[Freeipa-devel] [PATCH] 0002 - User Life Cycle (create containers and scoping DS plugins)

2014-06-30 Thread thierry bordaz
Hello This patch (RF3813) setup DS plugins and containers required for User life cycle * creation of the Stage/Delete containers (Active container already exists) * attribute uniqueness (uid, ipaUniqueID, krbCanonicalName, krbPrincipalName) will be enforced across

Re: [Freeipa-devel] [PATCH] 692 webui: capitalize labels of undo and undo all buttons

2014-06-30 Thread Fraser Tweedale
On Fri, Jun 27, 2014 at 02:11:47PM +0200, Petr Vobornik wrote: Make the label of these buttons consistent with other buttons which have capital first letters. -- Petr Vobornik From 7214242fb0c5accc45b6af476a8ff7e7b1a7883f Mon Sep 17 00:00:00 2001 From: Petr Vobornik pvobo...@redhat.com

Re: [Freeipa-devel] [PATCH 0070] Normalization check only for IDNA domains

2014-06-30 Thread Martin Basti
On Fri, 2014-06-27 at 12:21 +0200, Petr Spacek wrote: On 27.6.2014 12:20, Alexander Bokovoy wrote: On Fri, 27 Jun 2014, Petr Spacek wrote: On 27.6.2014 12:04, Alexander Bokovoy wrote: diff --git a/ipalib/parameters.py b/ipalib/parameters.py index 1dff13c..09fed28 100644 ---

[Freeipa-devel] [PATCH] 0003 - User Life Cycle (prevent ipaUniqueID generation in provisioning)

2014-06-30 Thread thierry bordaz
This fix is to prevent IPA UUID DS plugin to generate a ipaUniqueID for users in provisioning container (Stage/Delete). thanks thierry From c06af590b11a3692dcd1afc4a52e724aab59173d Mon Sep 17 00:00:00 2001 From: Thierry bordaz (tbordaz) tbor...@redhat.com Date: Wed, 25 Jun 2014 12:49:45 +0200

Re: [Freeipa-devel] Reorganization of Web UI navigation items

2014-06-30 Thread Martin Kosek
On 06/27/2014 07:27 PM, Petr Vobornik wrote: On 2.6.2014 15:59, Petr Vobornik wrote: Hi List, the purpose if this mail is to start a discussion about reorganization of navigation items. Users are not fond of such change so we should come up with a solution which would last for some time.

Re: [Freeipa-devel] [PATCH 0070] Normalization check only for IDNA domains

2014-06-30 Thread Martin Basti
On Fri, 2014-06-27 at 14:03 +0300, Alexander Bokovoy wrote: On Fri, 27 Jun 2014, Martin Kosek wrote: On 06/27/2014 12:10 PM, Alexander Bokovoy wrote: On Fri, 27 Jun 2014, Petr Spacek wrote: On 27.6.2014 11:21, Jan Cholasta wrote: On 27.6.2014 10:58, Alexander Bokovoy wrote: On Fri, 27

Re: [Freeipa-devel] [PATCH 0070] Normalization check only for IDNA domains

2014-06-30 Thread Alexander Bokovoy
On Mon, 30 Jun 2014, Martin Basti wrote: On Fri, 2014-06-27 at 14:03 +0300, Alexander Bokovoy wrote: On Fri, 27 Jun 2014, Martin Kosek wrote: On 06/27/2014 12:10 PM, Alexander Bokovoy wrote: On Fri, 27 Jun 2014, Petr Spacek wrote: On 27.6.2014 11:21, Jan Cholasta wrote: On 27.6.2014 10:58,

Re: [Freeipa-devel] [PATCH] 692 webui: capitalize labels of undo and undo all buttons

2014-06-30 Thread Petr Vobornik
On 30.6.2014 09:13, Fraser Tweedale wrote: On Fri, Jun 27, 2014 at 02:11:47PM +0200, Petr Vobornik wrote: Make the label of these buttons consistent with other buttons which have capital first letters. -- Petr Vobornik From 7214242fb0c5accc45b6af476a8ff7e7b1a7883f Mon Sep 17 00:00:00 2001

Re: [Freeipa-devel] [PATCH] 472 Let Host Administrators use host-disable command

2014-06-30 Thread Petr Viktorin
On 06/27/2014 05:18 PM, Martin Kosek wrote: On 06/27/2014 05:16 PM, Simo Sorce wrote: On Fri, 2014-06-27 at 17:12 +0200, Martin Kosek wrote: On 06/27/2014 05:10 PM, Simo Sorce wrote: On Fri, 2014-06-27 at 16:16 +0200, Martin Kosek wrote: Host Administrators could not write to service keytab

Re: [Freeipa-devel] [PATCH] 472 Let Host Administrators use host-disable command

2014-06-30 Thread Martin Kosek
On 06/30/2014 10:55 AM, Petr Viktorin wrote: On 06/27/2014 05:18 PM, Martin Kosek wrote: On 06/27/2014 05:16 PM, Simo Sorce wrote: On Fri, 2014-06-27 at 17:12 +0200, Martin Kosek wrote: On 06/27/2014 05:10 PM, Simo Sorce wrote: On Fri, 2014-06-27 at 16:16 +0200, Martin Kosek wrote: Host

Re: [Freeipa-devel] [PATCH] 470 Add python-yubico to BuildRequires

2014-06-30 Thread Tomas Babej
Please note that python-yubico package is currently available in F20 updates-testing repository only. On 06/27/2014 10:18 AM, Martin Kosek wrote: python-yubico needs to be on a machine to be able to build FreeIPA. Without it, even ./makeapi and ./makeaci fails. -- Pushed to master under

Re: [Freeipa-devel] [PATCH] 472 Let Host Administrators use host-disable command

2014-06-30 Thread Petr Viktorin
On 06/30/2014 10:58 AM, Martin Kosek wrote: On 06/30/2014 10:55 AM, Petr Viktorin wrote: On 06/27/2014 05:18 PM, Martin Kosek wrote: On 06/27/2014 05:16 PM, Simo Sorce wrote: On Fri, 2014-06-27 at 17:12 +0200, Martin Kosek wrote: On 06/27/2014 05:10 PM, Simo Sorce wrote: On Fri, 2014-06-27

[Freeipa-devel] [PATCH] 0610 Allow admins to write krbLoginFailedCount

2014-06-30 Thread Petr Viktorin
Fix for https://fedorahosted.org/freeipa/ticket/4409 -- Petr³ ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel

Re: [Freeipa-devel] [PATCH] 683-690 webui: OTP token sync

2014-06-30 Thread Petr Vobornik
On 28.6.2014 01:59, Endi Sukma Dewata wrote: On 6/26/2014 9:11 AM, Petr Vobornik wrote: This set of patches creates page(s) for OTP Token Sync. there are two options: 1. from login page by Sync OTP Token link. - user can navigate between those two pages 2. standalone page on

[Freeipa-devel] [PATCH 0082] Forward zones: add warning about forwarders semantic change in dnszone-add/mod

2014-06-30 Thread Martin Basti
Ticket: https://fedorahosted.org/freeipa/ticket/3210#comment:16 Patch attached. -- Martin^2 Basti From 9334ebbe6f7965496faec63c15324dfc3eea6471 Mon Sep 17 00:00:00 2001 From: Martin Basti mba...@redhat.com Date: Mon, 30 Jun 2014 11:58:46 +0200 Subject: [PATCH] Add warning about semantic change

[Freeipa-devel] [PATCH 0083] Add DNSSEC experimental support warning message

2014-06-30 Thread Martin Basti
Patch attached. -- Martin^2 Basti From e29d8a89485fa9f36446517b69a0082c4a85f747 Mon Sep 17 00:00:00 2001 From: Martin Basti mba...@redhat.com Date: Mon, 30 Jun 2014 12:32:31 +0200 Subject: [PATCH] Add DNSSEC experimental support warning message Ticket:

Re: [Freeipa-devel] [PATCH] 691 webui-ci: fix action list action visibility and enablement assertion

2014-06-30 Thread Petr Vobornik
On 28.6.2014 02:04, Endi Sukma Dewata wrote: On 6/26/2014 9:15 AM, Petr Vobornik wrote: Fixes CA-less CI test fail The new html structure was not addressed properly. The new code is checking for the 'disabled' class in the list element, not the link element, is this correct? is_enabled =

[Freeipa-devel] [PATCH 0237] ipa-client-install: Restart nisdomain service instead of

2014-06-30 Thread Tomas Babej
Hi, To ensure new NIS domain name is loaded after ipa-client-install even in case when nisdomainname service is already running, we need to restart the service rather than starting it. https://fedorahosted.org/freeipa/ticket/4393 -- Tomas Babej Associate Software Engineer | Red Hat | Identity

Re: [Freeipa-devel] [PATCH] 677 webui: support unlock user command

2014-06-30 Thread Petr Vobornik
On 27.6.2014 18:09, Endi Sukma Dewata wrote: On 6/24/2014 10:44 AM, Petr Vobornik wrote: Call user-unlock command from Web UI. It will unlock displayed user on current master. related to: https://fedorahosted.org/freeipa/ticket/2792 Looks like there's a server problem (ticket #4409), but

Re: [Freeipa-devel] [PATCH] 680-682 webui: validation reporting improvements

2014-06-30 Thread Petr Vobornik
On 30.6.2014 06:41, Fraser Tweedale wrote: On Fri, Jun 27, 2014 at 10:54:39AM +0200, Petr Vobornik wrote: On 27.6.2014 09:48, Fraser Tweedale wrote: On Wed, Jun 25, 2014 at 06:58:52PM +0200, Petr Vobornik wrote: Patch 618 fixes a bug. Patches 680 and 681 were implemented along with it. They

Re: [Freeipa-devel] [PATCH] 470 Add python-yubico to BuildRequires

2014-06-30 Thread Martin Kosek
Right. I assume that Nathaniel would soon move that to stable updates repository if no blocking issue emerges. Martin On 06/30/2014 12:17 PM, Tomas Babej wrote: Please note that python-yubico package is currently available in F20 updates-testing repository only. On 06/27/2014 10:18 AM,

Re: [Freeipa-devel] [PATCH 0237] ipa-client-install: Restart nisdomain service instead of

2014-06-30 Thread Alexander Bokovoy
On Mon, 30 Jun 2014, Tomas Babej wrote: Hi, To ensure new NIS domain name is loaded after ipa-client-install even in case when nisdomainname service is already running, we need to restart the service rather than starting it. https://fedorahosted.org/freeipa/ticket/4393 ACK. -- / Alexander

Re: [Freeipa-devel] [PATCH] 470 Add python-yubico to BuildRequires

2014-06-30 Thread Alexander Bokovoy
On Mon, 30 Jun 2014, Martin Kosek wrote: Right. I assume that Nathaniel would soon move that to stable updates repository if no blocking issue emerges. Also for those using automatic git master builds, python-yubico is in ipa-devel repo too. -- / Alexander Bokovoy

Re: [Freeipa-devel] [PATCH 0070] Normalization check only for IDNA domains

2014-06-30 Thread Martin Basti
On Mon, 2014-06-30 at 11:43 +0300, Alexander Bokovoy wrote: On Mon, 30 Jun 2014, Martin Basti wrote: On Fri, 2014-06-27 at 14:03 +0300, Alexander Bokovoy wrote: On Fri, 27 Jun 2014, Martin Kosek wrote: On 06/27/2014 12:10 PM, Alexander Bokovoy wrote: On Fri, 27 Jun 2014, Petr Spacek

[Freeipa-devel] [RFC] Release notes for FreeIPA 4.0

2014-06-30 Thread Martin Kosek
Hello all, We should start working on FreeIPA 4.0 release notes. Lot of work has been done, there is a lot if relase information we need to address. I created the first draft partially generated and updated from Trac enhancement tickets, including the ticket+design links:

Re: [Freeipa-devel] [PATCH] 0610 Allow admins to write krbLoginFailedCount

2014-06-30 Thread Martin Kosek
On 06/30/2014 12:32 PM, Petr Viktorin wrote: Fix for https://fedorahosted.org/freeipa/ticket/4409 I think something is missing here :-) ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel

Re: [Freeipa-devel] [PATCH 0082] Forward zones: add warning about forwarders semantic change in dnszone-add/mod

2014-06-30 Thread Petr Viktorin
On 06/30/2014 12:48 PM, Martin Basti wrote: Ticket: https://fedorahosted.org/freeipa/ticket/3210#comment:16 Patch attached. When you add a new message, you should also define a new class for it in messages.py with a new errno, not just reuse PublicMessage with a custom string. -- Petr³

Re: [Freeipa-devel] [PATCH] 0610 Allow admins to write krbLoginFailedCount

2014-06-30 Thread Petr Viktorin
On 06/30/2014 01:53 PM, Martin Kosek wrote: On 06/30/2014 12:32 PM, Petr Viktorin wrote: Fix for https://fedorahosted.org/freeipa/ticket/4409 I think something is missing here :-) Sorry for that. -- Petr³ From 36fa1e33b21791d722ccc91353273935f154b280 Mon Sep 17 00:00:00 2001 From: Petr

Re: [Freeipa-devel] [PATCH 0237] ipa-client-install: Restart nisdomain service instead of

2014-06-30 Thread Martin Kosek
On 06/30/2014 01:46 PM, Alexander Bokovoy wrote: On Mon, 30 Jun 2014, Tomas Babej wrote: Hi, To ensure new NIS domain name is loaded after ipa-client-install even in case when nisdomainname service is already running, we need to restart the service rather than starting it.

Re: [Freeipa-devel] [PATCH 0083] Add DNSSEC experimental support warning message

2014-06-30 Thread Martin Basti
On Mon, 2014-06-30 at 12:49 +0200, Martin Basti wrote: Patch attached. ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel Updated patch attached -- Martin^2 Basti From

Re: [Freeipa-devel] [PATCH] 472 Let Host Administrators use host-disable command

2014-06-30 Thread Simo Sorce
On Mon, 2014-06-30 at 12:19 +0200, Petr Viktorin wrote: On 06/30/2014 10:58 AM, Martin Kosek wrote: On 06/30/2014 10:55 AM, Petr Viktorin wrote: On 06/27/2014 05:18 PM, Martin Kosek wrote: On 06/27/2014 05:16 PM, Simo Sorce wrote: On Fri, 2014-06-27 at 17:12 +0200, Martin Kosek wrote:

Re: [Freeipa-devel] [PATCH] 472 Let Host Administrators use host-disable command

2014-06-30 Thread Petr Viktorin
On 06/30/2014 02:37 PM, Simo Sorce wrote: On Mon, 2014-06-30 at 12:19 +0200, Petr Viktorin wrote: On 06/30/2014 10:58 AM, Martin Kosek wrote: On 06/30/2014 10:55 AM, Petr Viktorin wrote: On 06/27/2014 05:18 PM, Martin Kosek wrote: On 06/27/2014 05:16 PM, Simo Sorce wrote: On Fri, 2014-06-27

Re: [Freeipa-devel] [PATCH 0070] Normalization check only for IDNA domains

2014-06-30 Thread Alexander Bokovoy
On Mon, 30 Jun 2014, Martin Basti wrote: We can use 'label = label.encode(ascii)' to detect if IDNA is needed, without idna.ToASCII() conversion, and then use: is_nonnorm = any(encodings.idna.nameprep(x) != x for x in labels) Sounds good but don't forget exceptions' handling. :) Updated

Re: [Freeipa-devel] Reorganization of Web UI navigation items

2014-06-30 Thread Kyle Baker
- Original Message - On 06/27/2014 07:27 PM, Petr Vobornik wrote: On 2.6.2014 15:59, Petr Vobornik wrote: Hi List, the purpose if this mail is to start a discussion about reorganization of navigation items. Users are not fond of such change so we should come up with a

Re: [Freeipa-devel] [PATCH] 680-682 webui: validation reporting improvements

2014-06-30 Thread Endi Sukma Dewata
On 6/27/2014 3:54 AM, Petr Vobornik wrote: On 27.6.2014 09:48, Fraser Tweedale wrote: On Wed, Jun 25, 2014 at 06:58:52PM +0200, Petr Vobornik wrote: Patch 618 fixes a bug. Patches 680 and 681 were implemented along with it. They address pspacek's usability rant :). [PATCH] 680 webui: show

Re: [Freeipa-devel] [PATCH] 0610 Allow admins to write krbLoginFailedCount

2014-06-30 Thread Martin Kosek
On 06/30/2014 01:58 PM, Petr Viktorin wrote: On 06/30/2014 01:53 PM, Martin Kosek wrote: On 06/30/2014 12:32 PM, Petr Viktorin wrote: Fix for https://fedorahosted.org/freeipa/ticket/4409 I think something is missing here :-) Sorry for that. Looks ok. Do we need to add the new remove

Re: [Freeipa-devel] [PATCH 0082] Forward zones: add warning about forwarders semantic change in dnszone-add/mod

2014-06-30 Thread Petr Spacek
On 30.6.2014 13:57, Petr Viktorin wrote: On 06/30/2014 12:48 PM, Martin Basti wrote: Ticket: https://fedorahosted.org/freeipa/ticket/3210#comment:16 Patch attached. When you add a new message, you should also define a new class for it in messages.py with a new errno, not just reuse

Re: [Freeipa-devel] [PATCH 0083] Add DNSSEC experimental support warning message

2014-06-30 Thread Petr Spacek
On 30.6.2014 14:33, Martin Basti wrote: On Mon, 2014-06-30 at 12:49 +0200, Martin Basti wrote: Patch attached. It works for me. Please change the string little bit, I have realized that we should ensure that file permissions are correct: chown named: * chmod u= * (the chmod part new)

Re: [Freeipa-devel] [PATCH 0083] Add DNSSEC experimental support warning message

2014-06-30 Thread Martin Basti
On Mon, 2014-06-30 at 16:57 +0200, Petr Spacek wrote: On 30.6.2014 14:33, Martin Basti wrote: On Mon, 2014-06-30 at 12:49 +0200, Martin Basti wrote: Patch attached. It works for me. Please change the string little bit, I have realized that we should ensure that file permissions are

Re: [Freeipa-devel] DNSSEC: IPA Installation/Upgrade

2014-06-30 Thread Martin Basti
On Tue, 2014-06-24 at 11:49 +0200, Petr Spacek wrote: On 23.6.2014 17:49, Martin Basti wrote: On Mon, 2014-06-23 at 17:44 +0200, Martin Basti wrote: Hello, I have following issues: #1 Upgrading existing replicas to support DNSSEC won't work for current design (replica-file as storage

Re: [Freeipa-devel] DNSSEC: IPA Installation/Upgrade

2014-06-30 Thread Simo Sorce
On Mon, 2014-06-30 at 17:13 +0200, Martin Basti wrote: On Tue, 2014-06-24 at 11:49 +0200, Petr Spacek wrote: On 23.6.2014 17:49, Martin Basti wrote: On Mon, 2014-06-23 at 17:44 +0200, Martin Basti wrote: Hello, I have following issues: #1 Upgrading existing replicas to support

[Freeipa-devel] [PATCH] 0611 install/ui/build: Build core.js

2014-06-30 Thread Petr Viktorin
IPA wouldn't build for me because of a Makefile problem. This should solve the issue. -- Petr³ From c1d2e90c41c8939f02c7fcb2613163dd05abe4aa Mon Sep 17 00:00:00 2001 From: Petr Viktorin pvikt...@redhat.com Date: Mon, 30 Jun 2014 17:39:17 +0200 Subject: [PATCH] install/ui/build: Build core.js

Re: [Freeipa-devel] [PATCH 0078-0079] DNSSEC: Add TLSA record

2014-06-30 Thread Petr Vobornik
On 27.6.2014 14:55, Martin Basti wrote: On Thu, 2014-06-26 at 13:57 +0200, Petr Vobornik wrote: On 25.6.2014 14:35, Martin Basti wrote: On Wed, 2014-06-25 at 14:31 +0200, Martin Basti wrote: Ticket https://fedorahosted.org/freeipa/ticket/4328#comment:12 Patches attached. Note: ACI will be

Re: [Freeipa-devel] [PATCH] 470 Add python-yubico to BuildRequires

2014-06-30 Thread Nathaniel McCallum
Please feel free to provide karma: https://admin.fedoraproject.org/updates/FEDORA-2014-7700/python-yubico-1.2.1-3.fc20 On Mon, 2014-06-30 at 13:40 +0200, Martin Kosek wrote: Right. I assume that Nathaniel would soon move that to stable updates repository if no blocking issue emerges. Martin

Re: [Freeipa-devel] [PATCH] 0611 install/ui/build: Build core.js

2014-06-30 Thread Petr Vobornik
On 30.6.2014 17:43, Petr Viktorin wrote: IPA wouldn't build for me because of a Makefile problem. This should solve the issue. ACK Pushed to master: dfbd7170e901bc597462191c219c0e2b45c09afa Sorry about that. -- Petr Vobornik ___ Freeipa-devel

Re: [Freeipa-devel] [PATCH 0077] Fix ACI in DNS (was Add dnssecinlinesigning attribute to ACI)

2014-06-30 Thread Petr Viktorin
On 06/25/2014 06:49 PM, Martin Basti wrote: On Wed, 2014-06-25 at 18:47 +0200, Martin Basti wrote: On Wed, 2014-06-25 at 12:13 +0200, Petr Viktorin wrote: On 06/20/2014 03:32 PM, Martin Basti wrote: Required patches: mbasti-0060, mbasti-0073 Patch attached. Hi, For the raw ACI in

Re: [Freeipa-devel] [PATCHES] 295-299 Allow changing chaining of the IPA CA certificate

2014-06-30 Thread Rob Crittenden
Rob Crittenden wrote: Jan Cholasta wrote: On 26.6.2014 20:05, Rob Crittenden wrote: Jan Cholasta wrote: On 16.6.2014 15:35, Jan Cholasta wrote: Hi, the attached patches implement https://fedorahosted.org/freeipa/ticket/3737. My patches 241-253 and 262-294 are required for this

Re: [Freeipa-devel] [PATCHES] 295-299 Allow changing chaining of the IPA CA certificate

2014-06-30 Thread Nalin Dahyabhai
On Fri, Jun 27, 2014 at 06:19:25PM -0400, Rob Crittenden wrote: How it is monitoring with a ca-error I don't know. If there's a previously-issued certificate present, the state machine goes back to monitoring rather than the dead-end rejected state, so that it'll try again later when certificate

[Freeipa-devel] [PATCH] 0612 permission plugin: Ignore unparseable ACIs

2014-06-30 Thread Petr Viktorin
Hello, The new ipaAllowedOperation ACIs cannot be parsed by the ACI parser. This made operations on ACIs on the same entry fail (because the plugin needs to go through all ACIs on the entry, parsing out the name, until it finds one with the correct name). This fixes the issue, and adds a

[Freeipa-devel] [PATCH] 1108 Remove smartproxy

2014-06-30 Thread Rob Crittenden
The Foreman Smart Proxy server has its own upstream now at https://fedorahosted.org/freeipa-foreman-smartproxy/ so this source is no longer needed. rob From 12ce774bc4e7867d583e6f80a1bc0a181e685d9c Mon Sep 17 00:00:00 2001 From: Rob Crittenden rcrit...@redhat.com Date: Mon, 30 Jun 2014 18:27:31