Re: [Freeipa-devel] DNSSEC support design considerations: migration to RBTDB

2013-06-21 Thread Simo Sorce
On Thu, 2013-06-20 at 14:30 +0200, Petr Spacek wrote: > Hello, > > On 23.5.2013 16:32, Simo Sorce wrote: > > On Thu, 2013-05-23 at 14:35 +0200, Petr Spacek wrote: > >> It looks that we agree on nearly all points (I apologize if > >> overlooked > >> something). I will prepare a design document for

Re: [Freeipa-devel] [PATCH 0030] Require rid-base and secondary-rid-base options in idrange-add when trust exists

2013-06-21 Thread Tomas Babej
On 06/21/2013 03:38 PM, Ana Krivokapic wrote: On 06/21/2013 02:39 PM, Tomas Babej wrote: On 06/12/2013 07:06 PM, Ana Krivokapic wrote: On 06/11/2013 06:44 PM, Alexander Bokovoy wrote: On Tue, 11 Jun 2013, Martin Kosek wrote: 2) Is the used ldapsearch really the best way to find out if Trust i

Re: [Freeipa-devel] [PATCH 0030] Require rid-base and secondary-rid-base options in idrange-add when trust exists

2013-06-21 Thread Ana Krivokapic
On 06/21/2013 02:39 PM, Tomas Babej wrote: > On 06/12/2013 07:06 PM, Ana Krivokapic wrote: >> On 06/11/2013 06:44 PM, Alexander Bokovoy wrote: >>> On Tue, 11 Jun 2013, Martin Kosek wrote: >> 2) Is the used ldapsearch really the best way to find out if Trust is >> configured on a given maste

Re: [Freeipa-devel] [PATCH 0030] Require rid-base and secondary-rid-base options in idrange-add when trust exists

2013-06-21 Thread Tomas Babej
On 06/12/2013 07:06 PM, Ana Krivokapic wrote: On 06/11/2013 06:44 PM, Alexander Bokovoy wrote: On Tue, 11 Jun 2013, Martin Kosek wrote: 2) Is the used ldapsearch really the best way to find out if Trust is configured on a given master? Isn't a search in cn=masters,cn=ipa,... better? Alexander?

Re: [Freeipa-devel] [PATCH 0075] Change group ownership of CRL publish directory

2013-06-21 Thread Tomas Babej
On 06/21/2013 02:15 PM, Martin Kosek wrote: On 06/21/2013 02:11 PM, Tomas Babej wrote: On 06/20/2013 06:00 PM, Simo Sorce wrote: On Thu, 2013-06-20 at 17:47 +0200, Martin Kosek wrote: On 06/20/2013 05:44 PM, Simo Sorce wrote: On Thu, 2013-06-20 at 17:33 +0200, Martin Kosek wrote: On 06/20/20

Re: [Freeipa-devel] [PATCH 0075] Change group ownership of CRL publish directory

2013-06-21 Thread Martin Kosek
On 06/21/2013 02:11 PM, Tomas Babej wrote: > On 06/20/2013 06:00 PM, Simo Sorce wrote: >> On Thu, 2013-06-20 at 17:47 +0200, Martin Kosek wrote: >>> On 06/20/2013 05:44 PM, Simo Sorce wrote: On Thu, 2013-06-20 at 17:33 +0200, Martin Kosek wrote: > On 06/20/2013 05:15 PM, Tomas Babej wrote:

Re: [Freeipa-devel] [PATCH 0075] Change group ownership of CRL publish directory

2013-06-21 Thread Tomas Babej
On 06/20/2013 06:00 PM, Simo Sorce wrote: On Thu, 2013-06-20 at 17:47 +0200, Martin Kosek wrote: On 06/20/2013 05:44 PM, Simo Sorce wrote: On Thu, 2013-06-20 at 17:33 +0200, Martin Kosek wrote: On 06/20/2013 05:15 PM, Tomas Babej wrote: Hi, Spec file modified so that /var/lib/ipa/pki-ca/publ

Re: [Freeipa-devel] [PATCH 0073] Remove support for IPA deployments with no persistent search

2013-06-21 Thread Ana Krivokapic
On 06/12/2013 02:28 PM, Tomas Babej wrote: > Hi, > > Drops the code from ipa-server-install, ipa-dns-install and the > BindInstance itself. Also changed ipa-upgradeconfig script so > that it does not set zone_refresh to 0 on upgrades, as the option > is deprecated, but rather removes it altogether.

Re: [Freeipa-devel] [PATCH 0072] Provide ipa-client-advise tool

2013-06-21 Thread Tomas Babej
On 06/21/2013 09:32 AM, Jan Cholasta wrote: On 21.6.2013 09:16, Tomas Babej wrote: I'm also thinking about propagating the --verbose, etc. options provided by default by AdminTool down to plugin level so that plugin authors can make use of them. What do you think? +1 Newly added features:

Re: [Freeipa-devel] [PATCH 0072] Provide ipa-client-advise tool

2013-06-21 Thread Jan Cholasta
On 21.6.2013 09:16, Tomas Babej wrote: I'm also thinking about propagating the --verbose, etc. options provided by default by AdminTool down to plugin level so that plugin authors can make use of them. What do you think? +1 -- Jan Cholasta ___ Freei

Re: [Freeipa-devel] [PATCH 0072] Provide ipa-client-advise tool

2013-06-21 Thread Tomas Babej
On 06/20/2013 12:52 PM, Jan Cholasta wrote: On 20.6.2013 12:28, Tomas Babej wrote: Providing new version: - no longer requires root access defaultly - headers are printed out as comments Tomas You still have reference(s) to previous names of the script in the patch: +""" +Base