Re: [Freeipa-devel] [PATCH 0032] Remove dangling RUVs even if replicas are offline

2016-05-18 Thread Ludwig Krispenz
On 05/19/2016 08:02 AM, Stanislav Laznicka wrote: On 05/18/2016 04:44 PM, Petr Vobornik wrote: On 05/18/2016 04:36 PM, Stanislav Laznicka wrote: There's no ticket for this patch but as there was a fix to 389-ds mentioned in https://fedorahosted.org/freeipa/ticket/5396, the TODO section in clea

Re: [Freeipa-devel] [DESIGN-REVIEW] V4/Manage_replication_topology_4_4

2016-05-18 Thread Oleg Fayans
Hi Martin, I should probably rephrase my question: will the server_del API call be added to 'ipa-server-install --uninstall' within 4.4 or is it a more distant plan? On 05/18/2016 05:18 PM, Martin Babinsky wrote: > On 05/18/2016 05:01 PM, Oleg Fayans wrote: >> Hi guys, >> >> Did I understand corr

Re: [Freeipa-devel] [PATCH 0032] Remove dangling RUVs even if replicas are offline

2016-05-18 Thread Stanislav Laznicka
On 05/18/2016 04:44 PM, Petr Vobornik wrote: On 05/18/2016 04:36 PM, Stanislav Laznicka wrote: There's no ticket for this patch but as there was a fix to 389-ds mentioned in https://fedorahosted.org/freeipa/ticket/5396, the TODO section in clean_dangling_ruvs could be removed. What about using

Re: [Freeipa-devel] [PATCH] 0057..0058 Fix caIPAserviceCert regression

2016-05-18 Thread Fraser Tweedale
On Wed, May 18, 2016 at 03:17:37PM +0200, Jan Cholasta wrote: > Hi, > > On 18.5.2016 08:09, Fraser Tweedale wrote: > > Rebased version of 0057 attached, along with new patch 0058 that > > detects when the Dogtag version of caIPAserviceCert has been > > erroneously imported and repairs the profile.

[Freeipa-devel] [PATCH 0483] fix referenced before assignment error in baseldap

2016-05-18 Thread Martin Basti
Patch attached From 93a88da9dabc3037d3e303cb4b91699b5fcf26d1 Mon Sep 17 00:00:00 2001 From: Martin Basti Date: Wed, 18 May 2016 18:51:04 +0200 Subject: [PATCH] Fix referenced before assigment variables in except statements Variable msg may not exists in the last except context, and even it con

Re: [Freeipa-devel] [DESIGN-REVIEW] V4/Manage_replication_topology_4_4

2016-05-18 Thread Martin Babinsky
On 05/18/2016 05:01 PM, Oleg Fayans wrote: Hi guys, Did I understand correctly that in 4.4 release the function of both 'ipa-csreplica-manage del' and 'ipa-replica-manage del' will be transfered to the API calls executed during replica uninstallation with 'ipa-server-install --uninstall'? Which

Re: [Freeipa-devel] [DESIGN-REVIEW] V4/Manage_replication_topology_4_4

2016-05-18 Thread Oleg Fayans
Hi guys, Did I understand correctly that in 4.4 release the function of both 'ipa-csreplica-manage del' and 'ipa-replica-manage del' will be transfered to the API calls executed during replica uninstallation with 'ipa-server-install --uninstall'? Which means that 'ipa-replica-manage del' will be

Re: [Freeipa-devel] [PATCH 0095-0098] NTP: use augeas, configure chronyd, do not overwrite config

2016-05-18 Thread Petr Spacek
On 16.5.2016 13:58, David Kupka wrote: >>> >>> >>> On 14.03.2016 13:46, Martin Babinsky wrote: On 03/11/2016 09:16 AM, David Kupka wrote: > Current version (0.5.0) of python-augeas is missing copy() method. Use > dkupka/python-augeas copr repo before new version it's build and > av

Re: [Freeipa-devel] [TESTS][PATCH] Ping module tests in a non-declarative way

2016-05-18 Thread Martin Basti
On 18.05.2016 11:07, Peter Lacko wrote: So last one (hopefully). Peter - Original Message - From: "Martin Basti" To: "Peter Lacko" Cc: freeipa-devel@redhat.com Sent: Monday, May 16, 2016 6:32:49 PM Subject: Re: [Freeipa-devel] [TESTS][PATCH] Ping module tests in a non-declarative

Re: [Freeipa-devel] [DESIGN] Time-Based HBAC Policies

2016-05-18 Thread Jakub Hrozek
On Wed, May 18, 2016 at 05:13:11PM +0300, Alexander Bokovoy wrote: > On Wed, 18 May 2016, Stanislav Laznicka wrote: > > On 05/18/2016 02:19 PM, Alexander Bokovoy wrote: > > > On Wed, 18 May 2016, Stanislav Laznicka wrote: > > > > > > when removal succeeds but addition fails for some > > > > > > rea

Re: [Freeipa-devel] [PATCH 0032] Remove dangling RUVs even if replicas are offline

2016-05-18 Thread Petr Vobornik
On 05/18/2016 04:36 PM, Stanislav Laznicka wrote: > There's no ticket for this patch but as there was a fix to 389-ds > mentioned in https://fedorahosted.org/freeipa/ticket/5396, the TODO > section in clean_dangling_ruvs could be removed. > What about using 'replica-force-cleaning':'yes', ever

Re: [Freeipa-devel] [DESIGN] Time-Based HBAC Policies

2016-05-18 Thread Martin Basti
On 18.05.2016 16:13, Alexander Bokovoy wrote: On Wed, 18 May 2016, Stanislav Laznicka wrote: On 05/18/2016 02:19 PM, Alexander Bokovoy wrote: On Wed, 18 May 2016, Stanislav Laznicka wrote: when removal succeeds but addition fails for some reason? The operation is not atomic anymore. We o

[Freeipa-devel] [PATCH 0032] Remove dangling RUVs even if replicas are offline

2016-05-18 Thread Stanislav Laznicka
There's no ticket for this patch but as there was a fix to 389-ds mentioned in https://fedorahosted.org/freeipa/ticket/5396, the TODO section in clean_dangling_ruvs could be removed. From af7ef756e2118638bd2d2871c76d69d206f594ef Mon Sep 17 00:00:00 2001 From: Stanislav Laznicka Date: Wed, 18 M

Re: [Freeipa-devel] [DESIGN] Time-Based HBAC Policies

2016-05-18 Thread Alexander Bokovoy
On Wed, 18 May 2016, Stanislav Laznicka wrote: On 05/18/2016 02:19 PM, Alexander Bokovoy wrote: On Wed, 18 May 2016, Stanislav Laznicka wrote: when removal succeeds but addition fails for some reason? The operation is not atomic anymore. We offline-discussed this with Honza. There should be

Re: [Freeipa-devel] [DESIGN] Time-Based HBAC Policies

2016-05-18 Thread Stanislav Laznicka
On 05/18/2016 02:19 PM, Alexander Bokovoy wrote: On Wed, 18 May 2016, Stanislav Laznicka wrote: when removal succeeds but addition fails for some reason? The operation is not atomic anymore. We offline-discussed this with Honza. There should be a new command `ipa hbacrule-replace-accesstime

Re: [Freeipa-devel] [PATCH] 0057..0058 Fix caIPAserviceCert regression

2016-05-18 Thread Jan Cholasta
Hi, On 18.5.2016 08:09, Fraser Tweedale wrote: Rebased version of 0057 attached, along with new patch 0058 that detects when the Dogtag version of caIPAserviceCert has been erroneously imported and repairs the profile. How to reproduce the issue? So far I had no luck with freeipa-server-4.2.4

Re: [Freeipa-devel] [DESIGN] Time-Based HBAC Policies

2016-05-18 Thread Alexander Bokovoy
On Wed, 18 May 2016, Stanislav Laznicka wrote: when removal succeeds but addition fails for some reason? The operation is not atomic anymore. We offline-discussed this with Honza. There should be a new command `ipa hbacrule-replace-accesstime rule_name --orig-time=icalstr1 --new-time=icalst

Re: [Freeipa-devel] [DESIGN] Time-Based HBAC Policies

2016-05-18 Thread Stanislav Laznicka
On 05/18/2016 01:47 PM, Stanislav Laznicka wrote: On 05/18/2016 01:15 PM, Stanislav Laznicka wrote: On 05/18/2016 01:00 PM, Petr Spacek wrote: On 18.5.2016 12:52, Jan Cholasta wrote: On 18.5.2016 12:43, Stanislav Laznicka wrote: On 05/18/2016 12:38 PM, Jan Cholasta wrote: On 18.5.2016 12:2

Re: [Freeipa-devel] [DESIGN] Time-Based HBAC Policies

2016-05-18 Thread Martin Basti
On 18.05.2016 13:47, Stanislav Laznicka wrote: On 05/18/2016 01:15 PM, Stanislav Laznicka wrote: On 05/18/2016 01:00 PM, Petr Spacek wrote: On 18.5.2016 12:52, Jan Cholasta wrote: On 18.5.2016 12:43, Stanislav Laznicka wrote: On 05/18/2016 12:38 PM, Jan Cholasta wrote: On 18.5.2016 12:23,

Re: [Freeipa-devel] [TESTS]{PATCH 0013] Maximum username length higher than 255 cannot be set

2016-05-18 Thread Ganna Kaihorodova
- Original Message - From: "Lenka Doudova" To: "Ganna Kaihorodova" Sent: Wednesday, May 18, 2016 10:37:49 AM Subject: Fwd: [Freeipa-devel] [TESTS]{PATCH 0013] Maximum username length higher than 255 cannot be set Forwarded Message Subject:[Freeipa-devel] [T

Re: [Freeipa-devel] [DESIGN] Time-Based HBAC Policies

2016-05-18 Thread Stanislav Laznicka
On 05/18/2016 01:15 PM, Stanislav Laznicka wrote: On 05/18/2016 01:00 PM, Petr Spacek wrote: On 18.5.2016 12:52, Jan Cholasta wrote: On 18.5.2016 12:43, Stanislav Laznicka wrote: On 05/18/2016 12:38 PM, Jan Cholasta wrote: On 18.5.2016 12:23, Petr Spacek wrote: On 18.5.2016 08:25, Stanislav

Re: [Freeipa-devel] [DESIGN] Time-Based HBAC Policies

2016-05-18 Thread Jan Cholasta
On 18.5.2016 13:00, Petr Spacek wrote: On 18.5.2016 12:52, Jan Cholasta wrote: On 18.5.2016 12:43, Stanislav Laznicka wrote: On 05/18/2016 12:38 PM, Jan Cholasta wrote: On 18.5.2016 12:23, Petr Spacek wrote: On 18.5.2016 08:25, Stanislav Laznicka wrote: On 05/17/2016 12:40 PM, Petr Spacek wr

Re: [Freeipa-devel] [DESIGN] Time-Based HBAC Policies

2016-05-18 Thread Stanislav Laznicka
On 05/18/2016 01:00 PM, Petr Spacek wrote: On 18.5.2016 12:52, Jan Cholasta wrote: On 18.5.2016 12:43, Stanislav Laznicka wrote: On 05/18/2016 12:38 PM, Jan Cholasta wrote: On 18.5.2016 12:23, Petr Spacek wrote: On 18.5.2016 08:25, Stanislav Laznicka wrote: On 05/17/2016 12:40 PM, Petr Space

Re: [Freeipa-devel] [DESIGN] Time-Based HBAC Policies

2016-05-18 Thread Petr Spacek
On 18.5.2016 12:52, Jan Cholasta wrote: > On 18.5.2016 12:43, Stanislav Laznicka wrote: >> On 05/18/2016 12:38 PM, Jan Cholasta wrote: >>> On 18.5.2016 12:23, Petr Spacek wrote: On 18.5.2016 08:25, Stanislav Laznicka wrote: > On 05/17/2016 12:40 PM, Petr Spacek wrote: >> On 13.5.2016 1

Re: [Freeipa-devel] [DESIGN] Time-Based HBAC Policies

2016-05-18 Thread Jan Cholasta
On 18.5.2016 12:43, Stanislav Laznicka wrote: On 05/18/2016 12:38 PM, Jan Cholasta wrote: On 18.5.2016 12:23, Petr Spacek wrote: On 18.5.2016 08:25, Stanislav Laznicka wrote: On 05/17/2016 12:40 PM, Petr Spacek wrote: On 13.5.2016 13:50, Stanislav Laznicka wrote: Hello list, We had a discus

Re: [Freeipa-devel] [PATCH 0473-0476]DNS Locations: Prologue

2016-05-18 Thread Martin Basti
On 12.05.2016 16:16, Martin Basti wrote: On 12.05.2016 11:01, Martin Basti wrote: On 11.05.2016 09:41, Martin Basti wrote: On 10.05.2016 18:56, Petr Spacek wrote: On 10.5.2016 15:38, Petr Spacek wrote: On 10.5.2016 15:26, Martin Basti wrote: On 10.05.2016 15:23, Petr Spacek wrote:

Re: [Freeipa-devel] [DESIGN] Time-Based HBAC Policies

2016-05-18 Thread Stanislav Laznicka
On 05/18/2016 12:38 PM, Jan Cholasta wrote: On 18.5.2016 12:23, Petr Spacek wrote: On 18.5.2016 08:25, Stanislav Laznicka wrote: On 05/17/2016 12:40 PM, Petr Spacek wrote: On 13.5.2016 13:50, Stanislav Laznicka wrote: Hello list, We had a discussion today over integrating the Time Rules into

Re: [Freeipa-devel] [DESIGN] Time-Based HBAC Policies

2016-05-18 Thread Jan Cholasta
On 18.5.2016 12:23, Petr Spacek wrote: On 18.5.2016 08:25, Stanislav Laznicka wrote: On 05/17/2016 12:40 PM, Petr Spacek wrote: On 13.5.2016 13:50, Stanislav Laznicka wrote: Hello list, We had a discussion today over integrating the Time Rules into the CLI and WebUI and a problem came up with

Re: [Freeipa-devel] [DESIGN] Time-Based HBAC Policies

2016-05-18 Thread Petr Spacek
On 18.5.2016 08:25, Stanislav Laznicka wrote: > On 05/17/2016 12:40 PM, Petr Spacek wrote: >> On 13.5.2016 13:50, Stanislav Laznicka wrote: >>> Hello list, >>> >>> We had a discussion today over integrating the Time Rules into the CLI and >>> WebUI and a problem came up with with the current soluti

Re: [Freeipa-devel] [TESTS][PATCH] Ping module tests in a non-declarative way

2016-05-18 Thread Peter Lacko
So last one (hopefully). Peter - Original Message - From: "Martin Basti" To: "Peter Lacko" Cc: freeipa-devel@redhat.com Sent: Monday, May 16, 2016 6:32:49 PM Subject: Re: [Freeipa-devel] [TESTS][PATCH] Ping module tests in a non-declarative way On 13.05.2016 15:05, Peter Lacko wrot

Re: [Freeipa-devel] [TESTS]{PATCH 0013] Maximum username length higher than 255 cannot be set

2016-05-18 Thread Lenka Doudova
Bump for review (Ganna) Thanks, Lenka On 05/13/2016 01:08 PM, Lenka Doudova wrote: Patch attached. Lenka -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/C

[Freeipa-devel] Karma Request for Dogtag 10.3.1 on Fedora 24

2016-05-18 Thread Petr Vobornik
raising awareness Forwarded Message Subject:Karma Request for Dogtag 10.3.1 on Fedora 24 Date: Tue, 17 May 2016 17:28:49 -0600 From: Matthew Harmsen The following candidate builds of Dogtag 10.3.1 for Fedora 24 (final) consist of the following: * dogtag-pki-them