit differently. My proposal would be to keep this page as the main access point and only store pointers to other pages, organized by component. We can keep the

[Freeipa-devel] Re: [DESIGN DRAFT] IPA client installation with Ansible

2017-09-07 Thread Florence Blanc-Renaud via FreeIPA-devel
On 09/01/2017 03:56 PM, Rob Crittenden via FreeIPA-devel wrote: Florence Blanc-Renaud via FreeIPA-devel wrote: On 08/16/2017 09:16 AM, Martin Kosek wrote: On 08/02/2017 01:36 PM, Florence Blanc-Renaud via FreeIPA-devel wrote: Hi all, The first version of a new design document is available

[Freeipa-devel] [DESIGN DRAFT] IPA client installation with Ansible

2017-08-02 Thread Florence Blanc-Renaud via FreeIPA-devel
Hi all, The first version of a new design document is available at https://www.freeipa.org/page/V4/ClientInstallationWithAnsible The feature will allow to deploy IPA clients using Ansible. Please feel free to send your comments, suggestions or concerns. Thanks, Flo