Re: [Freeipa-devel] [PATCH] 161 Use configured dogtag LDAP port instead of default one when renewing certs

2013-07-23 Thread Jan Cholasta
On 22.7.2013 17:40, Simo Sorce wrote: On Mon, 2013-07-22 at 17:36 +0200, Jan Cholasta wrote: if nickname == 'subsystemCert cert-pki-ca': -update_people_entry('pkidbuser', cert) +update_people_entry(dogtag_uri, 'pkidbuser', cert) This is probably wrong, there is no pkidbuser in old i

Re: [Freeipa-devel] [PATCH] 0047 Honor 'enabled' option for widgets

2013-07-23 Thread Petr Vobornik
On 07/22/2013 04:46 PM, Ana Krivokapic wrote: On 07/18/2013 09:47 AM, Petr Vobornik wrote: On 07/17/2013 09:18 PM, Ana Krivokapic wrote: Hello, This patch addresses ticket https://fedorahosted.org/freeipa/ticket/3793. Hello, 1) IMO we should not create attribute which is just a negation o

Re: [Freeipa-devel] [PATCH] 431-434 Web UI integration tests continuation

2013-07-23 Thread Petr Viktorin
On 07/23/2013 05:50 PM, Ana Krivokapic wrote: On 07/18/2013 01:35 PM, Petr Vobornik wrote: On 07/18/2013 01:34 PM, Petr Vobornik wrote: [PATCH] 431 Web UI integration tests: Add trust tests [PATCH] 432 Web UI integration tests: Add ui_driver method descriptions [PATCH] 433 Web UI integration

Re: [Freeipa-devel] [PATCH] 431-434 Web UI integration tests continuation

2013-07-23 Thread Ana Krivokapic
On 07/18/2013 01:35 PM, Petr Vobornik wrote: > On 07/18/2013 01:34 PM, Petr Vobornik wrote: >> [PATCH] 431 Web UI integration tests: Add trust tests >> >> [PATCH] 432 Web UI integration tests: Add ui_driver method descriptions >> >> [PATCH] 433 Web UI integration tests: Verify data after add and mo

Re: [Freeipa-devel] [PATCHES] 143-147 Improve performance with large groups

2013-07-23 Thread Petr Viktorin
On 07/23/2013 04:54 PM, Petr Viktorin wrote: On 07/23/2013 01:30 PM, Martin Kosek wrote: On 07/19/2013 01:10 PM, Petr Vobornik wrote: On 07/18/2013 05:29 PM, Jan Cholasta wrote: On 18.7.2013 17:26, Martin Kosek wrote: On 07/18/2013 05:22 PM, Jan Cholasta wrote: On 18.7.2013 17:07, Martin Kos

Re: [Freeipa-devel] [PATCH] slapi-nis support for trusted domains

2013-07-23 Thread Nalin Dahyabhai
On Tue, Jul 23, 2013 at 10:15:47AM +0300, Alexander Bokovoy wrote: > On Tue, 23 Jul 2013, Nalin Dahyabhai wrote: > >Apologies for the delay. > Thanks for the review! > > One short comment -- PAM code is from PAM pass-through plugin from > 389-ds. That's the reason why its code doesn't follow slapi

Re: [Freeipa-devel] [PATCHES] 143-147 Improve performance with large groups

2013-07-23 Thread Petr Viktorin
On 07/23/2013 01:30 PM, Martin Kosek wrote: On 07/19/2013 01:10 PM, Petr Vobornik wrote: On 07/18/2013 05:29 PM, Jan Cholasta wrote: On 18.7.2013 17:26, Martin Kosek wrote: On 07/18/2013 05:22 PM, Jan Cholasta wrote: On 18.7.2013 17:07, Martin Kosek wrote: On 07/18/2013 04:53 PM, Jan Cholast

Re: [Freeipa-devel] [PATCH] 0109-0110 Support querying AD DC when establishing trust as HTTP/ipa.server principal

2013-07-23 Thread Simo Sorce
On Tue, 2013-07-23 at 16:11 +0300, Alexander Bokovoy wrote: > On Tue, 23 Jul 2013, Simo Sorce wrote: > >On Thu, 2013-07-18 at 18:37 +0300, Alexander Bokovoy wrote: > >> Hi! > >> > >> Attached patches make possible to use HTTP/ipa.server@REALM to query AD > >> DC over LDAP immediately after trust is

Re: [Freeipa-devel] [PATCH] 430 Break long words in notification area

2013-07-23 Thread Petr Vobornik
On 07/22/2013 05:19 PM, Ana Krivokapic wrote: On 07/18/2013 12:58 PM, Petr Vobornik wrote: Long words (ie. service principal) breaks out of notification area. It doesn't look good. Patch adds word-wrap to break them to multiple pieces. Reproduction: modify a service in Web UI ACK Pushed t

Re: [Freeipa-devel] [PATCH] 436 Remove word 'field' from GECOS param label

2013-07-23 Thread Petr Vobornik
On 07/23/2013 01:12 PM, Ana Krivokapic wrote: On 07/23/2013 12:58 PM, Petr Vobornik wrote: On 07/22/2013 05:33 PM, Ana Krivokapic wrote: On 07/22/2013 09:01 AM, Martin Kosek wrote: On 07/19/2013 11:19 PM, Dmitri Pal wrote: On 07/19/2013 09:26 AM, Jan Pazdziora wrote: On Fri, Jul 19, 2013 at

Re: [Freeipa-devel] [PATCH 0076] Use AD LDAP probing to create trusted domain ID range

2013-07-23 Thread Alexander Bokovoy
On Tue, 23 Jul 2013, Tomas Babej wrote: This improved revision creates ranges of sizes that are multiples of default range size (20). ACK, works fine. Pushed to master. -- / Alexander Bokovoy ___ Freeipa-devel mailing list Freeipa-devel@redhat.

Re: [Freeipa-devel] [PATCH] 436 Remove word 'field' from GECOS param label

2013-07-23 Thread Petr Vobornik
On 07/23/2013 09:02 AM, Martin Kosek wrote: On 07/23/2013 01:31 AM, Dmitri Pal wrote: On 07/22/2013 08:38 AM, Petr Vobornik wrote: On 07/19/2013 11:19 PM, Dmitri Pal wrote: On 07/19/2013 09:26 AM, Jan Pazdziora wrote: On Fri, Jul 19, 2013 at 03:17:49PM +0200, Petr Vobornik wrote: Disclaimer:

Re: [Freeipa-devel] [PATCH] Two minor IPA KDB MS-PAC fixes

2013-07-23 Thread Alexander Bokovoy
On Tue, 23 Jul 2013, Jakub Hrozek wrote: clang found one branch with undefined variable return and one unused variable. ACK. Pushed both to master together with my 0109-0111 and Tomas' 0076 as your patches are on top of mine. -- / Alexander Bokovoy __

Re: [Freeipa-devel] [PATCH] 0109-0110 Support querying AD DC when establishing trust as HTTP/ipa.server principal

2013-07-23 Thread Alexander Bokovoy
On Tue, 23 Jul 2013, Simo Sorce wrote: On Thu, 2013-07-18 at 18:37 +0300, Alexander Bokovoy wrote: Hi! Attached patches make possible to use HTTP/ipa.server@REALM to query AD DC over LDAP immediately after trust is established. We need this to get range discovery working prior to creating range

[Freeipa-devel] [PATCH] Two minor IPA KDB MS-PAC fixes

2013-07-23 Thread Jakub Hrozek
clang found one branch with undefined variable return and one unused variable. >From 09962a9a40cd589c4694ecab4b4faa3c39e8a4a3 Mon Sep 17 00:00:00 2001 From: Jakub Hrozek Date: Tue, 23 Jul 2013 15:07:39 +0200 Subject: [PATCH 1/2] IPA KDB MS-PAC: return ENOMEM if allocation fails --- daemons/ipa-k

Re: [Freeipa-devel] [PATCH] 0109-0110 Support querying AD DC when establishing trust as HTTP/ipa.server principal

2013-07-23 Thread Simo Sorce
On Thu, 2013-07-18 at 18:37 +0300, Alexander Bokovoy wrote: > Hi! > > Attached patches make possible to use HTTP/ipa.server@REALM to query AD > DC over LDAP immediately after trust is established. We need this to get > range discovery working prior to creating range for trusted domain. > > The pa

Re: [Freeipa-devel] [PATCHES] 143-147 Improve performance with large groups

2013-07-23 Thread Martin Kosek
On 07/19/2013 01:10 PM, Petr Vobornik wrote: > On 07/18/2013 05:29 PM, Jan Cholasta wrote: >> On 18.7.2013 17:26, Martin Kosek wrote: >>> On 07/18/2013 05:22 PM, Jan Cholasta wrote: On 18.7.2013 17:07, Martin Kosek wrote: > On 07/18/2013 04:53 PM, Jan Cholasta wrote: >> Added patch whi

Re: [Freeipa-devel] [PATCH] 436 Remove word 'field' from GECOS param label

2013-07-23 Thread Ana Krivokapic
On 07/23/2013 12:58 PM, Petr Vobornik wrote: > On 07/22/2013 05:33 PM, Ana Krivokapic wrote: >> On 07/22/2013 09:01 AM, Martin Kosek wrote: >>> On 07/19/2013 11:19 PM, Dmitri Pal wrote: On 07/19/2013 09:26 AM, Jan Pazdziora wrote: > On Fri, Jul 19, 2013 at 03:17:49PM +0200, Petr Vobornik w

Re: [Freeipa-devel] [PATCH] 436 Remove word 'field' from GECOS param label

2013-07-23 Thread Petr Vobornik
On 07/22/2013 05:33 PM, Ana Krivokapic wrote: On 07/22/2013 09:01 AM, Martin Kosek wrote: On 07/19/2013 11:19 PM, Dmitri Pal wrote: On 07/19/2013 09:26 AM, Jan Pazdziora wrote: On Fri, Jul 19, 2013 at 03:17:49PM +0200, Petr Vobornik wrote: Disclaimer: I have no strong feelings in this matter,

Re: [Freeipa-devel] [PATCH 0076] Use AD LDAP probing to create trusted domain ID range

2013-07-23 Thread Tomas Babej
This improved revision creates ranges of sizes that are multiples of default range size (20). Tomas -- / Alexander Bokovoy From 629428d12fcfafdf2695dad2b2861980a18cceb4 Mon Sep 17 00:00:00 2001 From: Tomas Babej Date: Wed, 17 Jul 2013 15:55:36 +0200 Subject: [PATCH] Use AD LDAP probing to

Re: [Freeipa-devel] DNSSEC support design considerations: key material handling

2013-07-23 Thread Petr Spacek
On 19.7.2013 19:55, Simo Sorce wrote: I will reply to the rest of the message later if necessary, still digesting some of your answers, but I wanted to address the following first. On Fri, 2013-07-19 at 18:29 +0200, Petr Spacek wrote: The most important question at the moment is "What can we p

Re: [Freeipa-devel] [PATCH] slapi-nis support for trusted domains

2013-07-23 Thread Alexander Bokovoy
On Tue, 23 Jul 2013, Nalin Dahyabhai wrote: Apologies for the delay. Thanks for the review! One short comment -- PAM code is from PAM pass-through plugin from 389-ds. That's the reason why its code doesn't follow slapi-nis way and why it has that license. I tried to keep it mostly intact to sha

Re: [Freeipa-devel] [PATCH] 436 Remove word 'field' from GECOS param label

2013-07-23 Thread Martin Kosek
On 07/23/2013 01:31 AM, Dmitri Pal wrote: > On 07/22/2013 08:38 AM, Petr Vobornik wrote: >> On 07/19/2013 11:19 PM, Dmitri Pal wrote: >>> On 07/19/2013 09:26 AM, Jan Pazdziora wrote: On Fri, Jul 19, 2013 at 03:17:49PM +0200, Petr Vobornik wrote: > Disclaimer: I have no strong feelings in t