Re: [Freeipa-devel] FreeIPA 4.2 Alpha preparations

2015-06-18 Thread Petr Vobornik
On 06/17/2015 05:44 PM, Martin Kosek wrote: On 06/17/2015 12:31 PM, Fraser Tweedale wrote: On Wed, Jun 17, 2015 at 07:55:10AM +0200, Martin Kosek wrote: On 06/16/2015 05:29 PM, Fraser Tweedale wrote: On Tue, Jun 16, 2015 at 05:10:00PM +0200, Martin Kosek wrote: On 06/12/2015 11:34 AM, Martin

Re: [Freeipa-devel] [PATCH 0256] DNS: add UnknonwRecord attribute to schema

2015-06-18 Thread Petr Vobornik
On 06/11/2015 04:55 PM, Petr Spacek wrote: On 22.5.2015 14:14, Martin Basti wrote: Patch attached. Initial part of https://fedorahosted.org/freeipa/ticket/4939 ACK Pushed to master: 3ababb763b93af4012705d59d2f55801d172835c -- Petr Vobornik -- Manage your subscription for the

Re: [Freeipa-devel] [PATCH] 0005 User life cycle: del/mod/find/show stageuser commands

2015-06-18 Thread Simo Sorce
On Thu, 2015-06-18 at 09:30 +0200, Jan Cholasta wrote: Dne 15.6.2015 v 17:29 thierry bordaz napsal(a): On 06/15/2015 05:00 PM, Simo Sorce wrote: On Mon, 2015-06-15 at 16:48 +0200, Petr Vobornik wrote: On 06/09/2015 02:02 PM, Jan Cholasta wrote: Dne 20.5.2015 v 11:26 Jan Cholasta

Re: [Freeipa-devel] [PATCH] 0005 User life cycle: del/mod/find/show stageuser commands

2015-06-18 Thread David Kupka
Dne 18.6.2015 v 13:22 Petr Vobornik napsal(a): On 06/18/2015 12:52 PM, Jan Cholasta wrote: Dne 18.6.2015 v 09:30 Jan Cholasta napsal(a): Dne 15.6.2015 v 17:29 thierry bordaz napsal(a): On 06/15/2015 05:00 PM, Simo Sorce wrote: On Mon, 2015-06-15 at 16:48 +0200, Petr Vobornik wrote: On

[Freeipa-devel] [PATCH 0035] Bump run-time requires to SoftHSM 2.0.0rc1

2015-06-18 Thread Petr Spacek
Hello, Another easytest! :-) Bump run-time requires to SoftHSM 2.0.0rc1. This is necessary to make DNSSEC support functional. Unfortunately my previous patch updated BuildRequires but I forgot to bump the same in Requires. Please get push it into alpha if possible. Thanks! -- Petr^2 Spacek

Re: [Freeipa-devel] with new cert profiles patches ipa-replica-prepare fails after update

2015-06-18 Thread Jan Cholasta
Dne 17.6.2015 v 12:26 Fraser Tweedale napsal(a): On Fri, Jun 12, 2015 at 03:47:38PM +0200, Petr Vobornik wrote: On 06/12/2015 03:18 PM, Fraser Tweedale wrote: On Thu, Jun 11, 2015 at 09:59:03AM +0200, Martin Babinsky wrote: On 06/04/2015 04:03 PM, Petr Vobornik wrote: - ipa-replica-prepare

[Freeipa-devel] [PATCH 0032-0034] Clarify DNS error messages in ipa-replica-prepare

2015-06-18 Thread Petr Spacek
Easytest! :-) -- Petr^2 Spacek From 8c9af1e8e15f0b0a37c554bbbfab176b9558f943 Mon Sep 17 00:00:00 2001 From: Petr Spacek pspa...@redhat.com Date: Thu, 18 Jun 2015 12:56:09 +0200 Subject: [PATCH] Improve error messages about reverse address resolution in ipa-replica-prepare ---

Re: [Freeipa-devel] FreeIPA 4.2 Alpha preparations

2015-06-18 Thread Ludwig Krispenz
Hi, I think you did not yet (want) to push patch0014 about one directional segments. In that case we should add something that the addition of one directional segments id not recommended (failure in some cases to chheck duplicates or removing agreements when deleting a merged segment).

Re: [Freeipa-devel] [PATCH 0032-0034] Clarify DNS error messages in ipa-replica-prepare

2015-06-18 Thread Martin Basti
On 18/06/15 13:36, Petr Spacek wrote: Easytest! :-) ACK -- Martin Basti -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Re: [Freeipa-devel] [PATCH 0041] add DS index for userCertificate attribute

2015-06-18 Thread Martin Basti
On 16/06/15 18:03, Martin Babinsky wrote: Related to http://www.freeipa.org/page/V4/User_Certificates and https://fedorahosted.org/freeipa/ticket/4238 ACK -- Martin Basti -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel

Re: [Freeipa-devel] [PATCH 0266] ipa-ca-install fix: reconnect ldap2 after DS restart

2015-06-18 Thread Martin Babinsky
On 06/17/2015 02:28 PM, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/5064 Patch attached. ACK -- Martin^3 Babinsky -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

Re: [Freeipa-devel] [PATCH] 0005 User life cycle: del/mod/find/show stageuser commands

2015-06-18 Thread Petr Vobornik
On 06/18/2015 12:52 PM, Jan Cholasta wrote: Dne 18.6.2015 v 09:30 Jan Cholasta napsal(a): Dne 15.6.2015 v 17:29 thierry bordaz napsal(a): On 06/15/2015 05:00 PM, Simo Sorce wrote: On Mon, 2015-06-15 at 16:48 +0200, Petr Vobornik wrote: On 06/09/2015 02:02 PM, Jan Cholasta wrote: Dne

Re: [Freeipa-devel] with new cert profiles patches ipa-replica-prepare fails after update

2015-06-18 Thread Petr Vobornik
On 06/18/2015 02:43 PM, David Kupka wrote: Dne 18.6.2015 v 13:18 Jan Cholasta napsal(a): Dne 17.6.2015 v 12:26 Fraser Tweedale napsal(a): On Fri, Jun 12, 2015 at 03:47:38PM +0200, Petr Vobornik wrote: On 06/12/2015 03:18 PM, Fraser Tweedale wrote: On Thu, Jun 11, 2015 at 09:59:03AM +0200,

Re: [Freeipa-devel] [PATCH 0032-0034] Clarify DNS error messages in ipa-replica-prepare

2015-06-18 Thread Petr Vobornik
On 06/18/2015 02:50 PM, Martin Basti wrote: On 18/06/15 13:36, Petr Spacek wrote: Easytest! :-) ACK pushed to master: * 3c95a5aea23b6deb9d9b91799d9fd29ab25a6d78 Improve error messages about reverse address resolution in ipa-replica-prepare * 6259be5fd6010d7e77101769e3421e6f3a141b0b

Re: [Freeipa-devel] [PATCH 0035] Bump run-time requires to SoftHSM 2.0.0rc1

2015-06-18 Thread Petr Vobornik
On 06/18/2015 01:49 PM, Petr Spacek wrote: Hello, Another easytest! :-) Bump run-time requires to SoftHSM 2.0.0rc1. This is necessary to make DNSSEC support functional. Unfortunately my previous patch updated BuildRequires but I forgot to bump the same in Requires. Please get push it into

Re: [Freeipa-devel] [PATCH 0041] add DS index for userCertificate attribute

2015-06-18 Thread Petr Vobornik
On 06/18/2015 02:59 PM, Martin Basti wrote: On 16/06/15 18:03, Martin Babinsky wrote: Related to http://www.freeipa.org/page/V4/User_Certificates and https://fedorahosted.org/freeipa/ticket/4238 ACK Pushed to master: 3bea4418089dc97136040cfc58157a77aea8b0aa -- Petr Vobornik -- Manage

Re: [Freeipa-devel] [PATCH] 0005 User life cycle: del/mod/find/show stageuser commands

2015-06-18 Thread Martin Kosek
On 06/18/2015 01:22 PM, Petr Vobornik wrote: On 06/18/2015 12:52 PM, Jan Cholasta wrote: Dne 18.6.2015 v 09:30 Jan Cholasta napsal(a): Dne 15.6.2015 v 17:29 thierry bordaz napsal(a): On 06/15/2015 05:00 PM, Simo Sorce wrote: On Mon, 2015-06-15 at 16:48 +0200, Petr Vobornik wrote: On

Re: [Freeipa-devel] [PATCH 0266] ipa-ca-install fix: reconnect ldap2 after DS restart

2015-06-18 Thread Martin Basti
On 18/06/15 15:04, Martin Babinsky wrote: On 06/17/2015 02:28 PM, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/5064 Patch attached. ACK Rebased patch attached. -- Martin Basti From e6827b6993706d16831af24e8be7d1ccec4c4975 Mon Sep 17 00:00:00 2001 From: Martin Basti

Re: [Freeipa-devel] [PATCH] 0005 User life cycle: del/mod/find/show stageuser commands

2015-06-18 Thread Petr Vobornik
On 06/18/2015 03:42 PM, David Kupka wrote: Dne 18.6.2015 v 13:22 Petr Vobornik napsal(a): On 06/18/2015 12:52 PM, Jan Cholasta wrote: Dne 18.6.2015 v 09:30 Jan Cholasta napsal(a): Dne 15.6.2015 v 17:29 thierry bordaz napsal(a): On 06/15/2015 05:00 PM, Simo Sorce wrote: On Mon, 2015-06-15 at

Re: [Freeipa-devel] Community Portal Prototype

2015-06-18 Thread Petr Spacek
On 18.6.2015 16:09, Drew Erny wrote: On 06/18/2015 03:53 AM, Petr Spacek wrote: On 17.6.2015 21:21, Drew Erny wrote: a) Most importantly, obtaining credentials for authentication to the FreeIPA server is completely missing. You need to 'somehow' fill in Kerberos credential cache with a valid

Re: [Freeipa-devel] [PATCH 0266] ipa-ca-install fix: reconnect ldap2 after DS restart

2015-06-18 Thread Martin Babinsky
On 06/18/2015 03:53 PM, Martin Basti wrote: On 18/06/15 15:04, Martin Babinsky wrote: On 06/17/2015 02:28 PM, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/5064 Patch attached. ACK Rebased patch attached. ACK to rebased patch :). -- Martin^3 Babinsky -- Manage your

Re: [Freeipa-devel] [PATCH 0265] Server Upgrade: Create NIS server configuration during upgrade in off mode

2015-06-18 Thread Martin Babinsky
On 06/11/2015 04:04 PM, Martin Basti wrote: Without this patch, upgrader shows the parent entry not found error. NIS Server plugin is disabled by default, must be enabled by ipa-nis-manage Patch attached. ACK -- Martin^3 Babinsky -- Manage your subscription for the Freeipa-devel mailing

Re: [Freeipa-devel] Community Portal Prototype

2015-06-18 Thread Drew Erny
On 06/18/2015 03:53 AM, Petr Spacek wrote: On 17.6.2015 21:21, Drew Erny wrote: Hello, all, I've built a prototype of the community portal, and I'd like a quick sanity check on it. If someone would look over the architecture of this code and make sure that the design is sensible before I

Re: [Freeipa-devel] [PATCH 0265] Server Upgrade: Create NIS server configuration during upgrade in off mode

2015-06-18 Thread Petr Vobornik
On 06/18/2015 03:50 PM, Martin Babinsky wrote: On 06/11/2015 04:04 PM, Martin Basti wrote: Without this patch, upgrader shows the parent entry not found error. NIS Server plugin is disabled by default, must be enabled by ipa-nis-manage Patch attached. ACK Pushed to master:

Re: [Freeipa-devel] [PATCH 0266] ipa-ca-install fix: reconnect ldap2 after DS restart

2015-06-18 Thread Petr Vobornik
On 06/18/2015 05:29 PM, Martin Babinsky wrote: On 06/18/2015 03:53 PM, Martin Basti wrote: On 18/06/15 15:04, Martin Babinsky wrote: On 06/17/2015 02:28 PM, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/5064 Patch attached. ACK Rebased patch attached. ACK to rebased

Re: [Freeipa-devel] Need to figure out how to make a schema change

2015-06-18 Thread Fraser Tweedale
On Thu, Jun 18, 2015 at 11:02:03AM -0700, Nathan Kinder wrote: On 06/18/2015 10:45 AM, Ade Lee wrote: In order for IPA to use some new functionality in Profile Management and Sub CAs, we need to add some additional schema to the Dogtag LDAP instance. Fraser has written a Dogtag

Re: [Freeipa-devel] Need to figure out how to make a schema change

2015-06-18 Thread Endi Sukma Dewata
On 6/18/2015 8:19 PM, Fraser Tweedale wrote: In order for IPA to use some new functionality in Profile Management and Sub CAs, we need to add some additional schema to the Dogtag LDAP instance. Fraser has written a Dogtag upgrade script to do this upgrade, but this script expects the DM

Re: [Freeipa-devel] Need to figure out how to make a schema change

2015-06-18 Thread Nathan Kinder
On 06/18/2015 07:08 PM, Endi Sukma Dewata wrote: On 6/18/2015 8:19 PM, Fraser Tweedale wrote: In order for IPA to use some new functionality in Profile Management and Sub CAs, we need to add some additional schema to the Dogtag LDAP instance. Fraser has written a Dogtag upgrade script to

Re: [Freeipa-devel] Need to figure out how to make a schema change

2015-06-18 Thread Nathan Kinder
On 06/18/2015 10:45 AM, Ade Lee wrote: In order for IPA to use some new functionality in Profile Management and Sub CAs, we need to add some additional schema to the Dogtag LDAP instance. Fraser has written a Dogtag upgrade script to do this upgrade, but this script expects the DM

Re: [Freeipa-devel] FreeIPA 4.2 Alpha preparations

2015-06-18 Thread Petr Vobornik
On 06/18/2015 02:05 PM, Petr Vobornik wrote: I'm going to tag alpha_1-4-3-0 today at 15:00 CET. I'm not aware of any alpha blockers on FreeIPA side. Please contact me if there are patches which should make the release. This release will be available in mkosek/freeipa-4-2 COPR repository. When

Re: [Freeipa-devel] FreeIPA 4.2 Alpha preparations

2015-06-18 Thread Jakub Hrozek
On Thu, Jun 18, 2015 at 08:02:23PM +0200, Petr Vobornik wrote: On 06/18/2015 02:05 PM, Petr Vobornik wrote: I'm going to tag alpha_1-4-3-0 today at 15:00 CET. I'm not aware of any alpha blockers on FreeIPA side. Please contact me if there are patches which should make the release. This

[Freeipa-devel] Need to figure out how to make a schema change

2015-06-18 Thread Ade Lee
In order for IPA to use some new functionality in Profile Management and Sub CAs, we need to add some additional schema to the Dogtag LDAP instance. Fraser has written a Dogtag upgrade script to do this upgrade, but this script expects the DM password to be in password.conf. Some discussion on

[Freeipa-devel] [RFC] Community Portal

2015-06-18 Thread Drew Erny
Hi, all, More email about the community portal. This time, I have a design proposal for you: http://www.freeipa.org/page/V4/Community_Portal Tell me what you think. Thanks, Drew Erny -- Manage your subscription for the Freeipa-devel mailing list:

Re: [Freeipa-devel] disabling topology segment has no effect

2015-06-18 Thread Oleg Fayans
Hi Ludwig, I've saved and analyzed all the console outputs from my activity on master and replica1 (from consoles that I by chance did not close). I was not able to detect the moment when the things went wrong. My guess is that the changes in topology get replicated slowly enough to be able

Re: [Freeipa-devel] Community Portal Prototype

2015-06-18 Thread Petr Spacek
On 17.6.2015 21:21, Drew Erny wrote: Hello, all, I've built a prototype of the community portal, and I'd like a quick sanity check on it. If someone would look over the architecture of this code and make sure that the design is sensible before I proceed any further, that would be very

Re: [Freeipa-devel] [PATCH] 0005 User life cycle: del/mod/find/show stageuser commands

2015-06-18 Thread Jan Cholasta
Dne 15.6.2015 v 17:29 thierry bordaz napsal(a): On 06/15/2015 05:00 PM, Simo Sorce wrote: On Mon, 2015-06-15 at 16:48 +0200, Petr Vobornik wrote: On 06/09/2015 02:02 PM, Jan Cholasta wrote: Dne 20.5.2015 v 11:26 Jan Cholasta napsal(a): Dne 18.5.2015 v 10:33 thierry bordaz napsal(a): On

Re: [Freeipa-devel] [PATCH] 0005 User life cycle: del/mod/find/show stageuser commands

2015-06-18 Thread Jan Cholasta
Dne 18.6.2015 v 09:30 Jan Cholasta napsal(a): Dne 15.6.2015 v 17:29 thierry bordaz napsal(a): On 06/15/2015 05:00 PM, Simo Sorce wrote: On Mon, 2015-06-15 at 16:48 +0200, Petr Vobornik wrote: On 06/09/2015 02:02 PM, Jan Cholasta wrote: Dne 20.5.2015 v 11:26 Jan Cholasta napsal(a): Dne