Re: [Freeipa-devel] [PATCH] 32 Don't delete NIS netgroup compat suffix on 'ipa-nis-manage disable'

2011-07-19 Thread Jan Cholasta
On 18.7.2011 18:48, Martin Kosek wrote: On Mon, 2011-07-18 at 17:16 +0200, Jan Cholasta wrote: https://fedorahosted.org/freeipa/ticket/1469 Honza The patch is missing. Martin Is it? ...it is! Sorry. Honza -- Jan Cholasta From 7ec54681c9eeb89b60ee6d5a7d8c1611be0c4af3 Mon Sep 17

Re: [Freeipa-devel] [PATCH] 830 change enrollment principal prompt

2011-07-19 Thread Martin Kosek
On Mon, 2011-07-18 at 22:49 -0400, Rob Crittenden wrote: Change the enrollment principal prompt to hopefully be more clear. ticket https://fedorahosted.org/freeipa/ticket/1449 ACK. Pushed to master, ipa-2-0. Adding Deon to CC, this will affect at lest the Fedora documentation. In the

Re: [Freeipa-devel] [PATCH] 35 remove escapes from the cvs parser in ipaserver/install/ldapupdate

2011-07-19 Thread Martin Kosek
On Mon, 2011-07-18 at 20:08 +, JR Aquino wrote: On Jul 18, 2011, at 1:08 PM, wrote: https://fedorahosted.org/freeipa/ticket/1472 Changeset 8e086fd7b8c1edd0ccfec527c0699d396a7954f9 introduced a bug with ldapupdate resulting in incorrect handling of uldif files. Particularly the

Re: [Freeipa-devel] [PATCH] 37 Correct sudo runasuser and runasgroup attributes in schema

2011-07-19 Thread Martin Kosek
On Mon, 2011-07-18 at 23:43 +, JR Aquino wrote: https://fedorahosted.org/freeipa/ticket/1309 Added .update file to correct the sudo schema during freeipa updates on older systems. Modified Makefile.am to account for new .update file. NACK. This fixes the schema well, but

Re: [Freeipa-devel] [PATCH] 096 Fix ipa-dns-install incorrect warning

2011-07-19 Thread Martin Kosek
On Mon, 2011-07-18 at 13:49 +0200, Jan Cholasta wrote: On 18.7.2011 12:56, Martin Kosek wrote: ipa-dns-install incorrectly warns about non-local IP addresses when installing without --ip-address parameter. https://fedorahosted.org/freeipa/ticket/1486 IMO the warning message should be

Re: [Freeipa-devel] [PATCH] 32 Don't delete NIS netgroup compat suffix on 'ipa-nis-manage disable'

2011-07-19 Thread Martin Kosek
On Tue, 2011-07-19 at 08:00 +0200, Jan Cholasta wrote: On 18.7.2011 18:48, Martin Kosek wrote: On Mon, 2011-07-18 at 17:16 +0200, Jan Cholasta wrote: https://fedorahosted.org/freeipa/ticket/1469 Honza The patch is missing. Martin Is it? ...it is! Sorry. Honza

Re: [Freeipa-devel] [PATCH] 098 Fix sudorule-remove-user

2011-07-19 Thread Jan Cholasta
On 19.7.2011 10:48, Martin Kosek wrote: This is a follow up to JR's patch 36. --- Removed sudorule External User is displayed in the output when --all switch is used. https://fedorahosted.org/freeipa/ticket/1489 ACK. Honza -- Jan Cholasta ___

Re: [Freeipa-devel] [PATCH] 098 Fix sudorule-remove-user

2011-07-19 Thread Martin Kosek
On Tue, 2011-07-19 at 15:21 +0200, Jan Cholasta wrote: On 19.7.2011 10:48, Martin Kosek wrote: This is a follow up to JR's patch 36. --- Removed sudorule External User is displayed in the output when --all switch is used. https://fedorahosted.org/freeipa/ticket/1489 ACK.

[Freeipa-devel] [PATCH] 05 Fix sssd.conf to always have IPA certificate for the domain

2011-07-19 Thread Alexander Bokovoy
https://fedorahosted.org/freeipa/ticket/1476 -- / Alexander Bokovoy From f80ccb1a3c85afd8d5aa03191ef5c323a35293de Mon Sep 17 00:00:00 2001 From: Alexander Bokovoy aboko...@redhat.com Date: Tue, 19 Jul 2011 16:07:05 +0300 Subject: [PATCH] Fix sssd.conf to always have IPA certificate for the

Re: [Freeipa-devel] [PATCH] 37 Correct sudo runasuser and runasgroup attributes in schema

2011-07-19 Thread JR Aquino
On Jul 19, 2011, at 2:32 AM, Martin Kosek mko...@redhat.com wrote: On Mon, 2011-07-18 at 23:43 +, JR Aquino wrote: https://fedorahosted.org/freeipa/ticket/1309 Added .update file to correct the sudo schema during freeipa updates on older systems. Modified Makefile.am to account for

[Freeipa-devel] [PATCH] 831 fix removing external netgroup hosts

2011-07-19 Thread Rob Crittenden
When removing an external host member it was still showing in the return data as a member despite being removed properly. ticket https://fedorahosted.org/freeipa/ticket/1492 From c98f280711289e5ee436ef436eb40c421106df40 Mon Sep 17 00:00:00 2001 From: Rob Crittenden rcrit...@redhat.com Date:

Re: [Freeipa-devel] [PATCH] 4 (1) ipa-client-install complains about non-existing nss_ldap

2011-07-19 Thread Alexander Bokovoy
On 06.07.2011 17:26, Rob Crittenden wrote: ipa-client-install should be usable on non-RH platforms (see https://fedorahosted.org/freeipa/ticket/1374), so you shouldn't use /bin/rpm, as that's platform-specific. Wouldn't just rephrasing the warning message (as suggested in the ticket) be

Re: [Freeipa-devel] [PATCH] 831 fix removing external netgroup hosts

2011-07-19 Thread Jan Cholasta
On 19.7.2011 15:34, Rob Crittenden wrote: When removing an external host member it was still showing in the return data as a member despite being removed properly. ticket https://fedorahosted.org/freeipa/ticket/1492 You store the result of ldap.get_entry in a variable and never use it

Re: [Freeipa-devel] [PATCH] 820 make client errors clearer

2011-07-19 Thread Martin Kosek
On Wed, 2011-07-06 at 11:03 -0400, Rob Crittenden wrote: Some client errors were rather generic or outright misleading. This cleans up some return values and displays output from the ipa-enrollment extended operation. ticket https://fedorahosted.org/freeipa/ticket/1417 NACK. Good patch,

Re: [Freeipa-devel] [PATCH] 831 fix removing external netgroup hosts

2011-07-19 Thread Rob Crittenden
Jan Cholasta wrote: On 19.7.2011 15:34, Rob Crittenden wrote: When removing an external host member it was still showing in the return data as a member despite being removed properly. ticket https://fedorahosted.org/freeipa/ticket/1492 You store the result of ldap.get_entry in a variable

Re: [Freeipa-devel] [PATCH] 831 fix removing external netgroup hosts

2011-07-19 Thread Jan Cholasta
On 19.7.2011 16:08, Rob Crittenden wrote: Jan Cholasta wrote: On 19.7.2011 15:34, Rob Crittenden wrote: When removing an external host member it was still showing in the return data as a member despite being removed properly. ticket https://fedorahosted.org/freeipa/ticket/1492 You store

Re: [Freeipa-devel] [PATCH] 31 Correct behavior for sudorunasgroup vs sudorunasuser

2011-07-19 Thread Martin Kosek
On Tue, 2011-06-14 at 19:03 +, JR Aquino wrote: Adjustment to install/share/schema_compat.uldif to correctly assign sudorunasuser for both a user and group object respectively. The bug had to do with the compat plugin syntax needing to correctly identify the difference behind intent

Re: [Freeipa-devel] [PATCH] 831 fix removing external netgroup hosts

2011-07-19 Thread Rob Crittenden
Jan Cholasta wrote: On 19.7.2011 16:08, Rob Crittenden wrote: Jan Cholasta wrote: On 19.7.2011 15:34, Rob Crittenden wrote: When removing an external host member it was still showing in the return data as a member despite being removed properly. ticket

Re: [Freeipa-devel] [PATCH] 810 fix re-enrolling a host with a OTP

2011-07-19 Thread Rob Crittenden
Martin Kosek wrote: On Fri, 2011-07-01 at 11:40 -0400, Rob Crittenden wrote: Rob Crittenden wrote: Rob Crittenden wrote: Don't set krbLastPwdChange when setting a host OTP password. We have no visibility into whether an entry has a keytab or not so krbLastPwdChange is used as a rough guide.

Re: [Freeipa-devel] [PATCH] 820 make client errors clearer

2011-07-19 Thread Rob Crittenden
Martin Kosek wrote: On Wed, 2011-07-06 at 11:03 -0400, Rob Crittenden wrote: Some client errors were rather generic or outright misleading. This cleans up some return values and displays output from the ipa-enrollment extended operation. ticket https://fedorahosted.org/freeipa/ticket/1417

Re: [Freeipa-devel] [PATCH] 05 Fix sssd.conf to always have IPA certificate for the domain

2011-07-19 Thread Rob Crittenden
Alexander Bokovoy wrote: https://fedorahosted.org/freeipa/ticket/1476 ack, pushed to master and ipa-2-0 ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel

Re: [Freeipa-devel] [PATCH] 34 Create FreeIPA CLI Plugin for the 389 Auto Membership plugin

2011-07-19 Thread JR Aquino
On Jul 15, 2011, at 7:55 AM, Rob Crittenden wrote: Martin Kosek wrote: On Thu, 2011-07-14 at 23:05 +, JR Aquino wrote: On Jul 14, 2011, at 11:55 AM, wrote: https://fedorahosted.org/freeipa/ticket/1272 * Added new container in etc to hold the automembership configs. * Modified

[Freeipa-devel] Bug fix tickets

2011-07-19 Thread Adam Young
Petr, the report for UI tickets Is: https://fedorahosted.org/freeipa/report/12 I'd like you to take a look at the two 2.1.1 tickets: I've assigned them to pvoborni, but I am not sure that is the right Fedora Account name, please adjust as necessary. For 1477, please follow the second

[Freeipa-devel] [PATCH] 211 Added checkbox to remove hosts from DNS.

2011-07-19 Thread Endi Sukma Dewata
A custom deleter dialog for hosts has been added to provide an option whether to remove the hosts from DNS. Ticket #1470 -- Endi S. Dewata From 68010a0e620b7c1220e617c5f5fcf2f0db59352e Mon Sep 17 00:00:00 2001 From: Endi S. Dewata edew...@redhat.com Date: Tue, 19 Jul 2011 13:46:09 -0500

[Freeipa-devel] [PATCH] 832 fix netgroup regression

2011-07-19 Thread Rob Crittenden
In my patch to fix netgroup calculation I convered one to many references to entry_attrs. The self tests caught this, too bad I didn't run them before submitting the patch. I pushed this as a one-liner. rob From dbcc37c7f08ea362ac2d422147e74e2b40e880be Mon Sep 17 00:00:00 2001 From: Rob

Re: [Freeipa-devel] [PATCH] 31 Correct behavior for sudorunasgroup vs sudorunasuser

2011-07-19 Thread JR Aquino
On Jul 19, 2011, at 7:30 AM, Martin Kosek wrote: On Tue, 2011-06-14 at 19:03 +, JR Aquino wrote: Adjustment to install/share/schema_compat.uldif to correctly assign sudorunasuser for both a user and group object respectively. The bug had to do with the compat plugin syntax needing to

[Freeipa-devel] [PATCH] 834 Hide the HBAC access type attribute now that deny is deprecated.

2011-07-19 Thread Rob Crittenden
Hide the HBAC access type attribute now that deny is deprecated. It won't appear in the UI/CLI but is still available via XML-RPC. allow is the default and deny will be rejected. This is not tested in the UI. I'm not sure if this is due to a problem in my tree or something else.

[Freeipa-devel] [PATCH] 835 set default min int, handle longs

2011-07-19 Thread Rob Crittenden
Our handling of long values wasn't the best when dealing with negative values. Added a default minint similar to maxint and validate_scalar in Int to allow either int or long types. This lets it get to the min/max rules where we can compare properly and give a better error response. Note that

Re: [Freeipa-devel] [PATCH] 37 Correct sudo runasuser and runasgroup attributes in schema

2011-07-19 Thread Rob Crittenden
JR Aquino wrote: On Jul 19, 2011, at 2:20 AM, Martin Kosek wrote: On Mon, 2011-07-18 at 23:43 +, JR Aquino wrote: https://fedorahosted.org/freeipa/ticket/1309 Added .update file to correct the sudo schema during freeipa updates on older systems. Modified Makefile.am to account for new

Re: [Freeipa-devel] [PATCH] 31 Correct behavior for sudorunasgroup vs sudorunasuser

2011-07-19 Thread Rob Crittenden
JR Aquino wrote: On Jul 19, 2011, at 2:05 PM, JR Aquino wrote: On Jul 19, 2011, at 7:30 AM, Martin Kosek wrote: On Tue, 2011-06-14 at 19:03 +, JR Aquino wrote: Adjustment to install/share/schema_compat.uldif to correctly assign sudorunasuser for both a user and group object