[Freeipa-devel] [PATCH] Reword help for the user module

2011-02-16 Thread Jan Zelený
The first part of the ticket has already been solved, hence it is not a part of this patch. https://fedorahosted.org/freeipa/ticket/351 Jan From 0d649884896d67759187a605526fefc31b4ad81c Mon Sep 17 00:00:00 2001 From: Jan Zeleny jzel...@redhat.com Date: Wed, 16 Feb 2011 03:10:14 -0500 Subject:

[Freeipa-devel] [PATCH] Fixed in ipa-server-install help and man page

2011-02-16 Thread Jan Zelený
https://fedorahosted.org/freeipa/ticket/831 Jan From 4fc3a69901c893f7e3403378ddf2d3bfa435132f Mon Sep 17 00:00:00 2001 From: Jan Zeleny jzel...@redhat.com Date: Wed, 16 Feb 2011 03:20:00 -0500 Subject: [PATCH] Fixed in ipa-server-install help and man page

Re: [Freeipa-devel] [PATCH] 057 Validate MX records

2011-02-16 Thread Jan Zelený
Jakub Hrozek jhro...@redhat.com wrote: https://fedorahosted.org/freeipa/ticket/967 I'm wondering whether to extend the patch - if the mail server name does not end with a dot, BIND treats it as relative to the zone. So if you do: ipa dnsrecord-add example.com @ --mx-rec=10

Re: [Freeipa-devel] [PATCH] Reword help for the user module

2011-02-16 Thread Martin Kosek
On Wed, 2011-02-16 at 09:13 +0100, Jan Zelený wrote: The first part of the ticket has already been solved, hence it is not a part of this patch. https://fedorahosted.org/freeipa/ticket/351 Jan NACK Just a minor issue - s/this modules/this module/ Martin

Re: [Freeipa-devel] [PATCH] Reword help for the user module

2011-02-16 Thread Jan Zelený
Martin Kosek mko...@redhat.com wrote: On Wed, 2011-02-16 at 09:13 +0100, Jan Zelený wrote: The first part of the ticket has already been solved, hence it is not a part of this patch. https://fedorahosted.org/freeipa/ticket/351 Jan NACK Just a minor issue - s/this modules/this

Re: [Freeipa-devel] [PATCH] Reword help for the user module

2011-02-16 Thread Martin Kosek
On Wed, 2011-02-16 at 09:43 +0100, Jan Zelený wrote: Martin Kosek mko...@redhat.com wrote: On Wed, 2011-02-16 at 09:13 +0100, Jan Zelený wrote: The first part of the ticket has already been solved, hence it is not a part of this patch. https://fedorahosted.org/freeipa/ticket/351

[Freeipa-devel] [PATCH] 032 Service/Host disable command output clarification

2011-02-16 Thread Martin Kosek
When a service/host is disabled, the resulting summary message states that a Kerberos key was disabled. However, Kerberos key may not have been enabled before this command at all, which makes this information confusing for some users. Also, the summary message didn't state that an SSL certificate

[Freeipa-devel] [PATCH] 47 Validate that the reverse DNS record is correct

2011-02-16 Thread Jan Zelený
This patch ensures that PTR records added by FreeIPA are compliant with RFC. https://fedorahosted.org/freeipa/ticket/839 Jan From 4d2b3200920c90884ddf5a2d5ae784bbe35b41d1 Mon Sep 17 00:00:00 2001 From: Jan Zeleny jzel...@redhat.com Date: Wed, 16 Feb 2011 04:47:36 -0500 Subject: [PATCH] Validate

Re: [Freeipa-devel] [PATCH] Updated default Kerberos password policy

2011-02-16 Thread Rob Crittenden
Jan Zelený wrote: Jan Zelenyjzel...@redhat.com wrote: Rob Crittendenrcrit...@redhat.com wrote: Jan Zelený wrote: https://fedorahosted.org/freeipa/ticket/930 I put there a value Dmitri suggested. Feel free to change it before pushing if you think there should be the originally suggested 10

Re: [Freeipa-devel] [PATCH] Reword help for the user module

2011-02-16 Thread Rob Crittenden
Jan Zelený wrote: The first part of the ticket has already been solved, hence it is not a part of this patch. https://fedorahosted.org/freeipa/ticket/351 Jan ack, pushed to master ___ Freeipa-devel mailing list Freeipa-devel@redhat.com

Re: [Freeipa-devel] [PATCH] Fixed in ipa-server-install help and man page

2011-02-16 Thread Rob Crittenden
Jan Zelený wrote: https://fedorahosted.org/freeipa/ticket/831 Jan I think I'd like David's take on this, but my initial reaction is I'd prefer the word maximum to maximal. rob ___ Freeipa-devel mailing list Freeipa-devel@redhat.com

Re: [Freeipa-devel] [PATCH] Reword help for the user module

2011-02-16 Thread Rob Crittenden
Martin Kosek wrote: On Wed, 2011-02-16 at 09:43 +0100, Jan Zelený wrote: Martin Kosekmko...@redhat.com wrote: On Wed, 2011-02-16 at 09:13 +0100, Jan Zelený wrote: The first part of the ticket has already been solved, hence it is not a part of this patch.

Re: [Freeipa-devel] [PATCH] 057 Validate MX records

2011-02-16 Thread Jakub Hrozek
On Tue, Feb 15, 2011 at 03:45:12PM -0500, Rob Crittenden wrote: Jakub Hrozek wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 https://fedorahosted.org/freeipa/ticket/967 I'm wondering whether to extend the patch - if the mail server name does not end with a dot, BIND treats it as

[Freeipa-devel] [PATCH] 058 Validate and convert certificate SN

2011-02-16 Thread Jakub Hrozek
The cert plugin only worked OK with decimal certificate serial numbers. This patch allows specifying the serial number in hexadecimal, too. The conversion now works such that: * with no explicit radix, a best-effort conversion is done using int(str, 0) in python. If the format is ambiguous,

Re: [Freeipa-devel] [PATCH] 057 Validate MX records

2011-02-16 Thread Jakub Hrozek
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 02/16/2011 03:28 PM, Jakub Hrozek wrote: On Tue, Feb 15, 2011 at 03:45:12PM -0500, Rob Crittenden wrote: Jakub Hrozek wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 https://fedorahosted.org/freeipa/ticket/967 I'm wondering whether to

Re: [Freeipa-devel] [PATCH] 057 Validate MX records

2011-02-16 Thread Rob Crittenden
Jakub Hrozek wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 02/16/2011 03:28 PM, Jakub Hrozek wrote: On Tue, Feb 15, 2011 at 03:45:12PM -0500, Rob Crittenden wrote: Jakub Hrozek wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 https://fedorahosted.org/freeipa/ticket/967 I'm

Re: [Freeipa-devel] [PATCH] 727 don't allow host cn to be updated

2011-02-16 Thread Jakub Hrozek
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 02/15/2011 09:06 PM, Rob Crittenden wrote: We are required by LDAP schema to have a cn value in a host record. Don't let a user modify it, it will just cause confusion. tickets 706 and 707 rob Ack -BEGIN PGP SIGNATURE- Version:

Re: [Freeipa-devel] [PATCH] Send Accept-Language header over XML-RPC and translate on server.

2011-02-16 Thread Pavel Zůna
On 2011-02-04 18:35, Pavel Zůna wrote: On 2011-02-04 16:23, Rob Crittenden wrote: Pavel Zuna wrote: This patch makes the ipa client send the Accept-Language header, so that the server can translate things like exceptions, that cannot be translated on the client. It also fixes the language

[Freeipa-devel] [PATCH] Translate docstrings.

2011-02-16 Thread Pavel Zůna
This patch prepares the built-in help system for localized docstrings. Pavel freeipa-pzuna-80-docstringloc.patch Description: application/mbox ___ Freeipa-devel mailing list Freeipa-devel@redhat.com

[Freeipa-devel] [PATCH] Fix translatable strings in ipalib plugins.

2011-02-16 Thread Pavel Zůna
Some translatable strings were in a wrong format a there were some more related issues. This patch tries to fix all of them. Needed for xgettext/pygettext processing. Pavel freeipa-pzuna-81-fixlocstrings.patch Description: application/mbox ___

[Freeipa-devel] [PATCH] Fix i18n related failures in unit tests.

2011-02-16 Thread Pavel Zůna
Fixes unit test failures cause by the changes introduced in my other localization related patches. Pavel freeipa-pzuna-82-fixlocutests.patch Description: application/mbox ___ Freeipa-devel mailing list Freeipa-devel@redhat.com

Re: [Freeipa-devel] [PATCH] 026 HBAC plugin inconsistent output

2011-02-16 Thread Martin Kosek
On Mon, 2011-02-14 at 10:37 -0500, Rob Crittenden wrote: Jan Zelený wrote: Martin Kosekmko...@redhat.com wrote: On Mon, 2011-02-07 at 10:38 +0100, Jan Zelený wrote: Martin Kosekmko...@redhat.com wrote: This patch adds a proper summary text to HBAC command which is then printed out in

Re: [Freeipa-devel] [PATCH] 026 HBAC plugin inconsistent output

2011-02-16 Thread Rob Crittenden
Martin Kosek wrote: On Mon, 2011-02-14 at 10:37 -0500, Rob Crittenden wrote: Jan Zelený wrote: Martin Kosekmko...@redhat.com wrote: On Mon, 2011-02-07 at 10:38 +0100, Jan Zelený wrote: Martin Kosekmko...@redhat.com wrote: This patch adds a proper summary text to HBAC command which is

Re: [Freeipa-devel] [PATCH] 031 Remove WebUI identifiers from global namespace

2011-02-16 Thread Adam Young
On 02/16/2011 10:16 AM, Martin Kosek wrote: On Tue, 2011-02-15 at 13:26 -0500, Adam Young wrote: On 02/15/2011 08:25 AM, Martin Kosek wrote: Many WebUI identifiers were defined in a global namespace. This is not a good programming practice and may result in name clashes, for example with other

[Freeipa-devel] [PATCH] 18 Use TLS for ipadiscovery during ipa client install

2011-02-16 Thread JR Aquino
This patch addresses the need to utilize TLS when using the ipa-client-install tool. It addresses ticket: https://fedorahosted.org/freeipa/ticket/974 binh94MJnFPEx.bin Description: freeipa-jraquino-0018-Use-TLS-for-ipadiscovery-during-ipa-client-install.patch

[Freeipa-devel] [PATCH] 059 Use unicode parameters in the host plugin

2011-02-16 Thread Jakub Hrozek
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 While reviewing Rob's latest patch I found out that we didn't convert to unicode on couple of places in the host plugin. -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org/

Re: [Freeipa-devel] [PATCH] 17-2 Managed netgroups should be invisible

2011-02-16 Thread JR Aquino
Removed whitespace from patch and added API.txt changes to reflect the --private option added to netgroup On 2/15/11 12:45 PM, JR Aquino jr.aqu...@citrix.com wrote: This patch provides ipa netgroup-find a default filter which prevents the displaying of mepManageEntry Netgroups by default. It

Re: [Freeipa-devel] [PATCH] 47 Validate that the reverse DNS record is correct

2011-02-16 Thread Jan Zeleny
Adam Tkac at...@redhat.com wrote: On Wed, Feb 16, 2011 at 10:53:14AM +0100, Jan Zelený wrote: This patch ensures that PTR records added by FreeIPA are compliant with RFC. Nack. In my opinion the _ptrrecord_pre_callback should also handle PTR records for IPv6 addresses. You can check

[Freeipa-devel] [PATCH] 0084 Fix duplicate OIDs

2011-02-16 Thread Simo Sorce
Apparently we forgot to check OID consistency between the schema and the extensions, and we got duplicates. Technically the schema was done later but it is easier to change the extensions OIDs then to change the schema of current beta2/rc1 installations. The only side effect is that older

Re: [Freeipa-devel] [PATCH] 17-2 Managed netgroups should be invisible

2011-02-16 Thread Endi Sukma Dewata
On 2/15/11 12:45 PM, JR Aquino jr.aqu...@citrix.com wrote: This patch provides ipa netgroup-find a default filter which prevents the displaying of mepManageEntry Netgroups by default. It also introduces a ‹private flag similar to the group.py to allow for displaying them if necessary.

Re: [Freeipa-devel] [PATCH] Updated default Kerberos password policy

2011-02-16 Thread Jan Zeleny
Rob Crittenden rcrit...@redhat.com wrote: Jan Zelený wrote: Jan Zelenyjzel...@redhat.com wrote: Rob Crittendenrcrit...@redhat.com wrote: Jan Zelený wrote: https://fedorahosted.org/freeipa/ticket/930 I put there a value Dmitri suggested. Feel free to change it before pushing if

[Freeipa-devel] [PATCH 22/22] Update Polish Ukrainian translations

2011-02-16 Thread John Dennis
-- John Dennis jden...@redhat.com Looking to carve out IT costs? www.redhat.com/carveoutcosts/ From d1694b173e15684667daab912a75f7f81b0b3a08 Mon Sep 17 00:00:00 2001 From: John Dennis jden...@redhat.com Date: Wed, 16 Feb 2011 14:57:26 -0500 Subject: [PATCH 22/22] Update Polish Ukrainian

Re: [Freeipa-devel] [PATCH] 058 Validate and convert certificate SN

2011-02-16 Thread Rob Crittenden
Jakub Hrozek wrote: The cert plugin only worked OK with decimal certificate serial numbers. This patch allows specifying the serial number in hexadecimal, too. The conversion now works such that: * with no explicit radix, a best-effort conversion is done using int(str, 0) in python. If the

Re: [Freeipa-devel] [PATCH] 727 don't allow host cn to be updated

2011-02-16 Thread Rob Crittenden
Jakub Hrozek wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 02/15/2011 09:06 PM, Rob Crittenden wrote: We are required by LDAP schema to have a cn value in a host record. Don't let a user modify it, it will just cause confusion. tickets 706 and 707 rob Ack pushed to master

Re: [Freeipa-devel] [PATCH] 032 Service/Host disable command output clarification

2011-02-16 Thread Rob Crittenden
Martin Kosek wrote: When a service/host is disabled, the resulting summary message states that a Kerberos key was disabled. However, Kerberos key may not have been enabled before this command at all, which makes this information confusing for some users. Also, the summary message didn't state

Re: [Freeipa-devel] [PATCH] Updated default Kerberos password policy

2011-02-16 Thread Rob Crittenden
Jan Zeleny wrote: Rob Crittendenrcrit...@redhat.com wrote: Jan Zelený wrote: Jan Zelenyjzel...@redhat.com wrote: Rob Crittendenrcrit...@redhat.com wrote: Jan Zelený wrote: https://fedorahosted.org/freeipa/ticket/930 I put there a value Dmitri suggested. Feel free to change it before

[Freeipa-devel] [PATCH] 728 default roles

2011-02-16 Thread Rob Crittenden
Add default roles and permissions for HBAC, SUDO and pw policy Created some default roles as examples. In doing so I realized that we were completely missing default rules for HBAC, SUDO and password policy so I added those as well. I ran into a problem when the updater has a default record

Re: [Freeipa-devel] [PATCH] Fix i18n related failures in unit tests.

2011-02-16 Thread Rob Crittenden
Pavel Zůna wrote: Fixes unit test failures cause by the changes introduced in my other localization related patches. Pavel I don't understand this change, isn't the point to test other languages? -request.set_languages('en_US.UTF-8') +# request.set_languages('en_US.UTF-8') #

Re: [Freeipa-devel] Localization patches.

2011-02-16 Thread Rob Crittenden
Pavel Zůna wrote: My efforts in fixing localization all around the framework and preparing it for localizing docstrings have resulted in a lot of patches. Because I understand they have become a bit hard to track, I decided to post them all together in this thread to make review easier. After

[Freeipa-devel] [PATCH] 19 prevent duplicate netgroup entries

2011-02-16 Thread JR Aquino
This patch fixes the netgroup plugin's behavior of adding duplicate entries when the managed entry plugin creates a netgroup with a mepManagedEntry This problem is documented in ticket: https://fedorahosted.org/freeipa/ticket/963 As noted by Endi for issue #3 in the History: 3. Just out of