Re: [Freeipa-devel] [PATCH] add man page for ipa-kra-install

2014-08-25 Thread Petr Viktorin
On 08/24/2014 06:28 PM, Ade Lee wrote: Added man pages for ipa-kra-install. And its not even Tuesday yet :) Please review, Ade If I was new to this, I think I'd be quite lost. I think the man page should briefly explain what KRA is -- just a sentence would be fine. At the very least

Re: [Freeipa-devel] [PATCH] ipa trust-add command should be interactive

2014-08-25 Thread Jan Cholasta
The docstring of interactive_prompt_callback could use some tweaking, but besides that re-ACK. Dne 21.8.2014 v 14:50 Gabe Alford napsal(a): Hello, Just wondering if this needs to be re-ack'd. Thanks, Gabe On Thu, Jul 31, 2014 at 7:57 AM, Gabe Alford redhatri...@gmail.com

Re: [Freeipa-devel] [PATCH] ipa trust-add command should be interactive

2014-08-25 Thread Martin Kosek
Thanks. Pushed to: master: 9415aba87789512e34cb4ed62534cde7822ff70b ipa-4-1: 8bb2af0e0ca375e10a406883ada5769963813763 ipa-4-0: b708001074e1fc1e412bc18b1e5e0b408151847b Martin On 08/25/2014 12:00 PM, Jan Cholasta wrote: The docstring of interactive_prompt_callback could use some tweaking, but

Re: [Freeipa-devel] [PATCH] - Add DRM to IPA

2014-08-25 Thread Petr Viktorin
On 08/22/2014 03:28 PM, Petr Vobornik wrote: [...] Should the requirement of Dogtag 10.2 be reflected in a spec file? Yes. Sorry for forgetting that point in he review. We can do two things here: 1) Require Dogtag 10.2 (and ask developers to add the vakwetu-dogtag repo for ipa master) or

[Freeipa-devel] [PATCHES 0114-0115] DNS: allow to add root zone '.'

2014-08-25 Thread Martin Basti
Patches attached. Ticket: https://fedorahosted.org/freeipa/ticket/4149 There is a bug in bind-dyndb-ldap (or worse in dirsrv), which cause the named service is stopped after deleting zone. Bug ticket: https://fedorahosted.org/bind-dyndb-ldap/ticket/138 -- Martin Basti From

Re: [Freeipa-devel] [PATCH] - Add DRM to IPA

2014-08-25 Thread Ade Lee
We plan to do an alpha build of Dogtag 10.2 on Fedora 21 at the end of this week. Ade On Mon, 2014-08-25 at 13:14 +0200, Petr Viktorin wrote: On 08/22/2014 03:28 PM, Petr Vobornik wrote: [...] Should the requirement of Dogtag 10.2 be reflected in a spec file? Yes. Sorry for forgetting

Re: [Freeipa-devel] [PATCH] 0008 Use certmonger D-Bus API instead of messing with its files.

2014-08-25 Thread David Kupka
On 08/19/2014 05:44 PM, Rob Crittenden wrote: David Kupka wrote: On 08/19/2014 09:58 AM, Martin Kosek wrote: On 08/19/2014 09:05 AM, David Kupka wrote: FreeIPA will use certmonger D-Bus API as discussed in this thread https://www.redhat.com/archives/freeipa-devel/2014-July/msg00304.html This

[Freeipa-devel] [PATCH] 0009 Detect and configure all usable IP addresses.

2014-08-25 Thread David Kupka
https://fedorahosted.org/freeipa/ticket/3575 Also should fix https://bugzilla.redhat.com/show_bug.cgi?id=1128380 as installation is no longer interrupted when multiple IPs are resolved. But it does not add the option to change the IP address during second run. -- David Kupka From

Re: [Freeipa-devel] [PATCH] add man page for ipa-kra-install

2014-08-25 Thread Ade Lee
What if I add the following first paragraph? The KRA (Key Recovery Authority) is a component used to securely store secrets such as passwords, symmetric keys and private asymmetric keys. It is used as the back-end repository for the IPA Password Vault. Ade On Mon, 2014-08-25 at 10:28 +0200,

Re: [Freeipa-devel] [PATCH] add man page for ipa-kra-install

2014-08-25 Thread Petr Viktorin
On 08/25/2014 06:17 PM, Ade Lee wrote: What if I add the following first paragraph? The KRA (Key Recovery Authority) is a component used to securely store secrets such as passwords, symmetric keys and private asymmetric keys. It is used as the back-end repository for the IPA Password Vault.

[Freeipa-devel] [RFE] Backporting capabilities

2014-08-25 Thread Petr Viktorin
https://fedorahosted.org/freeipa/ticket/4427 Here is a design that enables backporting capabilities (i.e. backwards-incompatible API changes) to maintenance branches of FreeIPA. The premise is that no branched development occurs on the maintenance branch, only single targeted changes are

Re: [Freeipa-devel] [PATCH] add man page for ipa-kra-install

2014-08-25 Thread Ade Lee
New patch attached. If OK, please commit for me. Thanks, Ade On Mon, 2014-08-25 at 18:25 +0200, Petr Viktorin wrote: On 08/25/2014 06:17 PM, Ade Lee wrote: What if I add the following first paragraph? The KRA (Key Recovery Authority) is a component used to securely store secrets such as

[Freeipa-devel] [PATCH] CLIENT: Explicitly require python-backports-ssl_match_hostname

2014-08-25 Thread Jakub Hrozek
Hi, ipa-client-install was failing for me on a fresh F-21 machine until I manually dragged in python-backports-ssl_match_hostname From d5ff5ec7cb2ee0b3f116b4e9a25d2907bb8140d9 Mon Sep 17 00:00:00 2001 From: Jakub Hrozek jhro...@redhat.com Date: Mon, 25 Aug 2014 19:33:30 +0200 Subject: [PATCH]