URL: https://github.com/freeipa/freeipa/pull/747
Title: #747: vault: piped input for ipa vault-add fails
Label: +ack
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/737
Title: #737: Vault: Explicitly default to 3DES CBC
frasertweedale commented:
"""
Tested; fix makes it work again against Dogtag (where Dogtag does not contain
Ade's fix). ACK.
"""
See the full comment at
URL: https://github.com/freeipa/freeipa/pull/737
Title: #737: Vault: Explicitly default to 3DES CBC
Label: +ack
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/737
Title: #737: Vault: Explicitly default to 3DES CBC
Label: +blocker
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/747
Author: flo-renaud
Title: #747: vault: piped input for ipa vault-add fails
Action: opened
PR body:
"""
An exception is raised when using echo "Secret123\n" | ipa vault-add myvault
This happens because the code is using
URL: https://github.com/freeipa/freeipa/pull/746
Author: MartinBasti
Title: #746: KDC proxy URI records
Action: edited
Changed field: body
Original value:
"""
Automatic creation of KDC proxy URI records
Enables creation of following KDC proxy URL records per each replica:
URL: https://github.com/freeipa/freeipa/pull/746
Title: #746: KDC proxy URI records
Label: +postponed
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code
URL: https://github.com/freeipa/freeipa/pull/746
Author: MartinBasti
Title: #746: KDC proxy URI records
Action: opened
PR body:
"""
Automatic creation of KDC proxy URI records
Enables creation of following KDC proxy URL records per each replica:
_kerberos.example.com. IN URI
URL: https://github.com/freeipa/freeipa/pull/745
Author: MartinBasti
Title: #745: tests: add missing dependency iptables
Action: opened
PR body:
"""
KDC proxy tests are using iptables, but this is optional package in at
least Fedora cloud image, thus we must have it in dependencies
"""
To
URL: https://github.com/freeipa/freeipa/pull/737
Title: #737: Vault: Explicitly default to 3DES CBC
tiran commented:
"""
I talked to Matt. Dogtag 10.4 will not be pushed to F25 and F26, only
rawhide/F27. Additionally, Ade will also address the bug in Dogtag. The next
10.4 release will have a
On 2017-04-27 16:16, Martin Bašti wrote:
>
>
> On 27.04.2017 14:19, Christian Heimes wrote:
>> On 2017-04-27 14:00, Martin Bašti wrote:
>>> I would like to discuss consequences of adding kdc URI records:
>>>
>>> 1. basically all ipa clients enrolled using autodiscovery will use
>>> kdcproxy
On Thu, 2017-04-27 at 15:56 +0200, Petr Vobornik wrote:
> On 04/27/2017 02:19 PM, Christian Heimes wrote:
> > On 2017-04-27 14:00, Martin Bašti wrote:
> > > I would like to discuss consequences of adding kdc URI records:
> > >
> > > 1. basically all ipa clients enrolled using autodiscovery will
>
On 27.04.2017 14:19, Christian Heimes wrote:
On 2017-04-27 14:00, Martin Bašti wrote:
I would like to discuss consequences of adding kdc URI records:
1. basically all ipa clients enrolled using autodiscovery will use
kdcproxy instead of KDC on port 88, because URI takes precedence over
SRV
On 04/27/2017 02:19 PM, Christian Heimes wrote:
On 2017-04-27 14:00, Martin Bašti wrote:
I would like to discuss consequences of adding kdc URI records:
1. basically all ipa clients enrolled using autodiscovery will use
kdcproxy instead of KDC on port 88, because URI takes precedence over
SRV
URL: https://github.com/freeipa/freeipa/pull/729
Author: pvomacka
Title: #729: Turn on NSSOCSP check in mod_nss conf
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/729/head:pr729
git checkout pr729
From
URL: https://github.com/freeipa/freeipa/pull/742
Title: #742: Revert "Store GSSAPI session key in /var/run/ipa"
martbab commented:
"""
master:
* 50f6883662e258b0335c8b3cb69946d6dcbf206c Revert "Store GSSAPI session key in
/var/run/ipa"
"""
See the full comment at
URL: https://github.com/freeipa/freeipa/pull/742
Author: martbab
Title: #742: Revert "Store GSSAPI session key in /var/run/ipa"
Action: closed
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/742/head:pr742
git checkout pr742
URL: https://github.com/freeipa/freeipa/pull/742
Title: #742: Revert "Store GSSAPI session key in /var/run/ipa"
Label: +pushed
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/743
Title: #743: [ipa-4-5] Revert "Store GSSAPI session key in /var/run/ipa"
martbab commented:
"""
ipa-4-5:
* a4e1ab6c893182b8b3610c0b45120194be4a0376 Revert "Store GSSAPI session key in
/var/run/ipa"
"""
See the full comment at
URL: https://github.com/freeipa/freeipa/pull/743
Title: #743: [ipa-4-5] Revert "Store GSSAPI session key in /var/run/ipa"
Label: +pushed
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/743
Author: martbab
Title: #743: [ipa-4-5] Revert "Store GSSAPI session key in /var/run/ipa"
Action: closed
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/743/head:pr743
git
URL: https://github.com/freeipa/freeipa/pull/671
Author: tiran
Title: #671: Slim down dependencies
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/671/head:pr671
git checkout pr671
From
URL: https://github.com/freeipa/freeipa/pull/671
Author: tiran
Title: #671: Slim down dependencies
Action: edited
Changed field: body
Original value:
"""
* Remove unused install requires
* Correct dependencies for yubico otptoken
* Properly report optional dependency for yubico otptoken
*
URL: https://github.com/freeipa/freeipa/pull/671
Author: tiran
Title: #671: Slim down dependencies
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/671/head:pr671
git checkout pr671
From
URL: https://github.com/freeipa/freeipa/pull/744
Author: tiran
Title: #744: [4.5] Correct PyPI package dependencies
Action: opened
PR body:
"""
* Remove unused install requires from ipapython
* Add missing requirements to ipaserver
* Correct dependencies for yubico otptoken
* Python 2 uses
URL: https://github.com/freeipa/freeipa/pull/742
Author: martbab
Title: #742: Revert "Store GSSAPI session key in /var/run/ipa"
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/742/head:pr742
git checkout
URL: https://github.com/freeipa/freeipa/pull/743
Author: martbab
Title: #743: [ipa-4-5] Revert "Store GSSAPI session key in /var/run/ipa"
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/743/head:pr743
git
URL: https://github.com/freeipa/freeipa/pull/742
Title: #742: Revert "Store GSSAPI session key in /var/run/ipa"
Label: +ack
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/743
Title: #743: [ipa-4-5] Revert "Store GSSAPI session key in /var/run/ipa"
Label: +ack
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/742
Title: #742: Revert "Store GSSAPI session key in /var/run/ipa"
Label: -ack
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/742
Title: #742: Revert "Store GSSAPI session key in /var/run/ipa"
Label: +ack
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/723
Title: #723: Store GSSAPI session key in /var/run/httpd
simo5 commented:
"""
The current patch moved the key in a place where apache cannot write, resulting
in an ephemeral key that is thrown away each time apache is restarted/reloaded.
"""
See
URL: https://github.com/freeipa/freeipa/pull/743
Author: martbab
Title: #743: [ipa-4-5] Revert "Store GSSAPI session key in /var/run/ipa"
Action: opened
PR body:
"""
This reverts commit 2bab2d4. It was
pointed out that apache has no access to /var/lib/ipa directry breaking
the session
URL: https://github.com/freeipa/freeipa/pull/723
Title: #723: Store GSSAPI session key in /var/run/httpd
simo5 commented:
"""
As I noted in the ticket: "At most you may want to store it in
/var/lib/ipa/somewhere, but we do not want to break sessions (there are people
using APIs from
URL: https://github.com/freeipa/freeipa/pull/742
Author: martbab
Title: #742: Revert "Store GSSAPI session key in /var/run/ipa"
Action: opened
PR body:
"""
This reverts commit 2bab2d4963daa99742875f3633a99966bc56f5a3. It was
pointed out that apache has no access to /var/lib/ipa directry
URL: https://github.com/freeipa/freeipa/pull/723
Author: MartinBasti
Title: #723: Store GSSAPI session key in /var/run/httpd
Action: reopened
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/723/head:pr723
git checkout pr723
--
URL: https://github.com/freeipa/freeipa/pull/723
Title: #723: Store GSSAPI session key in /var/run/httpd
simo5 commented:
"""
This patch is wrong please revert
"""
See the full comment at
https://github.com/freeipa/freeipa/pull/723#issuecomment-297699615
--
Manage your subscription for the
On Thu, 2017-04-27 at 10:42 +0200, MartinBasti wrote:
> URL: https://github.com/freeipa/freeipa/pull/723
> Title: #723: Store GSSAPI session key in /var/run/httpd
>
> Label: +ack
Guys I explained in the bug[1] that this is wrong, why was this acked
and pushed ?
Besides how does this even work
On 2017-04-27 14:00, Martin Bašti wrote:
> I would like to discuss consequences of adding kdc URI records:
>
> 1. basically all ipa clients enrolled using autodiscovery will use
> kdcproxy instead of KDC on port 88, because URI takes precedence over
> SRV in KRB5 client implementation. Are we ok
On 26.04.2017 20:41, Simo Sorce wrote:
On Wed, 2017-04-26 at 12:57 +0200, Martin Bašti wrote:
On 25.04.2017 16:57, Martin Bašti wrote:
Hello all,
I'm going to implement automatic URI records for kdc proxy and I'd
like to clarify if following URI records are the right one.
URL: https://github.com/freeipa/freeipa/pull/740
Author: Akasurde
Title: #740: [4.5]Hide PKI Client database password in log file
Action: closed
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/740/head:pr740
git checkout pr740
URL: https://github.com/freeipa/freeipa/pull/740
Title: #740: [4.5]Hide PKI Client database password in log file
martbab commented:
"""
ipa-4-5:
* 1d911fc2186da1c6566648f94a6819c4e7a2a72b Hide PKI Client database password in
log file
"""
See the full comment at
URL: https://github.com/freeipa/freeipa/pull/740
Title: #740: [4.5]Hide PKI Client database password in log file
Label: +pushed
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/740
Title: #740: [4.5]Hide PKI Client database password in log file
Label: +ack
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/741
Author: stlaz
Title: #741: 6.9 -> 7.4 migration fixes
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/741/head:pr741
git checkout pr741
From
URL: https://github.com/freeipa/freeipa/pull/741
Author: stlaz
Title: #741: Migration
Action: opened
PR body:
"""
**Allow rewriting of cached properties**
Cached property should not be treated anyway special from a normal
property. If we need to rewrite/remove it, we should be able to do
URL: https://github.com/freeipa/freeipa/pull/741
Author: stlaz
Title: #741: Migration
Action: edited
Changed field: title
Original value:
"""
Migration
"""
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to
URL: https://github.com/freeipa/freeipa/pull/740
Author: Akasurde
Title: #740: [4.5]Hide PKI Client database password in log file
Action: opened
PR body:
"""
This fix masks PKI client database password from showing
in CA/KRA installer log file
Fixes https://pagure.io/freeipa/issue/6904
URL: https://github.com/freeipa/freeipa/pull/733
Title: #733: [4.5] Fix CA/server cert validation in FIPS
stlaz commented:
"""
Made a quickfix according to @tiran, the ACK can stay. Thanks, I was being
paranoid.
"""
See the full comment at
URL: https://github.com/freeipa/freeipa/pull/733
Author: stlaz
Title: #733: [4.5] Fix CA/server cert validation in FIPS
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/733/head:pr733
git checkout pr733
URL: https://github.com/freeipa/freeipa/pull/723
Title: #723: Store GSSAPI session key in /var/run/httpd
martbab commented:
"""
master:
* 2bab2d4963daa99742875f3633a99966bc56f5a3 Store GSSAPI session key in
/var/run/ipa
ipa-4-5:
* b2aa3ed0bc9f5385ab6e8b1720d9f1d33136e5dc Store GSSAPI session
URL: https://github.com/freeipa/freeipa/pull/723
Author: MartinBasti
Title: #723: Store GSSAPI session key in /var/run/httpd
Action: closed
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/723/head:pr723
git checkout pr723
--
URL: https://github.com/freeipa/freeipa/pull/733
Title: #733: [4.5] Fix CA/server cert validation in FIPS
Label: +ack
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/723
Title: #723: Store GSSAPI session key in /var/run/httpd
Label: +pushed
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/694
Title: #694: RFC: implement local PKINIT deployment in server/replica install
martbab commented:
"""
Any volunteer to do a functional review?
"""
See the full comment at
https://github.com/freeipa/freeipa/pull/694#issuecomment-297677004
--
URL: https://github.com/freeipa/freeipa/pull/723
Title: #723: Store GSSAPI session key in /var/run/httpd
Label: +ack
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/723
Title: #723: Store GSSAPI session key in /var/run/httpd
MartinBasti commented:
"""
This approach was agreed on devel meeting
"""
See the full comment at
https://github.com/freeipa/freeipa/pull/723#issuecomment-297651621
--
Manage your
URL: https://github.com/freeipa/freeipa/pull/694
Title: #694: RFC: implement local PKINIT deployment in server/replica install
HonzaCholasta commented:
"""
LGTM.
"""
See the full comment at
https://github.com/freeipa/freeipa/pull/694#issuecomment-297645225
--
Manage your subscription for the
URL: https://github.com/freeipa/freeipa/pull/694
Author: martbab
Title: #694: RFC: implement local PKINIT deployment in server/replica install
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/694/head:pr694
URL: https://github.com/freeipa/freeipa/pull/735
Title: #735: automount install: do not wait for sssd restart on uninstallation
pvoborni commented:
"""
The error message was reverted to original (I was fixing the comment below and
wondered why it was not fixed, now I know).
"""
See the full
URL: https://github.com/freeipa/freeipa/pull/735
Author: pvoborni
Title: #735: automount install: do not wait for sssd restart on uninstallation
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa
URL: https://github.com/freeipa/freeipa/pull/739
Title: #739: [4.5] spec file: bump krb5 Requires for certauth fixes
Label: +pushed
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/731
Title: #731: spec file: bump krb5 Requires for certauth fixes
Label: +pushed
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/739
Title: #739: [4.5] spec file: bump krb5 Requires for certauth fixes
martbab commented:
"""
ipa-4-5:
* ec3a2a6063beb4ec96796b66abb82476a5c7bd0f spec file: bump krb5 Requires for
certauth fixes
"""
See the full comment at
URL: https://github.com/freeipa/freeipa/pull/739
Author: HonzaCholasta
Title: #739: [4.5] spec file: bump krb5 Requires for certauth fixes
Action: closed
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/739/head:pr739
git
URL: https://github.com/freeipa/freeipa/pull/731
Author: HonzaCholasta
Title: #731: spec file: bump krb5 Requires for certauth fixes
Action: closed
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/731/head:pr731
git checkout
URL: https://github.com/freeipa/freeipa/pull/731
Title: #731: spec file: bump krb5 Requires for certauth fixes
martbab commented:
"""
master:
* 0f42670afa935801c25bc66f733a8d1b90ea5a0b spec file: bump krb5 Requires for
certauth fixes
"""
See the full comment at
URL: https://github.com/freeipa/freeipa/pull/739
Title: #739: [4.5] spec file: bump krb5 Requires for certauth fixes
Label: +ack
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
68 matches
Mail list logo