[Freeipa-devel] [freeipa PR#228][comment] cert-request: allow directoryName in SAN extension

2016-11-28 Thread frasertweedale
URL: https://github.com/freeipa/freeipa/pull/228 Title: #228: cert-request: allow directoryName in SAN extension frasertweedale commented: """ @tomaskrizek 1. The SAN DN is permitted if it matches the IPA principal's full DN in LDAP. The _certificate_ subject DN need not match the LDAP DN.

[Freeipa-devel] [freeipa PR#174][comment] add log module

2016-11-28 Thread shanyin
URL: https://github.com/freeipa/freeipa/pull/174 Title: #174: add log module shanyin commented: """ I am sorry that the follow comments could not be sent successfully. What do you mean is that I should send the log module as separate PR? If so, I will do it later. """ See the full comment at

[Freeipa-devel] [freeipa PR#62][comment] Configure Anonymous PKINIT on server install

2016-11-28 Thread simo5
URL: https://github.com/freeipa/freeipa/pull/62 Title: #62: Configure Anonymous PKINIT on server install simo5 commented: """ @splashx we are starting to pollute this PR here now. Please provide KDC logs on the user's mailing list and let's proceed there. """ See the full comment at

Re: [Freeipa-devel] NTP in FreeIPA

2016-11-28 Thread John Dennis
On 11/28/2016 02:57 PM, Rob Crittenden wrote: David Kupka wrote: On 22/11/16 23:15, Gabe Alford wrote: I would say that it is worth keeping in FreeIPA. I know myself and some customers use its functionality by having the clients sync to the IPA servers and have the servers sync to the NTP

Re: [Freeipa-devel] NTP in FreeIPA

2016-11-28 Thread Rob Crittenden
David Kupka wrote: > On 22/11/16 23:15, Gabe Alford wrote: >> I would say that it is worth keeping in FreeIPA. I know myself and some >> customers use its functionality by having the clients sync to the IPA >> servers and have the servers sync to the NTP source. This way if the NTP >> source ever

[Freeipa-devel] [freeipa PR#182][comment] Use env var IPA_CONFDIR to get confdir for 'cli' context

2016-11-28 Thread rcritten
URL: https://github.com/freeipa/freeipa/pull/182 Title: #182: Use env var IPA_CONFDIR to get confdir for 'cli' context rcritten commented: """ I don't see this as a convenience method. I'd find it less likely to use directly with the ipa tool (though having to specify -e every time I used a

[Freeipa-devel] [freeipa PR#270][synchronized] Test: uniqueness of certificate renewal master

2016-11-28 Thread ofayans
URL: https://github.com/freeipa/freeipa/pull/270 Author: ofayans Title: #270: Test: uniqueness of certificate renewal master Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/270/head:pr270 git checkout

[Freeipa-devel] [freeipa PR#255][comment] Adjustments for setup requirements

2016-11-28 Thread pvoborni
URL: https://github.com/freeipa/freeipa/pull/255 Title: #255: Adjustments for setup requirements pvoborni commented: """ The commit message doesn't explain why python-gssapi version is raised. Is it required by something? It also doesn't explain if the minimal required version of

[Freeipa-devel] [freeipa PR#278][synchronized] Restore the original functionality of `env` and `plugins` commands

2016-11-28 Thread martbab
URL: https://github.com/freeipa/freeipa/pull/278 Author: martbab Title: #278: Restore the original functionality of `env` and `plugins` commands Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa

[Freeipa-devel] [freeipa PR#225][comment] tests: Added basic tests for certs in idoverrides

2016-11-28 Thread ofayans
URL: https://github.com/freeipa/freeipa/pull/225 Title: #225: tests: Added basic tests for certs in idoverrides ofayans commented: """ @apophys done, thank you for review! """ See the full comment at https://github.com/freeipa/freeipa/pull/225#issuecomment-263331778 -- Manage your

[Freeipa-devel] [freeipa PR#225][synchronized] tests: Added basic tests for certs in idoverrides

2016-11-28 Thread ofayans
URL: https://github.com/freeipa/freeipa/pull/225 Author: ofayans Title: #225: tests: Added basic tests for certs in idoverrides Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/225/head:pr225 git checkout

[Freeipa-devel] [freeipa PR#279][comment] installer: Stop adding distro-specific NTP servers into ntp.conf

2016-11-28 Thread pspacek
URL: https://github.com/freeipa/freeipa/pull/279 Title: #279: installer: Stop adding distro-specific NTP servers into ntp.conf pspacek commented: """ Have you tested the code? I would bet that it will remove everything except 127.127... from the list of servers. """ See the full comment at

[Freeipa-devel] [freeipa PR#62][comment] Configure Anonymous PKINIT on server install

2016-11-28 Thread splashx
URL: https://github.com/freeipa/freeipa/pull/62 Title: #62: Configure Anonymous PKINIT on server install splashx commented: """ @simo5 done, however not successfully. It's [not really my first time](http://www.securiteam.com/securitynews/6C02X0AHGA.html) on the pkinit rodeo, so I'm wondering

[Freeipa-devel] [freeipa PR#279][comment] installer: Stop adding distro-specific NTP servers into ntp.conf

2016-11-28 Thread pspacek
URL: https://github.com/freeipa/freeipa/pull/279 Title: #279: installer: Stop adding distro-specific NTP servers into ntp.conf pspacek commented: """ NACK ``` Pylint is running, please wait ... * Module ipaserver.install.ntpinstance ipaserver/install/ntpinstance.py:23:

[Freeipa-devel] [freeipa PR#62][comment] Configure Anonymous PKINIT on server install

2016-11-28 Thread splashx
URL: https://github.com/freeipa/freeipa/pull/62 Title: #62: Configure Anonymous PKINIT on server install splashx commented: """ @simo5 done, however not successfully. It's [not really my first time](http://www.securiteam.com/securitynews/6C02X0AHGA.html) on the pkinit rodeo, so I'm wondering

[Freeipa-devel] [freeipa PR#62][comment] Configure Anonymous PKINIT on server install

2016-11-28 Thread splashx
URL: https://github.com/freeipa/freeipa/pull/62 Title: #62: Configure Anonymous PKINIT on server install splashx commented: """ @simo5 done, however not successfully. It's [not really my first time](http://www.securiteam.com/securitynews/6C02X0AHGA.html) on the pkinit rodeo, so I'm wondering

[Freeipa-devel] [freeipa PR#263][comment] Backwards compatibility with setuptools 0.9.8

2016-11-28 Thread pvomacka
URL: https://github.com/freeipa/freeipa/pull/263 Title: #263: Backwards compatibility with setuptools 0.9.8 pvomacka commented: """ I'm able to build FreeIPA on Fedora and it also fixes bugs in building on RHEL, so it works for me. But I don't see any ticket in the commit. Do we have any

[Freeipa-devel] [freeipa PR#182][synchronized] Use env var IPA_CONFDIR to get confdir for 'cli' context

2016-11-28 Thread tiran
URL: https://github.com/freeipa/freeipa/pull/182 Author: tiran Title: #182: Use env var IPA_CONFDIR to get confdir for 'cli' context Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/182/head:pr182 git

[Freeipa-devel] [freeipa PR#281][opened] Accept server host names resolvable only using /etc/hosts

2016-11-28 Thread pspacek
URL: https://github.com/freeipa/freeipa/pull/281 Author: pspacek Title: #281: Accept server host names resolvable only using /etc/hosts Action: opened PR body: """ Apparently "files" implementation of hosts NSS database cannot deal with trailing period in host names. Previously name

[Freeipa-devel] [freeipa PR#182][comment] Use env var IPA_CONFDIR to get confdir for 'cli' context

2016-11-28 Thread tiran
URL: https://github.com/freeipa/freeipa/pull/182 Title: #182: Use env var IPA_CONFDIR to get confdir for 'cli' context tiran commented: """ Latest PR depends on PR #280 . """ See the full comment at https://github.com/freeipa/freeipa/pull/182#issuecomment-263313005 -- Manage your

[Freeipa-devel] [freeipa PR#255][synchronized] Adjustments for setup requirements

2016-11-28 Thread tiran
URL: https://github.com/freeipa/freeipa/pull/255 Author: tiran Title: #255: Adjustments for setup requirements Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/255/head:pr255 git checkout pr255 From

[Freeipa-devel] [freeipa PR#263][comment] Backwards compatibility with setuptools 0.9.8

2016-11-28 Thread tiran
URL: https://github.com/freeipa/freeipa/pull/263 Title: #263: Backwards compatibility with setuptools 0.9.8 tiran commented: """ PR #255 fixes the problem with download of wheel package. """ See the full comment at https://github.com/freeipa/freeipa/pull/263#issuecomment-263302787 -- Manage

[Freeipa-devel] [freeipa PR#280][comment] Set explicit confdir option for global contexts

2016-11-28 Thread tiran
URL: https://github.com/freeipa/freeipa/pull/280 Title: #280: Set explicit confdir option for global contexts tiran commented: """ For #182 """ See the full comment at https://github.com/freeipa/freeipa/pull/280#issuecomment-263301120 -- Manage your subscription for the Freeipa-devel

[Freeipa-devel] [freeipa PR#280][opened] Set explicit confdir option for global contexts

2016-11-28 Thread tiran
URL: https://github.com/freeipa/freeipa/pull/280 Author: tiran Title: #280: Set explicit confdir option for global contexts Action: opened PR body: """ Some API contexts are used to modify global state (e.g. files in /etc and /var). These contexts do not support confdir overrides. Initialize

[Freeipa-devel] [freeipa PR#278][edited] Restore the original functionality of `env` and `plugins` commands

2016-11-28 Thread martbab
URL: https://github.com/freeipa/freeipa/pull/278 Author: martbab Title: #278: Restore the original functionality of `env` and `plugins` commands Action: edited Changed field: body Original value: """ This reverts commit 1166fbc4946596fcc2ed51a1ec6990fc7dae8964 "Add 'ipa localenv' subcommand"

[Freeipa-devel] [freeipa PR#278][synchronized] Restore the original functionality of `env` and `plugins` commands

2016-11-28 Thread martbab
URL: https://github.com/freeipa/freeipa/pull/278 Author: martbab Title: #278: Restore the original functionality of `env` and `plugins` commands Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa

[Freeipa-devel] [freeipa PR#279][opened] installer: Stop adding distro-specific NTP servers into ntp.conf

2016-11-28 Thread dkupka
URL: https://github.com/freeipa/freeipa/pull/279 Author: dkupka Title: #279: installer: Stop adding distro-specific NTP servers into ntp.conf Action: opened PR body: """ Distribution packaged ntpd has servers preconfigured in ntp.conf so there's no point in trying to add them again during

[Freeipa-devel] [freeipa PR#278][synchronized] Restore the original functionality of `env` and `plugins` commands

2016-11-28 Thread martbab
URL: https://github.com/freeipa/freeipa/pull/278 Author: martbab Title: #278: Restore the original functionality of `env` and `plugins` commands Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa

[Freeipa-devel] [freeipa PR#278][opened] Restore the original functionality of `env` and `plugins` commands

2016-11-28 Thread martbab
URL: https://github.com/freeipa/freeipa/pull/278 Author: martbab Title: #278: Restore the original functionality of `env` and `plugins` commands Action: opened PR body: """ This reverts commit 1166fbc4946596fcc2ed51a1ec6990fc7dae8964 "Add 'ipa localenv' subcommand" and instead fixes the

[Freeipa-devel] [freeipa PR#277][synchronized] DNS: URI records: bump python-dns requirements

2016-11-28 Thread mbasti-rh
URL: https://github.com/freeipa/freeipa/pull/277 Author: mbasti-rh Title: #277: DNS: URI records: bump python-dns requirements Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/277/head:pr277 git checkout

[Freeipa-devel] [freeipa PR#277][comment] DNS: URI records: bump python-dns requirements

2016-11-28 Thread tiran
URL: https://github.com/freeipa/freeipa/pull/277 Title: #277: DNS: URI records: bump python-dns requirements tiran commented: """ You forgot to bump ```ipasetup.py.in```. """ See the full comment at https://github.com/freeipa/freeipa/pull/277#issuecomment-263277910 -- Manage your

[Freeipa-devel] [freeipa PR#277][opened] DNS: URI records: bump python-dns requirements

2016-11-28 Thread mbasti-rh
URL: https://github.com/freeipa/freeipa/pull/277 Author: mbasti-rh Title: #277: DNS: URI records: bump python-dns requirements Action: opened PR body: """ Support for DNS URI records has been added in python-dns 1.13 https://fedorahosted.org/freeipa/ticket/6344 """ To pull the PR as Git

[Freeipa-devel] [freeipa PR#272][comment] Build: makerpms.sh generates Python 2 & 3 packages at the same time

2016-11-28 Thread mbasti-rh
URL: https://github.com/freeipa/freeipa/pull/272 Title: #272: Build: makerpms.sh generates Python 2 & 3 packages at the same time mbasti-rh commented: """ Shouldn't be there python3 in BuildRequires as well? At least with python3-pylint we need python3 dependencies to be able do pylint3

[Freeipa-devel] [freeipa PR#276][synchronized] replica-conncheck: improve error msg + logging

2016-11-28 Thread tomaskrizek
URL: https://github.com/freeipa/freeipa/pull/276 Author: tomaskrizek Title: #276: replica-conncheck: improve error msg + logging Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/276/head:pr276 git checkout

[Freeipa-devel] [freeipa PR#270][synchronized] Test: uniqueness of certificate renewal master

2016-11-28 Thread ofayans
URL: https://github.com/freeipa/freeipa/pull/270 Author: ofayans Title: #270: Test: uniqueness of certificate renewal master Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/270/head:pr270 git checkout

[Freeipa-devel] [freeipa PR#274][comment] Improve the robustness FreeIPA's i18n module and its tests

2016-11-28 Thread mbasti-rh
URL: https://github.com/freeipa/freeipa/pull/274 Title: #274: Improve the robustness FreeIPA's i18n module and its tests mbasti-rh commented: """ Fixed upstream master: https://fedorahosted.org/freeipa/changeset/211c944a353dbc241ae6e280c9474145ab48dbe4 """ See the full comment at

[Freeipa-devel] [freeipa PR#274][closed] Improve the robustness FreeIPA's i18n module and its tests

2016-11-28 Thread mbasti-rh
URL: https://github.com/freeipa/freeipa/pull/274 Author: martbab Title: #274: Improve the robustness FreeIPA's i18n module and its tests Action: closed To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/274/head:pr274 git

[Freeipa-devel] [freeipa PR#101][comment] Improved vault-show error message

2016-11-28 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/101 Title: #101: Improved vault-show error message stlaz commented: """ WONTFIX then. There's no winning here. """ See the full comment at https://github.com/freeipa/freeipa/pull/101#issuecomment-263265074 -- Manage your subscription for the

[Freeipa-devel] [freeipa PR#274][+pushed] Improve the robustness FreeIPA's i18n module and its tests

2016-11-28 Thread mbasti-rh
URL: https://github.com/freeipa/freeipa/pull/274 Title: #274: Improve the robustness FreeIPA's i18n module and its tests Label: +pushed -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#274][+ack] Improve the robustness FreeIPA's i18n module and its tests

2016-11-28 Thread mbasti-rh
URL: https://github.com/freeipa/freeipa/pull/274 Title: #274: Improve the robustness FreeIPA's i18n module and its tests Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#273][+ack] Build: workaround bug while calling parallel make from rpmbuild

2016-11-28 Thread mbasti-rh
URL: https://github.com/freeipa/freeipa/pull/273 Title: #273: Build: workaround bug while calling parallel make from rpmbuild Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#276][opened] replica-conncheck: improve error msg + logging

2016-11-28 Thread tomaskrizek
URL: https://github.com/freeipa/freeipa/pull/276 Author: tomaskrizek Title: #276: replica-conncheck: improve error msg + logging Action: opened PR body: """ Replica conncheck may fail for other reasons then network misconfiguration. For example, an incorrect admin password might be provided.

[Freeipa-devel] [freeipa PR#101][comment] Improved vault-show error message

2016-11-28 Thread mbasti-rh
URL: https://github.com/freeipa/freeipa/pull/101 Title: #101: Improved vault-show error message mbasti-rh commented: """ I had discussion with @jcholast and he disagrees. This weird handling of DN should stay isolated in vault code and shouldn't be spreaded across the framework. I'm starting

[Freeipa-devel] [freeipa PR#255][comment] Adjustments for setup requirements

2016-11-28 Thread mbasti-rh
URL: https://github.com/freeipa/freeipa/pull/255 Title: #255: Adjustments for setup requirements mbasti-rh commented: """ Better now, but commit message missing explanation why bumping requires was needed. """ See the full comment at

[Freeipa-devel] [freeipa PR#270][comment] Test: uniqueness of certificate renewal master

2016-11-28 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/270 Title: #270: Test: uniqueness of certificate renewal master flo-renaud commented: """ Hi, you may also want to perform the same test after changing the renewal master with _ipa config-mod --ca-renewal-master-server newrenewalmaster.example.com_.

[Freeipa-devel] [freeipa PR#271][comment] Remove hard dependency on ipaplatform from ipapython, ipalib and ipaclient

2016-11-28 Thread tiran
URL: https://github.com/freeipa/freeipa/pull/271 Title: #271: Remove hard dependency on ipaplatform from ipapython, ipalib and ipaclient tiran commented: """ This PR is just too big and has too many CI errors to even begin a sensible review. I would need at least half a day without any

[Freeipa-devel] [freeipa PR#275][opened] Enhance __repr__ method of Principal

2016-11-28 Thread martbab
URL: https://github.com/freeipa/freeipa/pull/275 Author: martbab Title: #275: Enhance __repr__ method of Principal Action: opened PR body: """ `__repr__` now returns more descriptive string containing the actual principal name while keeping the ability to reconstruct the object from it. This

[Freeipa-devel] [freeipa PR#101][synchronized] Improved vault-show error message

2016-11-28 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/101 Author: stlaz Title: #101: Improved vault-show error message Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/101/head:pr101 git checkout pr101 From

[Freeipa-devel] [freeipa PR#255][synchronized] Adjustments for setup requirements

2016-11-28 Thread tiran
URL: https://github.com/freeipa/freeipa/pull/255 Author: tiran Title: #255: Adjustments for setup requirements Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/255/head:pr255 git checkout pr255 From

[Freeipa-devel] [freeipa PR#267][synchronized] ipa-replica-conncheck: do not close listening ports until required

2016-11-28 Thread tomaskrizek
URL: https://github.com/freeipa/freeipa/pull/267 Author: tomaskrizek Title: #267: ipa-replica-conncheck: do not close listening ports until required Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa