[Freeipa-devel] [freeipa PR#355][synchronized] Set up DS TLS on replica in CA-less topology

2016-12-21 Thread frasertweedale
URL: https://github.com/freeipa/freeipa/pull/355 Author: frasertweedale Title: #355: Set up DS TLS on replica in CA-less topology Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/355/head:pr355 git checkout

[Freeipa-devel] [freeipa PR#359][comment] dogtag: search past the first 100 certificates

2016-12-21 Thread frasertweedale
URL: https://github.com/freeipa/freeipa/pull/359 Title: #359: dogtag: search past the first 100 certificates frasertweedale commented: """ This change is working for me, including having the expected behaviour for WebUI. @tomaskrizek please provide steps to reproduce your WebUI behaviour. """

[Freeipa-devel] [freeipa PR#355][synchronized] Set up DS TLS on replica in CA-less topology

2016-12-21 Thread frasertweedale
URL: https://github.com/freeipa/freeipa/pull/355 Author: frasertweedale Title: #355: Set up DS TLS on replica in CA-less topology Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/355/head:pr355 git checkout

[Freeipa-devel] [freeipa PR#317][comment] Unify password generation across FreeIPA

2016-12-21 Thread mbasti-rh
URL: https://github.com/freeipa/freeipa/pull/317 Title: #317: Unify password generation across FreeIPA mbasti-rh commented: """ I would like to review this as well, so removing ACK to prevent pushing this to master """ See the full comment at

[Freeipa-devel] [freeipa PR#317][-ack] Unify password generation across FreeIPA

2016-12-21 Thread mbasti-rh
URL: https://github.com/freeipa/freeipa/pull/317 Title: #317: Unify password generation across FreeIPA Label: -ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#317][comment] Unify password generation across FreeIPA

2016-12-21 Thread pspacek
URL: https://github.com/freeipa/freeipa/pull/317 Title: #317: Unify password generation across FreeIPA pspacek commented: """ Works for me, server installation including DNSSEC worked fine. """ See the full comment at https://github.com/freeipa/freeipa/pull/317#issuecomment-268575899 --

[Freeipa-devel] [freeipa PR#317][+ack] Unify password generation across FreeIPA

2016-12-21 Thread pspacek
URL: https://github.com/freeipa/freeipa/pull/317 Title: #317: Unify password generation across FreeIPA Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#355][comment] Set up DS TLS on replica in CA-less topology

2016-12-21 Thread mbasti-rh
URL: https://github.com/freeipa/freeipa/pull/355 Title: #355: Set up DS TLS on replica in CA-less topology mbasti-rh commented: """ > @tomaskrizek FYI, the current documentation states that ipa-certupdate must > be run after ipa-ca-install (see >

[Freeipa-devel] [freeipa PR#299][closed] Remove "Request Certificate with SubjectAltName" permission

2016-12-21 Thread martbab
URL: https://github.com/freeipa/freeipa/pull/299 Author: frasertweedale Title: #299: Remove "Request Certificate with SubjectAltName" permission Action: closed To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/299/head:pr299 git

[Freeipa-devel] [freeipa PR#299][comment] Remove "Request Certificate with SubjectAltName" permission

2016-12-21 Thread martbab
URL: https://github.com/freeipa/freeipa/pull/299 Title: #299: Remove "Request Certificate with SubjectAltName" permission martbab commented: """ Fixed upstream master: https://fedorahosted.org/freeipa/changeset/bdbb1c34a2f5ef864cd3a943dcd047cde20de681 """ See the full comment at

[Freeipa-devel] [freeipa PR#299][+pushed] Remove "Request Certificate with SubjectAltName" permission

2016-12-21 Thread martbab
URL: https://github.com/freeipa/freeipa/pull/299 Title: #299: Remove "Request Certificate with SubjectAltName" permission Label: +pushed -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#299][+ack] Remove "Request Certificate with SubjectAltName" permission

2016-12-21 Thread martbab
URL: https://github.com/freeipa/freeipa/pull/299 Title: #299: Remove "Request Certificate with SubjectAltName" permission Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#361][opened] This PR implements a number of improvements for our Travis CI:

2016-12-21 Thread martbab
URL: https://github.com/freeipa/freeipa/pull/361 Author: martbab Title: #361: This PR implements a number of improvements for our Travis CI: Action: opened PR body: """ * split out the test runner part into a standalone script, .travis.yml should now only define test matrix, set environment

[Freeipa-devel] [freeipa PR#355][comment] Set up DS TLS on replica in CA-less topology

2016-12-21 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/355 Title: #355: Set up DS TLS on replica in CA-less topology flo-renaud commented: """ @tomaskrizek FYI, the current documentation states that ipa-certupdate must be run after ipa-ca-install (see

[Freeipa-devel] [freeipa PR#317][synchronized] Unify password generation across FreeIPA

2016-12-21 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/317 Author: stlaz Title: #317: Unify password generation across FreeIPA Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/317/head:pr317 git checkout pr317 From

[Freeipa-devel] [freeipa PR#317][synchronized] Unify password generation across FreeIPA

2016-12-21 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/317 Author: stlaz Title: #317: Unify password generation across FreeIPA Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/317/head:pr317 git checkout pr317 From

[Freeipa-devel] [freeipa PR#359][comment] dogtag: search past the first 100 certificates

2016-12-21 Thread tomaskrizek
URL: https://github.com/freeipa/freeipa/pull/359 Title: #359: dogtag: search past the first 100 certificates tomaskrizek commented: """ With this fix, more than 100 certificates are displayed and click-able from WebUI overview. However, I'm still getting an error message pop up saying ```

[Freeipa-devel] [freeipa PR#360][opened] x509: use PyASN1 to parse PKCS#7

2016-12-21 Thread jcholast
URL: https://github.com/freeipa/freeipa/pull/360 Author: jcholast Title: #360: x509: use PyASN1 to parse PKCS#7 Action: opened PR body: """ Use PyASN1 with the PKCS#7 definitions from `pyasn1_modules` to parse PKCS#7 in `pkcs7_to_pems()` instead of calling `openssl pkcs7` in a subprocess.

[Freeipa-devel] [freeipa PR#317][synchronized] Unify password generation across FreeIPA

2016-12-21 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/317 Author: stlaz Title: #317: Unify password generation across FreeIPA Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/317/head:pr317 git checkout pr317 From

[Freeipa-devel] [freeipa PR#358][comment] Use the tar Posix option for tarballs

2016-12-21 Thread martbab
URL: https://github.com/freeipa/freeipa/pull/358 Title: #358: Use the tar Posix option for tarballs martbab commented: """ Fixed upstream master: https://fedorahosted.org/freeipa/changeset/2bc01ec5b4a91a805912bdada429a91ab08ed196 """ See the full comment at

[Freeipa-devel] [freeipa PR#358][closed] Use the tar Posix option for tarballs

2016-12-21 Thread martbab
URL: https://github.com/freeipa/freeipa/pull/358 Author: simo5 Title: #358: Use the tar Posix option for tarballs Action: closed To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/358/head:pr358 git checkout pr358 -- Manage your

[Freeipa-devel] [freeipa PR#358][+pushed] Use the tar Posix option for tarballs

2016-12-21 Thread martbab
URL: https://github.com/freeipa/freeipa/pull/358 Title: #358: Use the tar Posix option for tarballs Label: +pushed -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#358][+ack] Use the tar Posix option for tarballs

2016-12-21 Thread pspacek
URL: https://github.com/freeipa/freeipa/pull/358 Title: #358: Use the tar Posix option for tarballs Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#358][comment] Use the tar Posix option for tarballs

2016-12-21 Thread pspacek
URL: https://github.com/freeipa/freeipa/pull/358 Title: #358: Use the tar Posix option for tarballs pspacek commented: """ Thanks, ACK! """ See the full comment at https://github.com/freeipa/freeipa/pull/358#issuecomment-268527273 -- Manage your subscription for the Freeipa-devel mailing

[Freeipa-devel] [freeipa PR#355][comment] Set up DS TLS on replica in CA-less topology

2016-12-21 Thread tomaskrizek
URL: https://github.com/freeipa/freeipa/pull/355 Title: #355: Set up DS TLS on replica in CA-less topology tomaskrizek commented: """ I've tested the following use cases: - CA-less replica promotion domlvl1: *ldapssl running*; but the following behaviour is present: If `ipa-ca-install` is

[Freeipa-devel] [freeipa PR#348][comment] ca: fix ca-find with --pkey-only

2016-12-21 Thread frasertweedale
URL: https://github.com/freeipa/freeipa/pull/348 Title: #348: ca: fix ca-find with --pkey-only frasertweedale commented: """ LGTM """ See the full comment at https://github.com/freeipa/freeipa/pull/348#issuecomment-268509213 -- Manage your subscription for the Freeipa-devel mailing list:

[Freeipa-devel] [freeipa PR#298][closed] ipaldap: handle binary encoding option transparently

2016-12-21 Thread frasertweedale
URL: https://github.com/freeipa/freeipa/pull/298 Author: frasertweedale Title: #298: ipaldap: handle binary encoding option transparently Action: closed To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/298/head:pr298 git

[Freeipa-devel] [freeipa PR#298][comment] ipaldap: handle binary encoding option transparently

2016-12-21 Thread frasertweedale
URL: https://github.com/freeipa/freeipa/pull/298 Title: #298: ipaldap: handle binary encoding option transparently frasertweedale commented: """ OK, let's just fix all the plugins / other routines that deal with the relevant attributes to explicitly read both `userCertificate` and

[Freeipa-devel] [freeipa PR#358][comment] Use the tar Posix option for tarballs

2016-12-21 Thread simo5
URL: https://github.com/freeipa/freeipa/pull/358 Title: #358: Use the tar Posix option for tarballs simo5 commented: """ Amended """ See the full comment at https://github.com/freeipa/freeipa/pull/358#issuecomment-268507057 -- Manage your subscription for the Freeipa-devel mailing list:

[Freeipa-devel] [freeipa PR#358][synchronized] Use the tar Posix option for tarballs

2016-12-21 Thread simo5
URL: https://github.com/freeipa/freeipa/pull/358 Author: simo5 Title: #358: Use the tar Posix option for tarballs Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/358/head:pr358 git checkout pr358 From

[Freeipa-devel] [freeipa PR#348][synchronized] ca: fix ca-find with --pkey-only

2016-12-21 Thread jcholast
URL: https://github.com/freeipa/freeipa/pull/348 Author: jcholast Title: #348: ca: fix ca-find with --pkey-only Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/348/head:pr348 git checkout pr348 From

[Freeipa-devel] [freeipa PR#298][comment] ipaldap: handle binary encoding option transparently

2016-12-21 Thread jcholast
URL: https://github.com/freeipa/freeipa/pull/298 Title: #298: ipaldap: handle binary encoding option transparently jcholast commented: """ > If `ipaldap` is a generic LDAP client, it should obey the RFCs and always > transfer the relevant attributes (`userCertificate`, `cACertificate`, etc)

[Freeipa-devel] [freeipa PR#359][opened] dogtag: search past the first 100 certificates

2016-12-21 Thread jcholast
URL: https://github.com/freeipa/freeipa/pull/359 Author: jcholast Title: #359: dogtag: search past the first 100 certificates Action: opened PR body: """ Dogtag requires a size limit to be specified when searching for certificates. When no limit is specified in the dogtag plugin, a limit of