Re: [Freeipa-devel] cert profiles - test plan + patches

2015-09-04 Thread Lenka Doudova
Hi, there's no traceback in the file you mentioned, but I'm running it through lite-server, so here's the traceback from there: http://pastebin.test.redhat.com/310598 I can't really get to the problem. What I forgot to mention in the previous email was that the tests fail when attempting to

Re: [Freeipa-devel] fixing Kerberos principal aliases handling in IPA

2015-09-04 Thread thierry bordaz
On 09/03/2015 04:03 PM, David Kupka wrote: On 02/09/15 14:27, Simo Sorce wrote: On Wed, 2015-09-02 at 08:11 +0200, David Kupka wrote: On 01/09/15 16:53, Simo Sorce wrote: On Tue, 2015-09-01 at 16:39 +0200, Martin Babinsky wrote: Hi list, I own the following ticket

Re: [Freeipa-devel] FreeIPA 4.2.1 checklist

2015-09-04 Thread Martin Kosek
On 09/04/2015 10:10 AM, Jan Pazdziora wrote: > On Fri, Sep 04, 2015 at 09:03:27AM +0200, Martin Kosek wrote: >> ticket to the right version milestone ("FreeIPA 4.2.1") at the time the >> ticket >> is closed. But without proper tooling, I am afraid people may simply close >> the >> ticket within

Re: [Freeipa-devel] [PATCH] 377 Using LDAPI to setup CA and KRA agents.

2015-09-04 Thread Martin Basti
On 09/02/2015 06:42 AM, Endi Sukma Dewata wrote: On 9/1/2015 1:52 AM, Martin Basti wrote: The CA and KRA installation code has been modified to use LDAPI to create the CA and KRA agents directly in the CA and KRA database. This way it's no longer necessary to use the Directory Manager

Re: [Freeipa-devel] [PATH 0053] Inconsistency between ipasearchrecordslimit and --sizelimit

2015-09-04 Thread Gabe Alford
Bump for review. On Wed, Aug 12, 2015 at 9:32 AM, Gabe Alford wrote: > On Tue, Aug 11, 2015 at 1:34 AM, Jan Cholasta wrote: > >> On 6.8.2015 21:43, Gabe Alford wrote: >> >>> Hello, >>> >>> Updated patch attached. >>> >>> - Time limit is -1 for

Re: [Freeipa-devel] [PATCH 487] ldap: Make ldap2 connection management thread-safe again

2015-09-04 Thread Tomas Babej
On 09/02/2015 04:47 PM, Jan Cholasta wrote: > On 2.9.2015 16:20, thierry bordaz wrote: >> On 09/02/2015 03:16 PM, Jan Cholasta wrote: >>> On 2.9.2015 14:51, Martin Basti wrote: On 09/02/2015 02:32 PM, Jan Cholasta wrote: > Hi, > > the attached patch fixes >

Re: [Freeipa-devel] FreeIPA 4.2.1 checklist

2015-09-04 Thread Jakub Hrozek
On Fri, Sep 04, 2015 at 09:30:39AM +0200, Jakub Hrozek wrote: > On Fri, Sep 04, 2015 at 09:25:59AM +0200, Martin Kosek wrote: > > On 09/04/2015 09:23 AM, Jakub Hrozek wrote: > > > On Fri, Sep 04, 2015 at 09:19:16AM +0200, Martin Kosek wrote: > > >> On 09/04/2015 09:12 AM, Jakub Hrozek wrote: > >

[Freeipa-devel] [PATCH 0063] fix crash during standalone CA installation on CA-less master

2015-09-04 Thread Martin Babinsky
A quick fix for https://fedorahosted.org/freeipa/ticket/5288 -- Martin^3 Babinsky From ba43a113194b49dcbf3e0eeaa3a41bc204120c08 Mon Sep 17 00:00:00 2001 From: Martin Babinsky Date: Fri, 4 Sep 2015 15:14:48 +0200 Subject: [PATCH] load RA backend plugins during standalone CA

Re: [Freeipa-devel] [PATCH] 377 Using LDAPI to setup CA and KRA agents.

2015-09-04 Thread Endi Sukma Dewata
On 9/4/2015 6:35 AM, Martin Basti wrote: On 09/02/2015 06:42 AM, Endi Sukma Dewata wrote: On 9/1/2015 1:52 AM, Martin Basti wrote: The CA and KRA installation code has been modified to use LDAPI to create the CA and KRA agents directly in the CA and KRA database. This way it's no longer

Re: [Freeipa-devel] cert profiles - test plan + patches

2015-09-04 Thread Martin Babinsky
On 09/04/2015 11:06 AM, Lenka Doudova wrote: Hi, there's no traceback in the file you mentioned, but I'm running it through lite-server, so here's the traceback from there: http://pastebin.test.redhat.com/310598 I can't really get to the problem. What I forgot to mention in the previous email

Re: [Freeipa-devel] [PATCH] 377 Using LDAPI to setup CA and KRA agents.

2015-09-04 Thread Petr Vobornik
On 09/04/2015 04:03 PM, Endi Sukma Dewata wrote: On 9/4/2015 6:35 AM, Martin Basti wrote: On 09/02/2015 06:42 AM, Endi Sukma Dewata wrote: On 9/1/2015 1:52 AM, Martin Basti wrote: The CA and KRA installation code has been modified to use LDAPI to create the CA and KRA agents directly in the

Re: [Freeipa-devel] [PATCH 0004] Rewrap errors in get_principal to CCacheError

2015-09-04 Thread Michael Šimáček
On 2015-09-03 14:32, Tomas Babej wrote: On 09/03/2015 12:54 PM, Michael Šimáček wrote: After porting to gssapi, the ipa command prints ugly traceback when kerberos credentials are not available. Rewrapping to CCacheError when getting the principal name results in nicer error message.

Re: [Freeipa-devel] fixing Kerberos principal aliases handling in IPA

2015-09-04 Thread Simo Sorce
On Thu, 2015-09-03 at 16:03 +0200, David Kupka wrote: > On 02/09/15 14:27, Simo Sorce wrote: > > On Wed, 2015-09-02 at 08:11 +0200, David Kupka wrote: > >> On 01/09/15 16:53, Simo Sorce wrote: > >>> On Tue, 2015-09-01 at 16:39 +0200, Martin Babinsky wrote: > Hi list, > > I own the

Re: [Freeipa-devel] FreeIPA 4.2.1 checklist

2015-09-04 Thread Alexander Bokovoy
On Fri, 04 Sep 2015, Martin Kosek wrote: On 09/04/2015 09:08 AM, Alexander Bokovoy wrote: On Fri, 04 Sep 2015, Martin Kosek wrote: ... We also need to get krb5 update for KDC client referrals. Robby is working on that at bug https://bugzilla.redhat.com/show_bug.cgi?id=1259844 The patch is

Re: [Freeipa-devel] FreeIPA 4.2.1 checklist

2015-09-04 Thread Martin Kosek
On 09/04/2015 09:12 AM, Jakub Hrozek wrote: > On Fri, Sep 04, 2015 at 08:42:47AM +0200, Martin Kosek wrote: >> Hello everyone, >> >> It is now only couple days before Fedora 23 Beta freeze [1] and as we >> discussed, we would like to release FreeIPA 4.2.1, which already contains 148 >> patches on

Re: [Freeipa-devel] FreeIPA 4.2.1 checklist

2015-09-04 Thread Martin Kosek
On 09/04/2015 09:15 AM, Alexander Bokovoy wrote: > On Fri, 04 Sep 2015, Martin Kosek wrote: >> On 09/04/2015 09:08 AM, Alexander Bokovoy wrote: >>> On Fri, 04 Sep 2015, Martin Kosek wrote: >> ... >>> We also need to get krb5 update for KDC client referrals. Robby is >>> working on that at bug

Re: [Freeipa-devel] FreeIPA 4.2.1 checklist

2015-09-04 Thread Jakub Hrozek
On Fri, Sep 04, 2015 at 09:19:16AM +0200, Martin Kosek wrote: > On 09/04/2015 09:12 AM, Jakub Hrozek wrote: > > On Fri, Sep 04, 2015 at 08:42:47AM +0200, Martin Kosek wrote: > >> Hello everyone, > >> > >> It is now only couple days before Fedora 23 Beta freeze [1] and as we > >> discussed, we

Re: [Freeipa-devel] FreeIPA 4.2.1 checklist

2015-09-04 Thread Martin Kosek
On 09/04/2015 09:23 AM, Jakub Hrozek wrote: > On Fri, Sep 04, 2015 at 09:19:16AM +0200, Martin Kosek wrote: >> On 09/04/2015 09:12 AM, Jakub Hrozek wrote: >>> On Fri, Sep 04, 2015 at 08:42:47AM +0200, Martin Kosek wrote: Hello everyone, It is now only couple days before Fedora 23

Re: [Freeipa-devel] FreeIPA 4.2.1 checklist

2015-09-04 Thread Alexander Bokovoy
On Fri, 04 Sep 2015, Martin Kosek wrote: On 09/04/2015 09:15 AM, Alexander Bokovoy wrote: On Fri, 04 Sep 2015, Martin Kosek wrote: On 09/04/2015 09:08 AM, Alexander Bokovoy wrote: On Fri, 04 Sep 2015, Martin Kosek wrote: ... We also need to get krb5 update for KDC client referrals. Robby is

Re: [Freeipa-devel] FreeIPA 4.2.1 checklist

2015-09-04 Thread Jakub Hrozek
On Fri, Sep 04, 2015 at 09:25:59AM +0200, Martin Kosek wrote: > On 09/04/2015 09:23 AM, Jakub Hrozek wrote: > > On Fri, Sep 04, 2015 at 09:19:16AM +0200, Martin Kosek wrote: > >> On 09/04/2015 09:12 AM, Jakub Hrozek wrote: > >>> On Fri, Sep 04, 2015 at 08:42:47AM +0200, Martin Kosek wrote: >

Re: [Freeipa-devel] FreeIPA 4.2.1 checklist

2015-09-04 Thread Martin Kosek
On 09/04/2015 08:57 AM, Jan Pazdziora wrote: > On Fri, Sep 04, 2015 at 08:42:47AM +0200, Martin Kosek wrote: >> Hello everyone, >> >> It is now only couple days before Fedora 23 Beta freeze [1] and as we >> discussed, we would like to release FreeIPA 4.2.1, which already contains 148 > > Looking

Re: [Freeipa-devel] FreeIPA 4.2.1 checklist

2015-09-04 Thread Jakub Hrozek
On Fri, Sep 04, 2015 at 08:42:47AM +0200, Martin Kosek wrote: > Hello everyone, > > It is now only couple days before Fedora 23 Beta freeze [1] and as we > discussed, we would like to release FreeIPA 4.2.1, which already contains 148 > patches on top of FreeIPA 4.2.0, mostly stabilization of the

[Freeipa-devel] FreeIPA 4.2.1 checklist

2015-09-04 Thread Martin Kosek
Hello everyone, It is now only couple days before Fedora 23 Beta freeze [1] and as we discussed, we would like to release FreeIPA 4.2.1, which already contains 148 patches on top of FreeIPA 4.2.0, mostly stabilization of the new 4.2 features or upgrade fixes. IIRC, we miss 2 dependencies: 1)

Re: [Freeipa-devel] FreeIPA 4.2.1 checklist

2015-09-04 Thread Jan Pazdziora
On Fri, Sep 04, 2015 at 08:42:47AM +0200, Martin Kosek wrote: > Hello everyone, > > It is now only couple days before Fedora 23 Beta freeze [1] and as we > discussed, we would like to release FreeIPA 4.2.1, which already contains 148 Looking at

Re: [Freeipa-devel] FreeIPA 4.2.1 checklist

2015-09-04 Thread Alexander Bokovoy
On Fri, 04 Sep 2015, Martin Kosek wrote: Hello everyone, It is now only couple days before Fedora 23 Beta freeze [1] and as we discussed, we would like to release FreeIPA 4.2.1, which already contains 148 patches on top of FreeIPA 4.2.0, mostly stabilization of the new 4.2 features or upgrade

Re: [Freeipa-devel] FreeIPA 4.2.1 checklist

2015-09-04 Thread Martin Kosek
On 09/04/2015 09:08 AM, Alexander Bokovoy wrote: > On Fri, 04 Sep 2015, Martin Kosek wrote: ... > We also need to get krb5 update for KDC client referrals. Robby is > working on that at bug https://bugzilla.redhat.com/show_bug.cgi?id=1259844 > The patch is ready, we just need to push out the

Re: [Freeipa-devel] FreeIPA 4.2.1 checklist

2015-09-04 Thread Jan Pazdziora
On Fri, Sep 04, 2015 at 09:03:27AM +0200, Martin Kosek wrote: > ticket to the right version milestone ("FreeIPA 4.2.1") at the time the ticket > is closed. But without proper tooling, I am afraid people may simply close the > ticket within "FreeIPA 4.2.x backlog" and it would then not be clear

Re: [Freeipa-devel] [PATCH 0309-0310] DNSSEC CI: extend DNSSEC CI tests

2015-09-04 Thread Martin Basti
On 09/03/2015 07:21 PM, Oleg Fayans wrote: Hi Martin, The two functions test_disable_reenable_signing_master and test_disable_reenable_signing_replica the error message for the laste assertion is different, although the assertions are identical: "RRSIG should be different" and "DNSKEY