Re: [Freeipa-devel] [PATCH 0023] Add detection for users from trusted/invalid realms

2012-11-15 Thread Petr Vobornik
On 11/15/2012 11:54 AM, Tomas Babej wrote: Hi, This is server part of #3252. When user from other realm than FreeIPA's tries to use Web UI (login via forms-based auth or with valid trusted realm ticket), the 401 Unauthorized error with X-Ipa-Rejection-Reason=denied is returned. Also, the

Re: [Freeipa-devel] [PATCH 0023] Add detection for users from trusted/invalid realms

2012-11-15 Thread Tomas Babej
On 11/15/2012 12:41 PM, Petr Vobornik wrote: On 11/15/2012 11:54 AM, Tomas Babej wrote: Hi, This is server part of #3252. When user from other realm than FreeIPA's tries to use Web UI (login via forms-based auth or with valid trusted realm ticket), the 401 Unauthorized error with

Re: [Freeipa-devel] [PATCH] 334 Add requires for new dogtag10 and its server theme

2012-11-15 Thread Martin Kosek
On 11/15/2012 01:09 PM, Petr Viktorin wrote: On 11/15/2012 12:04 PM, Martin Kosek wrote: On 11/15/2012 11:01 AM, Petr Viktorin wrote: On 11/14/2012 05:16 PM, Martin Kosek wrote: On 11/14/2012 05:05 PM, Martin Kosek wrote: On 11/14/2012 02:41 PM, Rob Crittenden wrote: Martin Kosek wrote:

Re: [Freeipa-devel] [PATCH] 0098 Provide explicit user name for Dogtag installation scripts

2012-11-15 Thread Martin Kosek
On 11/14/2012 09:43 AM, Petr Viktorin wrote: On 11/13/2012 11:23 PM, Rob Crittenden wrote: Petr Viktorin wrote: See commit message. Dogtag is changing its behavior soon (as in: tomorrow). This patch will be needed for IPA to install on Fedora 18. It would be nice if this went in our daily

Re: [Freeipa-devel] [PATCH 0023] Add detection for users from trusted/invalid realms

2012-11-15 Thread Alexander Bokovoy
On Thu, 15 Nov 2012, Tomas Babej wrote: From e08691492241399bbe41802b945df0b714e16c00 Mon Sep 17 00:00:00 2001 From: Tomas Babej tba...@redhat.com Date: Thu, 15 Nov 2012 05:21:16 -0500 Subject: [PATCH] Add detection for users from trusted/invalid realms When user from other realm than

Re: [Freeipa-devel] [PATCH 0023] Add detection for users from trusted/invalid realms

2012-11-15 Thread Simo Sorce
On Thu, 2012-11-15 at 12:41 +0100, Petr Vobornik wrote: On 11/15/2012 11:54 AM, Tomas Babej wrote: Hi, This is server part of #3252. When user from other realm than FreeIPA's tries to use Web UI (login via forms-based auth or with valid trusted realm ticket), the 401 Unauthorized

Re: [Freeipa-devel] [PATCH] IPA tool scripts

2012-11-15 Thread Martin Kosek
On 11/13/2012 09:50 AM, Martin Kosek wrote: On 11/10/2012 12:08 AM, Dmitri Pal wrote: On 11/09/2012 05:52 PM, Simo Sorce wrote: On Fri, 2012-11-09 at 15:59 -0500, Dmitri Pal wrote: On 11/09/2012 07:58 AM, Petr Vobornik wrote: On 11/09/2012 01:43 PM, Lynn Root wrote: The VERSION file and

Re: [Freeipa-devel] [PATCHES] Re: Changes to use a single database for dogtag and IPA

2012-11-15 Thread Petr Viktorin
Recently, the specfile changed (dce53e4) and the patch for changed Dogtag defaults made it to master independently (91e477b). Attaching rebased patch. Note that to continue development on f17, you will need to use the dogtag-devel repo: sudo yum-config-manager

Re: [Freeipa-devel] [PATCH] 335 Stop and disable conflicting timedate services

2012-11-15 Thread Simo Sorce
On Thu, 2012-11-15 at 12:34 +0100, Martin Kosek wrote: Fedora 16 introduced chrony as default client timedate synchronization service: http://fedoraproject.org/wiki/Features/ChronyDefaultNTP Thus, there may be people already using chrony as their time and date synchronization service before

Re: [Freeipa-devel] [PATCH 0023] Add detection for users from trusted/invalid realms

2012-11-15 Thread Tomas Babej
On 11/15/2012 03:10 PM, Simo Sorce wrote: On Thu, 2012-11-15 at 12:41 +0100, Petr Vobornik wrote: On 11/15/2012 11:54 AM, Tomas Babej wrote: Hi, This is server part of #3252. When user from other realm than FreeIPA's tries to use Web UI (login via forms-based auth or with valid trusted realm

Re: [Freeipa-devel] [PATCH 0023] Add detection for users from trusted/invalid realms

2012-11-15 Thread Simo Sorce
On Thu, 2012-11-15 at 15:51 +0100, Tomas Babej wrote: On 11/15/2012 03:10 PM, Simo Sorce wrote: On Thu, 2012-11-15 at 12:41 +0100, Petr Vobornik wrote: On 11/15/2012 11:54 AM, Tomas Babej wrote: Hi, This is server part of #3252. When user from other realm than FreeIPA's tries to use

Re: [Freeipa-devel] cert-find design

2012-11-15 Thread Simo Sorce
On Thu, 2012-11-15 at 09:54 -0500, Rob Crittenden wrote: Simo Sorce wrote: On Wed, 2012-11-14 at 17:36 -0500, Rob Crittenden wrote: There is currently no way to search for a certificate. You can only look it up if you already know the serial number. Dogtag 10 has a fresh API which makes

Re: [Freeipa-devel] cert-find design

2012-11-15 Thread Simo Sorce
On Thu, 2012-11-15 at 09:54 -0500, Rob Crittenden wrote: Simo Sorce wrote: On Wed, 2012-11-14 at 17:36 -0500, Rob Crittenden wrote: There is currently no way to search for a certificate. You can only look it up if you already know the serial number. Dogtag 10 has a fresh API which makes

Re: [Freeipa-devel] [PATCHES] Re: Changes to use a single database for dogtag and IPA

2012-11-15 Thread Martin Kosek
On 11/15/2012 03:19 PM, Petr Viktorin wrote: Recently, the specfile changed (dce53e4) and the patch for changed Dogtag defaults made it to master independently (91e477b). Attaching rebased patch. Note that to continue development on f17, you will need to use the dogtag-devel repo: sudo

Re: [Freeipa-devel] [PATCH] 335 Stop and disable conflicting timedate services

2012-11-15 Thread Martin Kosek
On 11/15/2012 03:22 PM, Simo Sorce wrote: On Thu, 2012-11-15 at 12:34 +0100, Martin Kosek wrote: Fedora 16 introduced chrony as default client timedate synchronization service: http://fedoraproject.org/wiki/Features/ChronyDefaultNTP Thus, there may be people already using chrony as their time

Re: [Freeipa-devel] [PATCH] 335 Stop and disable conflicting timedate services

2012-11-15 Thread Petr Spacek
On 11/15/2012 05:33 PM, Martin Kosek wrote: On 11/15/2012 03:22 PM, Simo Sorce wrote: On Thu, 2012-11-15 at 12:34 +0100, Martin Kosek wrote: Fedora 16 introduced chrony as default client timedate synchronization service: http://fedoraproject.org/wiki/Features/ChronyDefaultNTP Thus, there may

Re: [Freeipa-devel] [PATCHES] Re: Changes to use a single database for dogtag and IPA

2012-11-15 Thread Petr Viktorin
On 11/15/2012 05:09 PM, Martin Kosek wrote: On 11/15/2012 03:19 PM, Petr Viktorin wrote: Recently, the specfile changed (dce53e4) and the patch for changed Dogtag defaults made it to master independently (91e477b). Attaching rebased patch. Note that to continue development on f17, you will

Re: [Freeipa-devel] [PATCH 0023] Add detection for users from trusted/invalid realms

2012-11-15 Thread Tomas Babej
On 11/15/2012 04:14 PM, Simo Sorce wrote: On Thu, 2012-11-15 at 15:51 +0100, Tomas Babej wrote: On 11/15/2012 03:10 PM, Simo Sorce wrote: On Thu, 2012-11-15 at 12:41 +0100, Petr Vobornik wrote: On 11/15/2012 11:54 AM, Tomas Babej wrote: Hi, This is server part of #3252. When user from

Re: [Freeipa-devel] [PATCH] 335 Stop and disable conflicting timedate services

2012-11-15 Thread Simo Sorce
On Thu, 2012-11-15 at 17:33 +0100, Martin Kosek wrote: On 11/15/2012 03:22 PM, Simo Sorce wrote: On Thu, 2012-11-15 at 12:34 +0100, Martin Kosek wrote: Fedora 16 introduced chrony as default client timedate synchronization service: http://fedoraproject.org/wiki/Features/ChronyDefaultNTP

[Freeipa-devel] [PATCH] 1072 enable transaction support

2012-11-15 Thread Rob Crittenden
This patch enables transaction support in 389-ds-base and fixes a few transaction issues within IPA. This converts parts of the password and modrnd plugins to support transactions. The password plugin still largely runs as non-transactional because extop plugins aren't supported in