Re: [Freeipa-devel] Ipa-server-install Firewall Support

2014-04-10 Thread Martin Kosek
On 04/10/2014 02:57 AM, Dmitri Pal wrote: On 04/08/2014 02:42 PM, Rob Crittenden wrote: Justin Brown wrote: ... b) Example: freeipa-server-install --setup-dns --forwarder=192.168.0.2 --forwarder=192.168.0.3 Let's talk about CLI. Shouldn't we add just one option - --no-firewall? I would assume

Re: [Freeipa-devel] [PATCH] 0454 Test fixes

2014-04-10 Thread Misnyovszki Adam
On Tue, 25 Mar 2014 10:23:56 +0100 Petr Viktorin pvikt...@redhat.com wrote: On 01/28/2014 03:35 PM, Petr Viktorin wrote: On 01/23/2014 01:54 PM, Petr Viktorin wrote: [...] Patch 454 changes the cert generation script for CA-less tests to use sequential serial numbers rather than random

Re: [Freeipa-devel] [PATCH] 0454 Test fixes

2014-04-10 Thread Petr Viktorin
On 04/10/2014 11:58 AM, Misnyovszki Adam wrote: On Tue, 25 Mar 2014 10:23:56 +0100 Petr Viktorin pvikt...@redhat.com wrote: On 01/28/2014 03:35 PM, Petr Viktorin wrote: On 01/23/2014 01:54 PM, Petr Viktorin wrote: [...] Patch 454 changes the cert generation script for CA-less tests to use

[Freeipa-devel] [PATCH] 0514 Add mechanism for adding default permissions to privileges

2014-04-10 Thread Petr Viktorin
Hello, This allows adding default permissions to privileges. The privileges need to be created before the managed permission updater runs (e.g. via the file-based updater). My updated patch 0513 will use this. -- Petr³ From 2cea76be8acaddf9fa7af6c5212dc2b1d0c6d100 Mon Sep 17 00:00:00 2001

Re: [Freeipa-devel] [PATCH] 0513 Add managed read permissions to permission

2014-04-10 Thread Petr Viktorin
On 04/09/2014 05:17 PM, Martin Kosek wrote: On 04/09/2014 04:54 PM, Petr Viktorin wrote: The meta-permissions. :-) Read access is given to all authenticated users. Reading membership info (i.e. privileges) is split into a separate permission. Another permission is added that allows read

Re: [Freeipa-devel] [PATCH] 0506 Default read ACIs for hosts

2014-04-10 Thread Petr Viktorin
On 04/09/2014 12:25 PM, Martin Kosek wrote: On 04/03/2014 12:09 PM, Petr Viktorin wrote: Hello, This adds read permissions to read hosts. Read access is given to all authenticated users. For reading host membership info, there is a separate permission that also defaults to all authenticated

Re: [Freeipa-devel] [PATCH] 0514 Add mechanism for adding default permissions to privileges

2014-04-10 Thread Martin Kosek
On 04/10/2014 01:44 PM, Petr Viktorin wrote: Hello, This allows adding default permissions to privileges. The privileges need to be created before the managed permission updater runs (e.g. via the file-based updater). My updated patch 0513 will use this. ACK. Works fine. Pushed to

Re: [Freeipa-devel] [PATCH] 0506 Default read ACIs for hosts

2014-04-10 Thread Simo Sorce
On Thu, 2014-04-10 at 13:56 +0200, Petr Viktorin wrote: On 04/09/2014 12:25 PM, Martin Kosek wrote: On 04/03/2014 12:09 PM, Petr Viktorin wrote: Hello, This adds read permissions to read hosts. Read access is given to all authenticated users. For reading host membership info, there is

Re: [Freeipa-devel] [PATCH] 0513 Add managed read permissions to permission

2014-04-10 Thread Martin Kosek
On 04/10/2014 01:46 PM, Petr Viktorin wrote: On 04/09/2014 05:17 PM, Martin Kosek wrote: On 04/09/2014 04:54 PM, Petr Viktorin wrote: The meta-permissions. :-) Read access is given to all authenticated users. Reading membership info (i.e. privileges) is split into a separate permission.

Re: [Freeipa-devel] [PATCH] 0513 Add managed read permissions to permission

2014-04-10 Thread Petr Viktorin
On 04/10/2014 02:58 PM, Martin Kosek wrote: On 04/10/2014 01:46 PM, Petr Viktorin wrote: On 04/09/2014 05:17 PM, Martin Kosek wrote: On 04/09/2014 04:54 PM, Petr Viktorin wrote: The meta-permissions. :-) Read access is given to all authenticated users. Reading membership info (i.e.

Re: [Freeipa-devel] [PATCH] 0506 Default read ACIs for hosts

2014-04-10 Thread Martin Kosek
On 04/10/2014 02:52 PM, Simo Sorce wrote: On Thu, 2014-04-10 at 13:56 +0200, Petr Viktorin wrote: On 04/09/2014 12:25 PM, Martin Kosek wrote: On 04/03/2014 12:09 PM, Petr Viktorin wrote: Hello, This adds read permissions to read hosts. Read access is given to all authenticated users. For

Re: [Freeipa-devel] [PATCH] 0513 Add managed read permissions to permission

2014-04-10 Thread Martin Kosek
On 04/10/2014 03:02 PM, Petr Viktorin wrote: On 04/10/2014 02:58 PM, Martin Kosek wrote: On 04/10/2014 01:46 PM, Petr Viktorin wrote: On 04/09/2014 05:17 PM, Martin Kosek wrote: On 04/09/2014 04:54 PM, Petr Viktorin wrote: The meta-permissions. :-) Read access is given to all

Re: [Freeipa-devel] [PATCH] 0513 Add managed read permissions to permission

2014-04-10 Thread Simo Sorce
On Thu, 2014-04-10 at 15:02 +0200, Petr Viktorin wrote: On 04/10/2014 02:58 PM, Martin Kosek wrote: On 04/10/2014 01:46 PM, Petr Viktorin wrote: On 04/09/2014 05:17 PM, Martin Kosek wrote: On 04/09/2014 04:54 PM, Petr Viktorin wrote: The meta-permissions. :-) Read access is given

Re: [Freeipa-devel] [PATCH] 0513 Add managed read permissions to permission

2014-04-10 Thread Martin Kosek
On 04/10/2014 03:07 PM, Simo Sorce wrote: On Thu, 2014-04-10 at 15:02 +0200, Petr Viktorin wrote: On 04/10/2014 02:58 PM, Martin Kosek wrote: On 04/10/2014 01:46 PM, Petr Viktorin wrote: On 04/09/2014 05:17 PM, Martin Kosek wrote: On 04/09/2014 04:54 PM, Petr Viktorin wrote: The

Re: [Freeipa-devel] [PATCH] 0513 Add managed read permissions to permission

2014-04-10 Thread Petr Viktorin
On 04/10/2014 03:07 PM, Martin Kosek wrote: On 04/10/2014 03:02 PM, Petr Viktorin wrote: On 04/10/2014 02:58 PM, Martin Kosek wrote: On 04/10/2014 01:46 PM, Petr Viktorin wrote: On 04/09/2014 05:17 PM, Martin Kosek wrote: On 04/09/2014 04:54 PM, Petr Viktorin wrote: The meta-permissions.

Re: [Freeipa-devel] [PATCH] 0513 Add managed read permissions to permission

2014-04-10 Thread Martin Kosek
On 04/10/2014 03:10 PM, Petr Viktorin wrote: On 04/10/2014 03:07 PM, Martin Kosek wrote: On 04/10/2014 03:02 PM, Petr Viktorin wrote: On 04/10/2014 02:58 PM, Martin Kosek wrote: On 04/10/2014 01:46 PM, Petr Viktorin wrote: On 04/09/2014 05:17 PM, Martin Kosek wrote: On 04/09/2014 04:54 PM,

[Freeipa-devel] [PATCH] 0515 Add managed read permission for SELinux user map

2014-04-10 Thread Petr Viktorin
Read access is given to all authenticated users. -- Petr³ From 713b37bb023d7d895355a0cd8f8a4bb707d69d0f Mon Sep 17 00:00:00 2001 From: Petr Viktorin pvikt...@redhat.com Date: Wed, 26 Mar 2014 17:52:28 +0100 Subject: [PATCH] Add managed read permission for SELinux user map Part of the work for:

[Freeipa-devel] [PATCH] 0516 Add managed read permissions to realmdomains

2014-04-10 Thread Petr Viktorin
Read access is given to all authenticated users. -- Petr³ From fe73d63509aba200d94e7d50c0143881965f8701 Mon Sep 17 00:00:00 2001 From: Petr Viktorin pvikt...@redhat.com Date: Wed, 26 Mar 2014 17:11:23 +0100 Subject: [PATCH] Add managed read permissions to realmdomains Part of the work for:

Re: [Freeipa-devel] [PATCH] 260 Fix update_ca_renewal_master plugin on CA-less installs

2014-04-10 Thread Martin Kosek
On 04/02/2014 11:13 AM, Jan Cholasta wrote: Hi, the attached patch fixes https://fedorahosted.org/freeipa/ticket/4294. Honza Works for me in both CA-less and CA-ful, ACK. Pushed to master: 50c7f3b2366aa48a966a958a7f95941c917ad3fa Martin ___

Re: [Freeipa-devel] [PATCH] 0513 Add managed read permissions to RBAC objects

2014-04-10 Thread Petr Viktorin
On 04/10/2014 03:20 PM, Martin Kosek wrote: On 04/10/2014 03:10 PM, Petr Viktorin wrote: On 04/10/2014 03:07 PM, Martin Kosek wrote: On 04/10/2014 03:02 PM, Petr Viktorin wrote: On 04/10/2014 02:58 PM, Martin Kosek wrote: On 04/10/2014 01:46 PM, Petr Viktorin wrote: On 04/09/2014 05:17 PM,

Re: [Freeipa-devel] [PATCH] 0506 Default read ACIs for hosts

2014-04-10 Thread Petr Viktorin
On 04/10/2014 03:04 PM, Martin Kosek wrote: On 04/10/2014 02:52 PM, Simo Sorce wrote: On Thu, 2014-04-10 at 13:56 +0200, Petr Viktorin wrote: On 04/09/2014 12:25 PM, Martin Kosek wrote: On 04/03/2014 12:09 PM, Petr Viktorin wrote: Hello, This adds read permissions to read hosts. Read access

Re: [Freeipa-devel] [PATCH 0158] Extend ipa-range-check DS plugin to handle range types

2014-04-10 Thread Petr Viktorin
On 04/08/2014 02:26 PM, Martin Kosek wrote: On 04/01/2014 10:52 AM, Tomas Babej wrote: On 04/01/2014 10:40 AM, Alexander Bokovoy wrote: On Tue, 01 Apr 2014, Tomas Babej wrote: From 736b3f747188696fd4a46ca63d91a6cca942fd56 Mon Sep 17 00:00:00 2001 From: Tomas Babej tba...@redhat.com Date:

Re: [Freeipa-devel] Random Certificate Serial Numbers

2014-04-10 Thread Dmitri Pal
On 04/08/2014 09:55 AM, Ade Lee wrote: On Mon, 2014-04-07 at 09:48 +0200, Martin Kosek wrote: Hi Rob, Ade and others, In the past, Rob was investigating enabling random certificate serial numbers for FreeIPA PKI [1]. We also have a ticket [2] planned to enable it for 4.0. Can we simply switch

Re: [Freeipa-devel] [PATCHES] 241-253 CA certificate renewal

2014-04-10 Thread Rob Crittenden
Some in-line, a whole ton of data appended to end. Jan Cholasta wrote: On 7.4.2014 20:09, Rob Crittenden wrote: Rob Crittenden wrote: Jan Cholasta wrote: Hi, the attached patches implement automatic CA certificate renewal as well as the initial version of the CA certificate management tool.