Re: [Freeipa-devel] Generic support for unknown DNS RR types (RFC 3597)

2015-03-10 Thread Simo Sorce
On Tue, 2015-03-10 at 19:24 +0100, Petr Spacek wrote: > On 10.3.2015 18:36, Simo Sorce wrote: > > On Tue, 2015-03-10 at 18:26 +0100, Petr Spacek wrote: > >> On 10.3.2015 17:35, Simo Sorce wrote: > >>> On Tue, 2015-03-10 at 16:19 +0100, Petr Spacek wrote: > On 10.3.2015 15:53, Simo Sorce wrote:

Re: [Freeipa-devel] Generic support for unknown DNS RR types (RFC 3597)

2015-03-10 Thread Petr Spacek
On 10.3.2015 18:36, Simo Sorce wrote: > On Tue, 2015-03-10 at 18:26 +0100, Petr Spacek wrote: >> On 10.3.2015 17:35, Simo Sorce wrote: >>> On Tue, 2015-03-10 at 16:19 +0100, Petr Spacek wrote: On 10.3.2015 15:53, Simo Sorce wrote: > On Tue, 2015-03-10 at 15:32 +0100, Petr Spacek wrote: >>>

Re: [Freeipa-devel] Time-based account policies

2015-03-10 Thread John Dennis
On 03/10/2015 12:56 PM, Alexander Bokovoy wrote: > See my answer to John. We don't need to end up with iCal at all since > iCal doesn't have procedural definitions of holidays. It has > EXDATE/RRULE allowing to express exceptions and repeating rules (EXRULE > for exception rules was removed in RFC5

Re: [Freeipa-devel] Purpose of default user group

2015-03-10 Thread Alexander Bokovoy
On Tue, 10 Mar 2015, Simo Sorce wrote: On Tue, 2015-03-10 at 16:01 +0100, Jakub Hrozek wrote: On Tue, Mar 10, 2015 at 03:52:44PM +0100, Martin Kosek wrote: > On 03/10/2015 03:27 PM, Rob Crittenden wrote: > > Petr Vobornik wrote: > >> Hi, > >> > >> I would like to ask what is a purpose of a defau

Re: [Freeipa-devel] Time-based account policies

2015-03-10 Thread Alexander Bokovoy
On Tue, 10 Mar 2015, Martin Kosek wrote: On 03/10/2015 05:18 PM, Alexander Bokovoy wrote: On Tue, 10 Mar 2015, John Dennis wrote: On 03/10/2015 11:06 AM, Jakub Hrozek wrote: We may need to use libraries for processing iCal rules, like libical (http://koji.fedoraproject.org/koji/buildinfo?build

Re: [Freeipa-devel] Time-based account policies

2015-03-10 Thread Stanislav Láznička
On 03/10/2015 04:06 PM, Jakub Hrozek wrote: On Tue, Mar 10, 2015 at 03:47:10PM +0100, Martin Kosek wrote: This is where importing iCal is helpful because it allows you to outsource the task of creating such event to something else. Parsing event information would produce a rule definition we wo

Re: [Freeipa-devel] Generic support for unknown DNS RR types (RFC 3597)

2015-03-10 Thread Simo Sorce
On Tue, 2015-03-10 at 16:19 +0100, Petr Spacek wrote: > On 10.3.2015 15:53, Simo Sorce wrote: > > On Tue, 2015-03-10 at 15:32 +0100, Petr Spacek wrote: > >> Hello, > >> > >> I would like to discuss Generic support for unknown DNS RR types (RFC 3597 > >> [0]). Here is the proposal: > >> > >> LDAP sc

Re: [Freeipa-devel] Time-based account policies

2015-03-10 Thread Alexander Bokovoy
On Tue, 10 Mar 2015, Gabe Alford wrote: On Tue, Mar 10, 2015 at 9:51 AM, Stanislav Láznička wrote: On 03/10/2015 04:06 PM, Jakub Hrozek wrote: On Tue, Mar 10, 2015 at 03:47:10PM +0100, Martin Kosek wrote: This is where importing iCal is helpful because it allows you to outsource the task

Re: [Freeipa-devel] Time-based account policies

2015-03-10 Thread Alexander Bokovoy
On Tue, 10 Mar 2015, John Dennis wrote: On 03/10/2015 12:13 PM, Alexander Bokovoy wrote: HBAC rule is a tuple (user|group, host|hostgroup, service|servicegroup). This tuple would get extension representing time/date information in a multivalued attribute that would describe all time/date interva

Re: [Freeipa-devel] Time-based account policies

2015-03-10 Thread Martin Kosek
On 03/10/2015 05:18 PM, Alexander Bokovoy wrote: > On Tue, 10 Mar 2015, John Dennis wrote: >> On 03/10/2015 11:06 AM, Jakub Hrozek wrote: We may need to use libraries for processing iCal rules, like libical (http://koji.fedoraproject.org/koji/buildinfo?buildID=606329)... >>> >>> Is that w

Re: [Freeipa-devel] Time-based account policies

2015-03-10 Thread John Dennis
On 03/10/2015 12:13 PM, Alexander Bokovoy wrote: > HBAC rule is a tuple (user|group, host|hostgroup, service|servicegroup). > This tuple would get extension representing time/date information in a > multivalued attribute that would describe all time/date intervals > applicable to this rule. I must

Re: [Freeipa-devel] Time-based account policies

2015-03-10 Thread Alexander Bokovoy
On Tue, 10 Mar 2015, John Dennis wrote: On 03/10/2015 11:06 AM, Jakub Hrozek wrote: We may need to use libraries for processing iCal rules, like libical (http://koji.fedoraproject.org/koji/buildinfo?buildID=606329)... Is that what Alexander said, though? In his reply, I see: "Parsing event

Re: [Freeipa-devel] Time-based account policies

2015-03-10 Thread Alexander Bokovoy
On Tue, 10 Mar 2015, Stanislav Láznička wrote: On 03/10/2015 04:06 PM, Jakub Hrozek wrote: On Tue, Mar 10, 2015 at 03:47:10PM +0100, Martin Kosek wrote: This is where importing iCal is helpful because it allows you to outsource the task of creating such event to something else. Parsing event i

Re: [Freeipa-devel] Time-based account policies

2015-03-10 Thread Gabe Alford
On Tue, Mar 10, 2015 at 9:51 AM, Stanislav Láznička wrote: > On 03/10/2015 04:06 PM, Jakub Hrozek wrote: > >> On Tue, Mar 10, 2015 at 03:47:10PM +0100, Martin Kosek wrote: >> >>> This is where importing iCal is helpful because it allows you to outsource the task of creating such event to som

Re: [Freeipa-devel] Purpose of default user group

2015-03-10 Thread Petr Spacek
On 10.3.2015 16:55, Alexander Bokovoy wrote: > On Tue, 10 Mar 2015, Petr Spacek wrote: >> On 10.3.2015 16:01, Jakub Hrozek wrote: >>> On Tue, Mar 10, 2015 at 03:52:44PM +0100, Martin Kosek wrote: On 03/10/2015 03:27 PM, Rob Crittenden wrote: > Petr Vobornik wrote: >> Hi, >> >>

Re: [Freeipa-devel] Purpose of default user group

2015-03-10 Thread Alexander Bokovoy
On Tue, 10 Mar 2015, Petr Spacek wrote: On 10.3.2015 16:01, Jakub Hrozek wrote: On Tue, Mar 10, 2015 at 03:52:44PM +0100, Martin Kosek wrote: On 03/10/2015 03:27 PM, Rob Crittenden wrote: Petr Vobornik wrote: Hi, I would like to ask what is a purpose of a default user group - by default ipau

Re: [Freeipa-devel] Generic support for unknown DNS RR types (RFC 3597)

2015-03-10 Thread Petr Spacek
On 10.3.2015 16:22, Petr Vobornik wrote: > On 03/10/2015 03:53 PM, Simo Sorce wrote: >> On Tue, 2015-03-10 at 15:32 +0100, Petr Spacek wrote: >>> Hello, >>> >>> I would like to discuss Generic support for unknown DNS RR types (RFC 3597 >>> [0]). Here is the proposal: >>> >>> LDAP schema >>> ===

Re: [Freeipa-devel] [PATCHES 306-316] Automated migration tool from Winsync

2015-03-10 Thread Tomas Babej
On 03/09/2015 12:26 PM, Tomas Babej wrote: Hi, this couple of patches provides a initial implementation of the winsync migration tool: https://fedorahosted.org/freeipa/ticket/4524 Some parts could use some polishing, but this is a sound foundation. Tomas Attaching one more patch to th

Re: [Freeipa-devel] Generic support for unknown DNS RR types (RFC 3597)

2015-03-10 Thread Petr Vobornik
On 03/10/2015 03:53 PM, Simo Sorce wrote: On Tue, 2015-03-10 at 15:32 +0100, Petr Spacek wrote: Hello, I would like to discuss Generic support for unknown DNS RR types (RFC 3597 [0]). Here is the proposal: LDAP schema === - 1 new attribute: ( NAME 'GenericRecord' DESC 'unknown DNS rec

Re: [Freeipa-devel] Generic support for unknown DNS RR types (RFC 3597)

2015-03-10 Thread Petr Spacek
On 10.3.2015 15:53, Simo Sorce wrote: > On Tue, 2015-03-10 at 15:32 +0100, Petr Spacek wrote: >> Hello, >> >> I would like to discuss Generic support for unknown DNS RR types (RFC 3597 >> [0]). Here is the proposal: >> >> LDAP schema >> === >> - 1 new attribute: >> ( NAME 'GenericRecord' D

Re: [Freeipa-devel] Time-based account policies

2015-03-10 Thread Jakub Hrozek
On Tue, Mar 10, 2015 at 03:47:10PM +0100, Martin Kosek wrote: > > This is where importing iCal is helpful because it allows you to > > outsource the task of creating such event to something else. > > > > Parsing event information would produce a rule definition we would store > > and SSSD would ap

Re: [Freeipa-devel] Purpose of default user group

2015-03-10 Thread Jakub Hrozek
On Tue, Mar 10, 2015 at 03:52:44PM +0100, Martin Kosek wrote: > On 03/10/2015 03:27 PM, Rob Crittenden wrote: > > Petr Vobornik wrote: > >> Hi, > >> > >> I would like to ask what is a purpose of a default user group - by > >> default ipausers? Default group is also a required field in ipa config. >

Re: [Freeipa-devel] Generic support for unknown DNS RR types (RFC 3597)

2015-03-10 Thread Simo Sorce
On Tue, 2015-03-10 at 15:32 +0100, Petr Spacek wrote: > Hello, > > I would like to discuss Generic support for unknown DNS RR types (RFC 3597 > [0]). Here is the proposal: > > LDAP schema > === > - 1 new attribute: > ( NAME 'GenericRecord' DESC 'unknown DNS record, RFC 3597' EQUALITY > c

Re: [Freeipa-devel] Purpose of default user group

2015-03-10 Thread Martin Kosek
On 03/10/2015 03:27 PM, Rob Crittenden wrote: > Petr Vobornik wrote: >> Hi, >> >> I would like to ask what is a purpose of a default user group - by >> default ipausers? Default group is also a required field in ipa config. > > To be able to apply some (undefined) group policy to all users. I'm no

Re: [Freeipa-devel] Time-based account policies

2015-03-10 Thread Martin Kosek
On 03/10/2015 03:40 PM, Alexander Bokovoy wrote: > On Tue, 10 Mar 2015, Martin Kosek wrote: >> On 03/09/2015 07:22 PM, Alexander Bokovoy wrote: >>> On Mon, 09 Mar 2015, Jakub Hrozek wrote: On Mon, Mar 09, 2015 at 04:08:46PM +0100, Martin Kosek wrote: > On 03/09/2015 03:58 PM, Alexander Bok

Re: [Freeipa-devel] Time-based account policies

2015-03-10 Thread Alexander Bokovoy
On Tue, 10 Mar 2015, Martin Kosek wrote: On 03/10/2015 03:34 PM, Alexander Bokovoy wrote: On Tue, 10 Mar 2015, Simo Sorce wrote: On Tue, 2015-03-10 at 14:54 +0100, Martin Kosek wrote: On 03/09/2015 09:05 PM, Nathaniel McCallum wrote: > On Mon, 2015-03-09 at 22:02 +0200, Alexander Bokovoy wrote

Re: [Freeipa-devel] Time-based account policies

2015-03-10 Thread Alexander Bokovoy
On Tue, 10 Mar 2015, Martin Kosek wrote: On 03/09/2015 07:22 PM, Alexander Bokovoy wrote: On Mon, 09 Mar 2015, Jakub Hrozek wrote: On Mon, Mar 09, 2015 at 04:08:46PM +0100, Martin Kosek wrote: On 03/09/2015 03:58 PM, Alexander Bokovoy wrote: > On Mon, 09 Mar 2015, Martin Kosek wrote: ... > One

[Freeipa-devel] Generic support for unknown DNS RR types (RFC 3597)

2015-03-10 Thread Petr Spacek
Hello, I would like to discuss Generic support for unknown DNS RR types (RFC 3597 [0]). Here is the proposal: LDAP schema === - 1 new attribute: ( NAME 'GenericRecord' DESC 'unknown DNS record, RFC 3597' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 ) The attribute sh

Re: [Freeipa-devel] Time-based account policies

2015-03-10 Thread Martin Kosek
On 03/10/2015 03:34 PM, Alexander Bokovoy wrote: > On Tue, 10 Mar 2015, Simo Sorce wrote: >> On Tue, 2015-03-10 at 14:54 +0100, Martin Kosek wrote: >>> On 03/09/2015 09:05 PM, Nathaniel McCallum wrote: >>> > On Mon, 2015-03-09 at 22:02 +0200, Alexander Bokovoy wrote: >>> >> On Mon, 09 Mar 2015, Sim

Re: [Freeipa-devel] Time-based account policies

2015-03-10 Thread Alexander Bokovoy
On Tue, 10 Mar 2015, Simo Sorce wrote: On Tue, 2015-03-10 at 14:54 +0100, Martin Kosek wrote: On 03/09/2015 09:05 PM, Nathaniel McCallum wrote: > On Mon, 2015-03-09 at 22:02 +0200, Alexander Bokovoy wrote: >> On Mon, 09 Mar 2015, Simo Sorce wrote: ... >>> For some tasks 'local' is the only thing

Re: [Freeipa-devel] Purpose of default user group

2015-03-10 Thread Rob Crittenden
Petr Vobornik wrote: > Hi, > > I would like to ask what is a purpose of a default user group - by > default ipausers? Default group is also a required field in ipa config. To be able to apply some (undefined) group policy to all users. I'm not aware that it has ever been used for this. > In ipa

Re: [Freeipa-devel] Time-based account policies

2015-03-10 Thread Simo Sorce
On Tue, 2015-03-10 at 15:00 +0100, Martin Kosek wrote: > On 03/09/2015 07:22 PM, Alexander Bokovoy wrote: > > On Mon, 09 Mar 2015, Jakub Hrozek wrote: > >> On Mon, Mar 09, 2015 at 04:08:46PM +0100, Martin Kosek wrote: > >>> On 03/09/2015 03:58 PM, Alexander Bokovoy wrote: > >>> > On Mon, 09 Mar 201

Re: [Freeipa-devel] Time-based account policies

2015-03-10 Thread Simo Sorce
On Tue, 2015-03-10 at 14:54 +0100, Martin Kosek wrote: > On 03/09/2015 09:05 PM, Nathaniel McCallum wrote: > > On Mon, 2015-03-09 at 22:02 +0200, Alexander Bokovoy wrote: > >> On Mon, 09 Mar 2015, Simo Sorce wrote: > ... > >>> For some tasks 'local' is the only thing that makes sense (your > >>> m

Re: [Freeipa-devel] Time-based account policies

2015-03-10 Thread Martin Kosek
On 03/09/2015 07:22 PM, Alexander Bokovoy wrote: > On Mon, 09 Mar 2015, Jakub Hrozek wrote: >> On Mon, Mar 09, 2015 at 04:08:46PM +0100, Martin Kosek wrote: >>> On 03/09/2015 03:58 PM, Alexander Bokovoy wrote: >>> > On Mon, 09 Mar 2015, Martin Kosek wrote: >>> ... >>> > One of bigger issues we had

Re: [Freeipa-devel] Time-based account policies

2015-03-10 Thread Martin Kosek
On 03/09/2015 09:05 PM, Nathaniel McCallum wrote: > On Mon, 2015-03-09 at 22:02 +0200, Alexander Bokovoy wrote: >> On Mon, 09 Mar 2015, Simo Sorce wrote: ... >>> For some tasks 'local' is the only thing that makes sense (your >>> morning alarm clock), for other things 'UTC' is the only thing >>>

Re: [Freeipa-devel] [PATCH] Use curl instead of wget

2015-03-10 Thread Tomas Babej
On 01/22/2015 04:01 PM, Alexander Bokovoy wrote: On Thu, 22 Jan 2015, Colin Walters wrote: On Thu, Jan 22, 2015, at 08:45 AM, Alexander Bokovoy wrote: We have abstraction layer to take care of different platforms on a wider scale than just this particular binary. We are gradually moving all

Re: [Freeipa-devel] [PATCH 142] extdom: fix memory leak

2015-03-10 Thread Tomas Babej
On 03/10/2015 12:10 PM, Sumit Bose wrote: On Tue, Mar 10, 2015 at 11:59:45AM +0100, Tomas Babej wrote: On 03/05/2015 08:00 AM, Alexander Bokovoy wrote: On Wed, 04 Mar 2015, Nathan Kinder wrote: On 03/04/2015 10:34 PM, Alexander Bokovoy wrote: On Wed, 04 Mar 2015, Sumit Bose wrote: Hi, whi

Re: [Freeipa-devel] [PATCH 142] extdom: fix memory leak

2015-03-10 Thread Sumit Bose
On Tue, Mar 10, 2015 at 11:59:45AM +0100, Tomas Babej wrote: > > On 03/05/2015 08:00 AM, Alexander Bokovoy wrote: > >On Wed, 04 Mar 2015, Nathan Kinder wrote: > >> > >> > >>On 03/04/2015 10:34 PM, Alexander Bokovoy wrote: > >>>On Wed, 04 Mar 2015, Sumit Bose wrote: > Hi, > > while run

Re: [Freeipa-devel] [PATCH 142] extdom: fix memory leak

2015-03-10 Thread Tomas Babej
On 03/05/2015 08:00 AM, Alexander Bokovoy wrote: On Wed, 04 Mar 2015, Nathan Kinder wrote: On 03/04/2015 10:34 PM, Alexander Bokovoy wrote: On Wed, 04 Mar 2015, Sumit Bose wrote: Hi, while running 389ds with valgrind to see if my other patches introduced a memory leak I found an older on

Re: [Freeipa-devel] [PATCH] extdom: return LDAP_NO_SUCH_OBJECT to the client

2015-03-10 Thread Tomas Babej
On 03/05/2015 07:28 AM, Alexander Bokovoy wrote: On Wed, 04 Mar 2015, Sumit Bose wrote: Hi, with this patch the extdom plugin will properly indicate to a client if the search object does not exist instead of returning a generic error. This is important for the client to act accordingly and imp

[Freeipa-devel] Purpose of default user group

2015-03-10 Thread Petr Vobornik
Hi, I would like to ask what is a purpose of a default user group - by default ipausers? Default group is also a required field in ipa config. In ipa migrate-ds we also set the group to all users who are not member of anything. Why is it important for a user to be a member of a group? Thank

Re: [Freeipa-devel] Rename IPAv3_AD_trust_setup?

2015-03-10 Thread Alexander Bokovoy
On Tue, 10 Mar 2015, Martin Kosek wrote: Hi, I just saw someone refer to [1] with respect to FreeIPA 4.x. Would it make sense to just rename the page from [1] to [2] (with keeping redirect of course)? This would move the page from Howto/ name space which we use for community HOWTO articles and

[Freeipa-devel] Rename IPAv3_AD_trust_setup?

2015-03-10 Thread Martin Kosek
Hi, I just saw someone refer to [1] with respect to FreeIPA 4.x. Would it make sense to just rename the page from [1] to [2] (with keeping redirect of course)? This would move the page from Howto/ name space which we use for community HOWTO articles and move it to standard default name space. We