Re: [Freeipa-devel] [PATCH 0033] Fix CA being presented as running even if it weren't

2016-06-15 Thread Martin Basti
On 02.06.2016 19:21, Martin Basti wrote: On 31.05.2016 16:32, Stanislav Laznicka wrote: On 05/31/2016 11:40 AM, Stanislav Laznicka wrote: On 05/31/2016 10:22 AM, Stanislav Laznicka wrote: On 05/30/2016 12:54 PM, Jan Cholasta wrote: On 30.5.2016 12:36, Martin Basti wrote: On 26.05.2016

Re: [Freeipa-devel] [PATCH] 0021 slapi-nis should allow password update on a virtual entry

2016-06-15 Thread Martin Basti
On 15.06.2016 17:19, thierry bordaz wrote: Hello, This patch is for https://fedorahosted.org/freeipa/ticket/5955 Please put this link to commit message This is the last patch related "IdM user password change support for legacy client compat tree" * It requires DS > 1.3.5.5 (https://fe

Re: [Freeipa-devel] [PATCH] 0068 upgrade: do not try to start CA if not configured

2016-06-15 Thread Martin Basti
On 15.06.2016 17:19, Martin Basti wrote: On 15.06.2016 17:17, Martin Basti wrote: On 15.06.2016 16:41, Petr Spacek wrote: On 15.6.2016 14:18, Fraser Tweedale wrote: Attached patch fixes https://fedorahosted.org/freeipa/ticket/5958. The regression was introduced in fix for https

Re: [Freeipa-devel] [PATCH] 0068 upgrade: do not try to start CA if not configured

2016-06-15 Thread Martin Basti
On 15.06.2016 17:17, Martin Basti wrote: On 15.06.2016 16:41, Petr Spacek wrote: On 15.6.2016 14:18, Fraser Tweedale wrote: Attached patch fixes https://fedorahosted.org/freeipa/ticket/5958. The regression was introduced in fix for https://fedorahosted.org/freeipa/ticket/5868. It works

Re: [Freeipa-devel] [PATCH] 0068 upgrade: do not try to start CA if not configured

2016-06-15 Thread Martin Basti
On 15.06.2016 16:41, Petr Spacek wrote: On 15.6.2016 14:18, Fraser Tweedale wrote: Attached patch fixes https://fedorahosted.org/freeipa/ticket/5958. The regression was introduced in fix for https://fedorahosted.org/freeipa/ticket/5868. It works for me, ACK. Pushed to master: 01795fca831ca5

Re: [Freeipa-devel] [freeipa-devel][PATCH] Added missing translation to automount.py method

2016-06-15 Thread Martin Basti
On 15.06.2016 11:13, Abhijeet Kasurde wrote: Hi All, Please review the attached patch. Fixes: https://fedorahosted.org/freeipa/ticket/5920 Thank you for the patch, Please follow this page for howto create internationalized strings: http://www.freeipa.org/page/Python_Coding_Style#Python_

Re: [Freeipa-devel] [PATCH 0159-0160] emancipate IPA NTP service into role

2016-06-15 Thread Martin Basti
On 15.06.2016 13:29, Petr Spacek wrote: On 15.6.2016 09:57, Martin Basti wrote: On 15.06.2016 09:55, Petr Vobornik wrote: On 06/14/2016 07:28 PM, Martin Basti wrote: On 14.06.2016 18:58, Martin Babinsky wrote: On 06/14/2016 05:06 PM, Martin Basti wrote: On 12.06.2016 17:37, Martin

Re: [Freeipa-devel] [PATCH] 0206 adtrust optimize forest root LDAP filter

2016-06-15 Thread Martin Basti
On 15.06.2016 09:02, Martin Babinsky wrote: On 06/14/2016 04:45 PM, Alexander Bokovoy wrote: On Tue, 07 Jun 2016, Alexander Bokovoy wrote: Hi, `ipa trust-find' command should only show trusted forest root domains The child domains should be visible via ipa trustdomain-find forest.root T

Re: [Freeipa-devel] [PATCH] 0045-47: webui: Sub-CAs

2016-06-15 Thread Martin Basti
On 14.06.2016 18:30, Petr Vobornik wrote: On 06/14/2016 10:17 AM, Pavel Vomacka wrote: On 06/14/2016 06:42 AM, Fraser Tweedale wrote: On Mon, Jun 13, 2016 at 07:48:58PM +0200, Pavel Vomacka wrote: On 06/13/2016 06:55 AM, Fraser Tweedale wrote: On Fri, Jun 10, 2016 at 04:34:33PM +0200, Pave

Re: [Freeipa-devel] [PATCH 0159-0160] emancipate IPA NTP service into role

2016-06-15 Thread Martin Basti
On 15.06.2016 09:55, Petr Vobornik wrote: On 06/14/2016 07:28 PM, Martin Basti wrote: On 14.06.2016 18:58, Martin Babinsky wrote: On 06/14/2016 05:06 PM, Martin Basti wrote: On 12.06.2016 17:37, Martin Babinsky wrote: These two patches turn oft-neglected ntp service into a full fledged

Re: [Freeipa-devel] [PATCH 0159-0160] emancipate IPA NTP service into role

2016-06-14 Thread Martin Basti
On 14.06.2016 18:58, Martin Babinsky wrote: On 06/14/2016 05:06 PM, Martin Basti wrote: On 12.06.2016 17:37, Martin Babinsky wrote: These two patches turn oft-neglected ntp service into a full fledged role whose status can be queried centrally. They should also enable generation of

Re: [Freeipa-devel] [PATCH 0159-0160] emancipate IPA NTP service into role

2016-06-14 Thread Martin Basti
On 12.06.2016 17:37, Martin Babinsky wrote: These two patches turn oft-neglected ntp service into a full fledged role whose status can be queried centrally. They should also enable generation of location-specific _ntp._udp records. Please note that NTP is LDAP-enabled by additional call afte

Re: [Freeipa-devel] [PATCH 0042] Removed dead code from LDAPRemoveReverseMember

2016-06-14 Thread Martin Basti
On 14.06.2016 16:37, Jan Cholasta wrote: On 14.6.2016 16:29, Martin Basti wrote: On 08.06.2016 14:17, Stanislav Laznicka wrote: On 06/07/2016 10:42 AM, Martin Basti wrote: On 07.06.2016 10:43, Jan Cholasta wrote: On 7.6.2016 10:22, Martin Basti wrote: On 07.06.2016 09:07, Jan

Re: [Freeipa-devel] [PATCH 0042] Removed dead code from LDAPRemoveReverseMember

2016-06-14 Thread Martin Basti
On 08.06.2016 14:17, Stanislav Laznicka wrote: On 06/07/2016 10:42 AM, Martin Basti wrote: On 07.06.2016 10:43, Jan Cholasta wrote: On 7.6.2016 10:22, Martin Basti wrote: On 07.06.2016 09:07, Jan Cholasta wrote: On 6.6.2016 18:29, Martin Basti wrote: On 03.06.2016 14:28, Stanislav

Re: [Freeipa-devel] [PATCH 0041] Increase nsslapd-db-locks

2016-06-14 Thread Martin Basti
On 09.06.2016 12:42, Stanislav Laznicka wrote: On 06/07/2016 08:56 AM, thierry bordaz wrote: On 06/06/2016 07:23 PM, Martin Basti wrote: On 03.06.2016 13:38, Stanislav Laznicka wrote: Hello, The attached patch implements solution to https://fedorahosted.org/freeipa/ticket/5914. The

Re: [Freeipa-devel] [PATCH 0501] Revert: switch /usr/bin/ipa to python3

2016-06-14 Thread Martin Basti
On 14.06.2016 13:05, Martin Babinsky wrote: On 06/14/2016 11:56 AM, Martin Basti wrote: On 14.06.2016 10:14, Martin Basti wrote: On 10.06.2016 10:57, Martin Basti wrote: On 10.06.2016 06:17, Jan Cholasta wrote: On 9.6.2016 20:57, Martin Basti wrote: Py3 support was enabled

Re: [Freeipa-devel] [PATCH 0494] Bump required version of pki-ca and pki-kra due bug in parsing '%' in DM password

2016-06-14 Thread Martin Basti
On 02.06.2016 09:26, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/5690 Patch attached You can ignore this patch, dogtag version has been bumped by different patch -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo

Re: [Freeipa-devel] [PATCH 0501] Revert: switch /usr/bin/ipa to python3

2016-06-14 Thread Martin Basti
On 14.06.2016 10:14, Martin Basti wrote: On 10.06.2016 10:57, Martin Basti wrote: On 10.06.2016 06:17, Jan Cholasta wrote: On 9.6.2016 20:57, Martin Basti wrote: Py3 support was enabled prematurely, attached patches removes python3 from /usr/bin/ipa Notes: * ipa 4.3.x won't

Re: [Freeipa-devel] [PATCH 0501] Revert: switch /usr/bin/ipa to python3

2016-06-14 Thread Martin Basti
On 10.06.2016 10:57, Martin Basti wrote: On 10.06.2016 06:17, Jan Cholasta wrote: On 9.6.2016 20:57, Martin Basti wrote: Py3 support was enabled prematurely, attached patches removes python3 from /usr/bin/ipa Notes: * ipa 4.3.x won't have enabled py3 * master (ipa 4.4+) will

Re: [Freeipa-devel] [PATCH] 0003 batch command can be used to trigger internal errors on server

2016-06-14 Thread Martin Basti
On 14.06.2016 08:04, Stanislav Laznicka wrote: On 06/13/2016 10:15 AM, Petr Vobornik wrote: On 06/10/2016 06:31 PM, Stanislav Laznicka wrote: On 06/08/2016 02:06 PM, Florence Blanc-Renaud wrote: On 06/08/2016 10:07 AM, Petr Spacek wrote: On 7.6.2016 15:11, Stanislav Laznicka wrote: Hello,

Re: [Freeipa-devel] [PATCH 0103-4] installer: Fix single command replica install with --setup-dns

2016-06-13 Thread Martin Basti
On 09.06.2016 16:16, Martin Babinsky wrote: On 06/09/2016 08:16 AM, David Kupka wrote: Should go into master, ipa-4-3 and ipa-4-2. https://fedorahosted.org/freeipa/ticket/5945 Works for me, ACK Pushed to master: * 54318d1a2c5133fc3a735872b7edc3cfacb032f9 installer: positional_arguments m

Re: [Freeipa-devel] [PATCHES 0146-0152] Server Roles v2

2016-06-13 Thread Martin Basti
On 13.06.2016 07:26, Jan Cholasta wrote: On 12.6.2016 17:29, Martin Babinsky wrote: On 06/10/2016 05:42 PM, Martin Babinsky wrote: On 06/10/2016 02:22 PM, Jan Cholasta wrote: On 9.6.2016 17:06, Martin Babinsky wrote: On 06/09/2016 03:54 PM, Petr Vobornik wrote: On 06/09/2016 01:02 PM, Mart

Re: [Freeipa-devel] [PATCH 0023] topology plugins sigsev when adding a managed host

2016-06-13 Thread Martin Basti
On 13.06.2016 15:54, thierry bordaz wrote: The fix is good for me. ACK thanks thierry On 06/13/2016 10:04 AM, Ludwig Krispenz wrote: revised patch (v2) attached: changed log level fixed order of statements in freeing host list On 06/10/2016 05:56 PM, Ludwig Krispenz wrote: On 06/10/2016 0

Re: [Freeipa-devel] [PATCH 0503-0513] DNS locations

2016-06-13 Thread Martin Basti
On 13.06.2016 14:57, Martin Basti wrote: Patches attached. https://fedorahosted.org/freeipa/ticket/2008 Missing parts: dns-server config, some warnings from design, some corner, cleanup of old unused location records cases, this will be covered in future patches It should be 'c

[Freeipa-devel] [PATCH 0503-0513] DNS locations

2016-06-13 Thread Martin Basti
2001 From: Martin Basti Date: Tue, 7 Jun 2016 10:43:50 +0200 Subject: [PATCH 01/11] DNS Locations: add index for ipalocation attribute For performace ipalocation should be indexed because it is used by referint plugin https://fedorahosted.org/freeipa/ticket/2008 --- install/share/indices.ldif

Re: [Freeipa-devel] [PATCH 0491] Fix: Local variable s_indent might be referenced before defined

2016-06-13 Thread Martin Basti
On 01.06.2016 16:13, Martin Babinsky wrote: On 06/01/2016 03:59 PM, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/5921 Patch attached. ACK Pushed to master: 493ae1e5028c6ce8a0888146ee3de6c798caa55f -- Manage your subscription for the Freeipa-devel mailing list: https

Re: [Freeipa-devel] [PATCH] 0051: webui: correct jslint warning

2016-06-13 Thread Martin Basti
On 13.06.2016 13:50, Martin Basti wrote: On 13.06.2016 12:20, Pavel Vomacka wrote: On 06/13/2016 12:00 PM, Pavel Vomacka wrote: Hello, I forgot to run jslint during the last review and there was one warning, so this patch fixes it. -- Pavel^3 Vomacka Added ticket to the commit

Re: [Freeipa-devel] [PATCH] 0051: webui: correct jslint warning

2016-06-13 Thread Martin Basti
On 13.06.2016 12:20, Pavel Vomacka wrote: On 06/13/2016 12:00 PM, Pavel Vomacka wrote: Hello, I forgot to run jslint during the last review and there was one warning, so this patch fixes it. -- Pavel^3 Vomacka Added ticket to the commit message. Would be nice to have covered js

Re: [Freeipa-devel] [PATCH 0492] Translations: update ipa-4-3 translations

2016-06-13 Thread Martin Basti
On 13.06.2016 12:25, Martin Babinsky wrote: On 06/13/2016 11:48 AM, Martin Basti wrote: On 13.06.2016 09:33, Lukas Slebodnik wrote: On (09/06/16 12:32), Martin Basti wrote: On 07.06.2016 12:51, Martin Babinsky wrote: On 06/01/2016 05:10 PM, Martin Basti wrote: Patch attached. ACK

Re: [Freeipa-devel] [PATCH 0492] Translations: update ipa-4-3 translations

2016-06-13 Thread Martin Basti
On 13.06.2016 09:33, Lukas Slebodnik wrote: On (09/06/16 12:32), Martin Basti wrote: On 07.06.2016 12:51, Martin Babinsky wrote: On 06/01/2016 05:10 PM, Martin Basti wrote: Patch attached. ACK Pushed to ipa-4-3: 22fcf65cd1b674b21496b677818a8c75adcd70a6 I am not sure but it's

Re: [Freeipa-devel] [PATCH] 0208-0209 webUI changes for external trust and UPN suffixes

2016-06-11 Thread Martin Basti
On 10.06.2016 23:23, Alexander Bokovoy wrote: On Fri, 10 Jun 2016, Pavel Vomacka wrote: On 06/09/2016 02:19 PM, Alexander Bokovoy wrote: On Thu, 09 Jun 2016, Sumit Bose wrote: On Thu, Jun 09, 2016 at 02:30:52PM +0300, Alexander Bokovoy wrote: Hi, webUI changes to support external trust a

Re: [Freeipa-devel] [PATCH] 0202 support UPNs for trusted domain users

2016-06-11 Thread Martin Basti
On 11.06.2016 16:13, Martin Babinsky wrote: On 06/09/2016 07:19 PM, Alexander Bokovoy wrote: On Thu, 09 Jun 2016, Martin Babinsky wrote: On 06/09/2016 06:46 PM, Alexander Bokovoy wrote: On Thu, 09 Jun 2016, Martin Babinsky wrote: On 06/07/2016 07:35 PM, Alexander Bokovoy wrote: On Tue, 07

Re: [Freeipa-devel] Storing directory path in variables

2016-06-11 Thread Martin Basti
On 10.06.2016 17:14, Florence Blanc-Renaud wrote: Hi, I am working on a bug linked to a trailing / in a directory name. It looks like hardcoded paths for directories sometimes contain the trailing / but not always (for instance dsinstance.config_dirname() returns something like '/etc/dirs

Re: [Freeipa-devel] [PATCH][WIP] DNS Location: generator for location records

2016-06-10 Thread Martin Basti
On 10.06.2016 10:21, Martin Basti wrote: On 09.06.2016 12:21, Martin Basti wrote: Hello, here is WIP version of generator for IPA DNS records and locations, that is responsible for creating and updating all IPA records for all masters. Please note that this is not finished yet and

Re: [Freeipa-devel] [PATCH] 0203 adtrust: remove ipanttrustpartner parameter

2016-06-10 Thread Martin Basti
On 10.06.2016 12:13, Martin Basti wrote: On 10.06.2016 11:01, Martin Kosek wrote: On 06/10/2016 10:01 AM, Martin Basti wrote: On 09.06.2016 21:45, Alexander Bokovoy wrote: On Thu, 09 Jun 2016, Martin Basti wrote: On 09.06.2016 17:56, Martin Babinsky wrote: On 06/06/2016 01:37 PM

Re: [Freeipa-devel] [PATCH] 0203 adtrust: remove ipanttrustpartner parameter

2016-06-10 Thread Martin Basti
On 10.06.2016 11:01, Martin Kosek wrote: On 06/10/2016 10:01 AM, Martin Basti wrote: On 09.06.2016 21:45, Alexander Bokovoy wrote: On Thu, 09 Jun 2016, Martin Basti wrote: On 09.06.2016 17:56, Martin Babinsky wrote: On 06/06/2016 01:37 PM, Alexander Bokovoy wrote: On Mon, 06 Jun 2016

Re: [Freeipa-devel] [PATCH 0501] Revert: switch /usr/bin/ipa to python3

2016-06-10 Thread Martin Basti
On 10.06.2016 06:17, Jan Cholasta wrote: On 9.6.2016 20:57, Martin Basti wrote: Py3 support was enabled prematurely, attached patches removes python3 from /usr/bin/ipa Notes: * ipa 4.3.x won't have enabled py3 * master (ipa 4.4+) will have disabled py3 temporarily NACK. you rev

Re: [Freeipa-devel] [PATCH][WIP] DNS Location: generator for location records

2016-06-10 Thread Martin Basti
On 09.06.2016 12:21, Martin Basti wrote: Hello, here is WIP version of generator for IPA DNS records and locations, that is responsible for creating and updating all IPA records for all masters. Please note that this is not finished yet and some methods may not work. Patch attached

Re: [Freeipa-devel] [PATCH] 0203 adtrust: remove ipanttrustpartner parameter

2016-06-10 Thread Martin Basti
On 09.06.2016 21:45, Alexander Bokovoy wrote: On Thu, 09 Jun 2016, Martin Basti wrote: On 09.06.2016 17:56, Martin Babinsky wrote: On 06/06/2016 01:37 PM, Alexander Bokovoy wrote: On Mon, 06 Jun 2016, Jan Cholasta wrote: On 6.6.2016 13:22, Martin Basti wrote: On 06.06.2016 13:14

Re: [Freeipa-devel] [PATCH] 0204 adtrust: support GSSAPI authentication to LDAP as Active Directory user

2016-06-09 Thread Martin Basti
On 09.06.2016 17:49, Martin Babinsky wrote: On 06/06/2016 12:38 PM, Alexander Bokovoy wrote: Hi, In case an ID override was created for an Active Directory user in the default trust view, allow mapping the incoming GSSAPI authenticated connection to the ID override for this user. This allows

Re: [Freeipa-devel] [PATCH] 0203 adtrust: remove ipanttrustpartner parameter

2016-06-09 Thread Martin Basti
On 09.06.2016 17:56, Martin Babinsky wrote: On 06/06/2016 01:37 PM, Alexander Bokovoy wrote: On Mon, 06 Jun 2016, Jan Cholasta wrote: On 6.6.2016 13:22, Martin Basti wrote: On 06.06.2016 13:14, Alexander Bokovoy wrote: On Mon, 06 Jun 2016, Martin Basti wrote: On 06.06.2016 12:36

Re: [Freeipa-devel] [PATCH] 0201 Add support for an external trust to Active Directory domain

2016-06-09 Thread Martin Basti
On 09.06.2016 18:03, Martin Babinsky wrote: On 06/07/2016 10:25 PM, Alexander Bokovoy wrote: On Tue, 07 Jun 2016, Alexander Bokovoy wrote: > del attrs['ipanttrusttype'] > +if attributes: > +del attrs['ipanttrustattributes'] > """ Updated pat

Re: [Freeipa-devel] [PATCH] 0156 extdom: add certificate request

2016-06-09 Thread Martin Basti
On 09.06.2016 14:45, Martin Basti wrote: On 09.06.2016 14:42, Martin Basti wrote: On 09.06.2016 14:38, Lukas Slebodnik wrote: On (09/06/16 14:29), Martin Basti wrote: On 09.06.2016 14:22, Alexander Bokovoy wrote: On Thu, 09 Jun 2016, Jakub Hrozek wrote: On Fri, May 20, 2016 at 09:23

[Freeipa-devel] [PATCH 0501] Revert: switch /usr/bin/ipa to python3

2016-06-09 Thread Martin Basti
Py3 support was enabled prematurely, attached patches removes python3 from /usr/bin/ipa Notes: * ipa 4.3.x won't have enabled py3 * master (ipa 4.4+) will have disabled py3 temporarily From c6bdd4bf73332438bb429c32dac9598ce465f11d Mon Sep 17 00:00:00 2001 From: Martin Basti Date: T

Re: [Freeipa-devel] [PATCH 0046] Don't fail in find/show methods if userCertificate is invalid

2016-06-09 Thread Martin Basti
On 09.06.2016 16:04, Fraser Tweedale wrote: On Thu, Jun 09, 2016 at 03:07:34PM +0200, Martin Basti wrote: On 09.06.2016 15:03, Martin Basti wrote: On 09.06.2016 15:02, Stanislav Laznicka wrote: On 06/09/2016 02:51 PM, Rob Crittenden wrote: Stanislav Laznicka wrote: Hello, Please see

Re: [Freeipa-devel] [PATCH 0500] regression: function resolve_rrsets: RRSet object is not hashable

2016-06-09 Thread Martin Basti
On 09.06.2016 15:40, Petr Spacek wrote: On 9.6.2016 14:25, Martin Basti wrote: This regression was introduce by https://fedorahosted.org/freeipa/ticket/5710 thus this should go to 4.3.2 as well Patch attached. ACK This was actually reproducible only with python3 (because some

Re: [Freeipa-devel] [PATCH 0046] Don't fail in find/show methods if userCertificate is invalid

2016-06-09 Thread Martin Basti
On 09.06.2016 15:03, Martin Basti wrote: On 09.06.2016 15:02, Stanislav Laznicka wrote: On 06/09/2016 02:51 PM, Rob Crittenden wrote: Stanislav Laznicka wrote: Hello, Please see the attached patch of https://fedorahosted.org/freeipa/ticket/5797. Standa Just wondering out loud but

Re: [Freeipa-devel] [PATCH 0046] Don't fail in find/show methods if userCertificate is invalid

2016-06-09 Thread Martin Basti
On 09.06.2016 15:02, Stanislav Laznicka wrote: On 06/09/2016 02:51 PM, Rob Crittenden wrote: Stanislav Laznicka wrote: Hello, Please see the attached patch of https://fedorahosted.org/freeipa/ticket/5797. Standa Just wondering out loud but should usercertificate be excluded from the o

Re: [Freeipa-devel] [PATCH] 0156 extdom: add certificate request

2016-06-09 Thread Martin Basti
On 09.06.2016 14:42, Martin Basti wrote: On 09.06.2016 14:38, Lukas Slebodnik wrote: On (09/06/16 14:29), Martin Basti wrote: On 09.06.2016 14:22, Alexander Bokovoy wrote: On Thu, 09 Jun 2016, Jakub Hrozek wrote: On Fri, May 20, 2016 at 09:23:46PM +0200, Sumit Bose wrote: Hi, this

Re: [Freeipa-devel] [PATCH] 0156 extdom: add certificate request

2016-06-09 Thread Martin Basti
On 09.06.2016 14:38, Lukas Slebodnik wrote: On (09/06/16 14:29), Martin Basti wrote: On 09.06.2016 14:22, Alexander Bokovoy wrote: On Thu, 09 Jun 2016, Jakub Hrozek wrote: On Fri, May 20, 2016 at 09:23:46PM +0200, Sumit Bose wrote: Hi, this patch allows the extom plugin to lookup users by

Re: [Freeipa-devel] [PATCH] 0006 add context to exception on LdapEntry decode error

2016-06-09 Thread Martin Basti
On 09.06.2016 14:31, Stanislav Laznicka wrote: On 06/09/2016 11:58 AM, Florence Blanc-Renaud wrote: On 06/08/2016 01:14 PM, Stanislav Laznicka wrote: On 06/08/2016 01:13 PM, Stanislav Laznicka wrote: On 06/07/2016 05:11 PM, Florence Blanc-Renaud wrote: On 06/07/2016 04:08 PM, Stanislav L

Re: [Freeipa-devel] [PATCH] 0156 extdom: add certificate request

2016-06-09 Thread Martin Basti
On 09.06.2016 14:22, Alexander Bokovoy wrote: On Thu, 09 Jun 2016, Jakub Hrozek wrote: On Fri, May 20, 2016 at 09:23:46PM +0200, Sumit Bose wrote: Hi, this patch allows the extom plugin to lookup users by certificate which is needed in the case where a IPA client wants to lookup an AD user w

[Freeipa-devel] [PATCH 0500] regression: function resolve_rrsets: RRSet object is not hashable

2016-06-09 Thread Martin Basti
This regression was introduce by https://fedorahosted.org/freeipa/ticket/5710 thus this should go to 4.3.2 as well Patch attached. From b47bd75ae4126a15a569fc45d2b3a2947ac25fa8 Mon Sep 17 00:00:00 2001 From: Martin Basti Date: Thu, 9 Jun 2016 14:09:45 +0200 Subject: [PATCH] Fix

Re: [Freeipa-devel] [PATCH] man: Decribe ipa-client-install workaround for broken D-Bus enviroment.

2016-06-09 Thread Martin Basti
On 09.06.2016 10:03, Florence Blanc-Renaud wrote: On 06/09/2016 07:00 AM, David Kupka wrote: On 02/03/16 11:18, David Kupka wrote: https://fedorahosted.org/freeipa/ticket/5694 Sending updated version crafted with Flo's help, thanks. ACK. Thanks for your patience explaining the details,

Re: [Freeipa-devel] [PATCH 0492] Translations: update ipa-4-3 translations

2016-06-09 Thread Martin Basti
On 07.06.2016 12:51, Martin Babinsky wrote: On 06/01/2016 05:10 PM, Martin Basti wrote: Patch attached. ACK Pushed to ipa-4-3: 22fcf65cd1b674b21496b677818a8c75adcd70a6 -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel

[Freeipa-devel] [PATCH][WIP] DNS Location: generator for location records

2016-06-09 Thread Martin Basti
Mon Sep 17 00:00:00 2001 From: Martin Basti Date: Wed, 8 Jun 2016 17:53:58 +0200 Subject: [PATCH] DNS Location: generator for records WIP --- ipalib/dns.py | 296 ++ 1 file changed, 296 insertions(+) diff --git a/ipalib/dns.py b/ipalib/dns.py

Re: [Freeipa-devel] [PATCH] 0005 Always qualify requests for admin in ipa-replica-conncheck

2016-06-07 Thread Martin Basti
On 07.06.2016 17:25, Florence Blanc-Renaud wrote: On 06/06/2016 07:18 PM, Martin Basti wrote: On 02.06.2016 14:58, Florence Blanc-Renaud wrote: Hi, this patch modifies ipa-replica-conncheck when it performs the SSH connection to the master, so that the username is always fully

Re: [Freeipa-devel] [PATCH 0499] Pylint: exclude some files/dirs from check

2016-06-07 Thread Martin Basti
On 07.06.2016 12:58, Pavel Vomacka wrote: On 06/06/2016 04:26 PM, Martin Basti wrote: See commit message, yacctab.py causes lint errors and must be excluded Patch attached. Works well, ACK. -- Pavel^3 Vomacka Pushed to master: 1d9425dab7b16a0c518dadc5ba42c027045c4529 -- Manage

Re: [Freeipa-devel] [PATCH 0042] Removed dead code from LDAPRemoveReverseMember

2016-06-07 Thread Martin Basti
On 07.06.2016 10:43, Jan Cholasta wrote: On 7.6.2016 10:22, Martin Basti wrote: On 07.06.2016 09:07, Jan Cholasta wrote: On 6.6.2016 18:29, Martin Basti wrote: On 03.06.2016 14:28, Stanislav Laznicka wrote: On 06/03/2016 02:19 PM, Martin Basti wrote: On 03.06.2016 14:13, Stanislav

Re: [Freeipa-devel] [PATCH 0497] Py3: fix unicode/str error in LDAP*ReverseMember

2016-06-07 Thread Martin Basti
On 07.06.2016 10:35, Jan Cholasta wrote: On 7.6.2016 10:29, Martin Basti wrote: On 07.06.2016 09:08, Jan Cholasta wrote: On 6.6.2016 14:33, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/5923 Patch attached. Could we drop the error message parsing and do something sane

Re: [Freeipa-devel] [PATCH 0497] Py3: fix unicode/str error in LDAP*ReverseMember

2016-06-07 Thread Martin Basti
On 07.06.2016 09:08, Jan Cholasta wrote: On 6.6.2016 14:33, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/5923 Patch attached. Could we drop the error message parsing and do something sane instead? Not now, we can do it later and push this patch just as workaround

Re: [Freeipa-devel] [PATCH 0042] Removed dead code from LDAPRemoveReverseMember

2016-06-07 Thread Martin Basti
On 07.06.2016 09:07, Jan Cholasta wrote: On 6.6.2016 18:29, Martin Basti wrote: On 03.06.2016 14:28, Stanislav Laznicka wrote: On 06/03/2016 02:19 PM, Martin Basti wrote: On 03.06.2016 14:13, Stanislav Laznicka wrote: https://fedorahosted.org/freeipa/ticket/5892 NACK please remove

Re: [Freeipa-devel] [PATCH 0102] test: test_cli: Do not expect defaults in kwargs.

2016-06-06 Thread Martin Basti
On 03.06.2016 12:35, David Kupka wrote: https://fedorahosted.org/freeipa/ticket/4739 With this patch all but one test in test_cli.py will pass again. The one failing is bug in the dns* commands prompt behavior and will be fixed soon. Shame! That is not a way how we name patches :) ACK P

Re: [Freeipa-devel] [PATCH] 0002 Add the culprit line when a configuration file has an incorrect format

2016-06-06 Thread Martin Basti
On 03.06.2016 09:45, Florence Blanc-Renaud wrote: On 06/02/2016 07:18 PM, Martin Basti wrote: On 30.05.2016 18:11, Florence Blanc-Renaud wrote: Hi Martin, thanks for the review and the suggestion. Please find the updated patch attached. Flo. On 05/30/2016 11:00 AM, Martin Basti

Re: [Freeipa-devel] [PATCH] 0039-40: DNS Location: WebUI

2016-06-06 Thread Martin Basti
On 05.06.2016 18:34, Pavel Vomacka wrote: Hello, please review attached patches which add WebUI part of DNS Locations feature. -- Pavel^3 Vomacka NACK 1) When I edit location description and click on revert button, then that nice location table just disappear :) 2) Can we put a plac

Re: [Freeipa-devel] [PATCH 0041] Increase nsslapd-db-locks

2016-06-06 Thread Martin Basti
On 03.06.2016 13:38, Stanislav Laznicka wrote: Hello, The attached patch implements solution to https://fedorahosted.org/freeipa/ticket/5914. The patch is rather hacky as nsslapd-db-locks requires to be modified when DS is not running although I accept proposals for better solution. Stand

Re: [Freeipa-devel] [PATCH] 0005 Always qualify requests for admin in ipa-replica-conncheck

2016-06-06 Thread Martin Basti
On 02.06.2016 14:58, Florence Blanc-Renaud wrote: Hi, this patch modifies ipa-replica-conncheck when it performs the SSH connection to the master, so that the username is always fully qualified. https://fedorahosted.org/freeipa/ticket/5812 -- Florence Blanc-Renaud Identity Management Team,

Re: [Freeipa-devel] [PATCH 0042] Removed dead code from LDAPRemoveReverseMember

2016-06-06 Thread Martin Basti
On 03.06.2016 14:28, Stanislav Laznicka wrote: On 06/03/2016 02:19 PM, Martin Basti wrote: On 03.06.2016 14:13, Stanislav Laznicka wrote: https://fedorahosted.org/freeipa/ticket/5892 NACK please remove it from LDAPAddReverseMember too, it contains the same code Martin^2 Please see

Re: [Freeipa-devel] [PATCH 0036] Increased mod_wsgi socket-timeout

2016-06-06 Thread Martin Basti
On 02.06.2016 19:34, Martin Basti wrote: On 01.06.2016 06:04, Martin Basti wrote: On 31.05.2016 09:41, Stanislav Laznicka wrote: On 05/30/2016 02:12 PM, Petr Spacek wrote: On 28.5.2016 15:59, Martin Basti wrote: On 27.05.2016 14:52, Stanislav Laznicka wrote: https://fedorahosted.org

[Freeipa-devel] [PATCH 0499] Pylint: exclude some files/dirs from check

2016-06-06 Thread Martin Basti
See commit message, yacctab.py causes lint errors and must be excluded Patch attached. From b8059400c5adf050576854a60455b94eed6e9cfb Mon Sep 17 00:00:00 2001 From: Martin Basti Date: Mon, 6 Jun 2016 16:20:07 +0200 Subject: [PATCH] Exclude unneeded dirs and files from pylint check Generated

[Freeipa-devel] [PATCH 0497] Py3: fix unicode/str error in LDAP*ReverseMember

2016-06-06 Thread Martin Basti
https://fedorahosted.org/freeipa/ticket/5923 Patch attached. From 4e4480deef0b336ef89915b3e5dd91a12767051a Mon Sep 17 00:00:00 2001 From: Martin Basti Date: Mon, 6 Jun 2016 12:12:45 +0200 Subject: [PATCH] Py3: Fix unicode/str error in LDAP*ReverseMember There was incorrectly used str

Re: [Freeipa-devel] [PATCH 0123-132] DNS upgrade: change forwarding policy to "only" if private IPs are used

2016-06-06 Thread Martin Basti
On 06.06.2016 14:28, Petr Spacek wrote: On 6.6.2016 11:55, Martin Basti wrote: On 30.05.2016 12:49, Petr Spacek wrote: On 29.5.2016 14:45, Martin Basti wrote: On 27.05.2016 14:12, Petr Spacek wrote: On 25.5.2016 12:50, Martin Basti wrote: On 20.05.2016 12:19, Petr Spacek wrote: On

Re: [Freeipa-devel] [PATCH] 0203 adtrust: remove ipanttrustpartner parameter

2016-06-06 Thread Martin Basti
On 06.06.2016 13:14, Alexander Bokovoy wrote: On Mon, 06 Jun 2016, Martin Basti wrote: On 06.06.2016 12:36, Alexander Bokovoy wrote: Hi, MS-ADTS spec requires that TrustPartner field should be equal to the commonName (cn) of the trust. We used it a bit wrongly to express trust

Re: [Freeipa-devel] [PATCH] 0203 adtrust: remove ipanttrustpartner parameter

2016-06-06 Thread Martin Basti
On 06.06.2016 12:36, Alexander Bokovoy wrote: Hi, MS-ADTS spec requires that TrustPartner field should be equal to the commonName (cn) of the trust. We used it a bit wrongly to express trust relationship between parent and child domains. In fact, we have parent-child relationship recorded in t

Re: [Freeipa-devel] [PATCH] 0002 New User Role Tests

2016-06-06 Thread Martin Basti
On 02.06.2016 16:16, Peter Lacko wrote: Rebased with updated tests. Peter - Original Message - From: "Martin Basti" To: "Peter Lacko" Cc: freeipa-devel@redhat.com Sent: Thursday, June 2, 2016 1:50:06 PM Subject: Re: [Freeipa-devel] [PATCH] 0002 New User Ro

Re: [Freeipa-devel] [PATCH 0123-132] DNS upgrade: change forwarding policy to "only" if private IPs are used

2016-06-06 Thread Martin Basti
On 30.05.2016 12:49, Petr Spacek wrote: On 29.5.2016 14:45, Martin Basti wrote: On 27.05.2016 14:12, Petr Spacek wrote: On 25.5.2016 12:50, Martin Basti wrote: On 20.05.2016 12:19, Petr Spacek wrote: On 11.5.2016 12:08, Martin Basti wrote: On 03.05.2016 14:59, Petr Spacek wrote: Hello

Re: [Freeipa-devel] [Testplan Review] Manage replication topology

2016-06-06 Thread Martin Basti
On 06.06.2016 10:00, Oleg Fayans wrote: Hi Petr, I've updated the testplan according to your notes. What should we do with this testcase about abort-clean-ruv? I mean, it would be quite complicated to reliably automate. Should we leave the testcase anyway with a note that the stem may fail if

Re: [Freeipa-devel] [PATCH] script for provisioning

2016-06-05 Thread Martin Basti
On 03.06.2016 17:49, thierry bordaz wrote: Hello, A performance bottleneck during provisioning was described http://www.freeipa.org/page/V4/Performance_Improvements#typical_provisioning:_ldapadd_entries.2C_migrate-ds... I wrote the attached script that is following http://www.freeipa.org/p

Re: [Freeipa-devel] [PATCH 0037] Added /etc/krb5.conf.d/ to krb5.conf

2016-06-05 Thread Martin Basti
On 02.06.2016 19:59, Martin Basti wrote: On 31.05.2016 19:19, Robbie Harwood wrote: Alexander Bokovoy writes: On Sat, 28 May 2016, Robbie Harwood wrote: Alexander Bokovoy writes: On Fri, 27 May 2016, Robbie Harwood wrote: Stanislav Laznicka writes: From: Stanislav Laznicka The

Re: [Freeipa-devel] [PATCH] 0036-38 webui: Server roles

2016-06-03 Thread Martin Basti
On 03.06.2016 15:10, Petr Vobornik wrote: On 06/02/2016 01:40 PM, Pavel Vomacka wrote: Hello, please review my patches which add webui for server roles. Did not test yet. I'm waiting for rebase of backend. Patch 36: ACK (assuming it works when ^^ is available) Patch 37: 1. typo: 'overrid

Re: [Freeipa-devel] [PATCH] Fix minor typo

2016-06-03 Thread Martin Basti
On 03.06.2016 15:20, Yuri Chornoivan wrote: Hi, There is a minor typo in one of the FreeIPA user visible messages: "you OTP device" -> "your OTP device". Thanks for fixing it. Best regards, Yuri Thank you! ACK Pushed to master: fd4386d5c98e4b823a9f05e18c8b0db857bf1284 -- Manage your

Re: [Freeipa-devel] [PATCH 0032] Remove dangling RUVs even if replicas are offline

2016-06-03 Thread Martin Basti
On 19.05.2016 09:30, Stanislav Laznicka wrote: On 05/19/2016 08:52 AM, Ludwig Krispenz wrote: On 05/19/2016 08:02 AM, Stanislav Laznicka wrote: On 05/18/2016 04:44 PM, Petr Vobornik wrote: On 05/18/2016 04:36 PM, Stanislav Laznicka wrote: There's no ticket for this patch but as there was a

Re: [Freeipa-devel] [PATCH 0031] Fix replica deletion when there's no RUVs on the server

2016-06-03 Thread Martin Basti
On 13.05.2016 15:48, Stanislav Laznicka wrote: Fix. On 05/13/2016 03:43 PM, Stanislav Laznicka wrote: Got distracted with the code, beautifying replacement of previous patch attached. On 05/13/2016 03:30 PM, Stanislav Laznicka wrote: https://fedorahosted.org/freeipa/ticket/5307 Please see

Re: [Freeipa-devel] [PATCH 0042] Removed dead code from LDAPRemoveReverseMember

2016-06-03 Thread Martin Basti
On 03.06.2016 14:13, Stanislav Laznicka wrote: https://fedorahosted.org/freeipa/ticket/5892 NACK please remove it from LDAPAddReverseMember too, it contains the same code Martin^2 -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/free

Re: [Freeipa-devel] [PATCH 0040] Always add hostname=IPAREALM to krb5.conf

2016-06-03 Thread Martin Basti
On 03.06.2016 10:15, Alexander Bokovoy wrote: On Thu, 02 Jun 2016, Martin Basti wrote: On 02.06.2016 16:02, Stanislav Laznicka wrote: Hello, In this patch I am adding the mapping = to krb5.conf as requested in https://fedorahosted.org/freeipa/ticket/5903. ACK I have just one

Re: [Freeipa-devel] [PATCH 0473-0476, 0478-0482]DNS Locations: Prologue

2016-06-03 Thread Martin Basti
On 03.06.2016 08:53, Petr Spacek wrote: On 2.6.2016 17:53, Martin Basti wrote: Typo - redundant ' ' at the end. Conditional NACK, warnings mentioned in http://www.freeipa.org/page/V4/DNS_Location_Mechanism#CLI are not there. I'm open to changing this to ACK if you open a

Re: [Freeipa-devel] [PATCH 0038] Reduced time for IO blocking of DS

2016-06-02 Thread Martin Basti
On 02.06.2016 10:09, thierry bordaz wrote: On 06/02/2016 09:48 AM, Martin Basti wrote: On 31.05.2016 17:10, Stanislav Laznicka wrote: Hello, This is a fix to https://fedorahosted.org/freeipa/ticket/5383. From the comments I am not sure if nsslapd-idletimeout should be reduced as well

Re: [Freeipa-devel] [PATCH 0040] Always add hostname=IPAREALM to krb5.conf

2016-06-02 Thread Martin Basti
On 02.06.2016 16:02, Stanislav Laznicka wrote: Hello, In this patch I am adding the mapping = to krb5.conf as requested in https://fedorahosted.org/freeipa/ticket/5903. ACK I have just one question, where is install/share/krb5.conf.template file used in code? Anyway, for the god of c

Re: [Freeipa-devel] [PATCH 0037] Added /etc/krb5.conf.d/ to krb5.conf

2016-06-02 Thread Martin Basti
On 31.05.2016 19:19, Robbie Harwood wrote: Alexander Bokovoy writes: On Sat, 28 May 2016, Robbie Harwood wrote: Alexander Bokovoy writes: On Fri, 27 May 2016, Robbie Harwood wrote: Stanislav Laznicka writes: From: Stanislav Laznicka The include of /etc/krb5.conf.d/ is required for cr

Re: [Freeipa-devel] [PATCH 0036] Increased mod_wsgi socket-timeout

2016-06-02 Thread Martin Basti
On 01.06.2016 06:04, Martin Basti wrote: On 31.05.2016 09:41, Stanislav Laznicka wrote: On 05/30/2016 02:12 PM, Petr Spacek wrote: On 28.5.2016 15:59, Martin Basti wrote: On 27.05.2016 14:52, Stanislav Laznicka wrote: https://fedorahosted.org/freeipa/ticket/5833 Is possible to

Re: [Freeipa-devel] [PATCH 0033] Fix CA being presented as running even if it weren't

2016-06-02 Thread Martin Basti
On 31.05.2016 16:32, Stanislav Laznicka wrote: On 05/31/2016 11:40 AM, Stanislav Laznicka wrote: On 05/31/2016 10:22 AM, Stanislav Laznicka wrote: On 05/30/2016 12:54 PM, Jan Cholasta wrote: On 30.5.2016 12:36, Martin Basti wrote: On 26.05.2016 19:31, Stanislav Laznicka wrote: Self

Re: [Freeipa-devel] [PATCH] 0002 Add the culprit line when a configuration file has an incorrect format

2016-06-02 Thread Martin Basti
On 30.05.2016 18:11, Florence Blanc-Renaud wrote: Hi Martin, thanks for the review and the suggestion. Please find the updated patch attached. Flo. On 05/30/2016 11:00 AM, Martin Basti wrote: On 27.05.2016 11:35, Florence Blanc-Renaud wrote: Hi all, this patch adds information to

Re: [Freeipa-devel] [PATCH 0039] Deprecate --domain-level option from ipa-server-install

2016-06-02 Thread Martin Basti
On 02.06.2016 14:15, Stanislav Laznicka wrote: I had a different solution prepared but it seems that the deprecated flag in KnobBase does the trick. Although if the only thing it does is to remove the option from help, it may need to be renamed (help_hidden, maybe?). https://fedorahosted.or

Re: [Freeipa-devel] [PATCH 0473-0476, 0478-0482]DNS Locations: Prologue

2016-06-02 Thread Martin Basti
Typo - redundant ' ' at the end. Conditional NACK, warnings mentioned in http://www.freeipa.org/page/V4/DNS_Location_Mechanism#CLI are not there. I'm open to changing this to ACK if you open a separate ticket for this omission so we do not forget to add them later on. I forgot to add, this

Re: [Freeipa-devel] [PATCH 0473-0476, 0478-0482]DNS Locations: Prologue

2016-06-02 Thread Martin Basti
On 02.06.2016 15:03, Jan Cholasta wrote: On 2.6.2016 14:39, Petr Spacek wrote: On 2.6.2016 14:20, Jan Cholasta wrote: On 2.6.2016 14:06, Petr Spacek wrote: On 1.6.2016 18:00, Martin Basti wrote: updated patches attached freeipa-mbasti-0473.6-DNS-Locations-Always-create-DNS-related

Re: [Freeipa-devel] [PATCH 0473-0476, 0478-0482]DNS Locations: Prologue

2016-06-02 Thread Martin Basti
On 02.06.2016 14:53, Martin Basti wrote: On 02.06.2016 14:41, Pavel Vomacka wrote: On 06/02/2016 02:20 PM, Jan Cholasta wrote: On 2.6.2016 14:06, Petr Spacek wrote: On 1.6.2016 18:00, Martin Basti wrote: updated patches attached freeipa-mbasti-0473.6-DNS-Locations-Always-create-DNS

Re: [Freeipa-devel] [PATCH 0473-0476, 0478-0482]DNS Locations: Prologue

2016-06-02 Thread Martin Basti
On 02.06.2016 14:41, Pavel Vomacka wrote: On 06/02/2016 02:20 PM, Jan Cholasta wrote: On 2.6.2016 14:06, Petr Spacek wrote: On 1.6.2016 18:00, Martin Basti wrote: updated patches attached freeipa-mbasti-0473.6-DNS-Locations-Always-create-DNS-related-privileges.patch From

Re: [Freeipa-devel] [PATCH] 0002 New User Role Tests

2016-06-02 Thread Martin Basti
On 02.06.2016 11:49, Peter Lacko wrote: Sorry for late response, I wasn't working these days. Fixed patch is in attachment. Peter - Original Message ----- From: "Martin Basti" To: "Peter Lacko" , freeipa-devel@redhat.com Sent: Monday, May 9, 2016 1:06:08 PM Subje

Re: [Freeipa-devel] [PATCH 0488-0489] Perfomance: membership processing related patches

2016-06-02 Thread Martin Basti
On 02.06.2016 09:41, Martin Basti wrote: On 31.05.2016 14:10, Martin Basti wrote: On 31.05.2016 14:08, Martin Babinsky wrote: On 05/31/2016 01:57 PM, Martin Basti wrote: On 31.05.2016 12:44, Martin Babinsky wrote: On 05/28/2016 01:17 PM, Martin Basti wrote: https://fedorahosted.org

Re: [Freeipa-devel] [PATCH] 0001 (update 2) provide more information for "ipa cert-revoke -h"

2016-06-02 Thread Martin Basti
On 06.05.2016 14:45, Martin Basti wrote: On 04.05.2016 14:30, Gabe Alford wrote: On Wed, May 4, 2016 at 1:35 AM, Patrice Duc-Jacquet wrote: Hi everyone this is a second update that take into account review feedback. In case the proposal fix is K what are the next step to

<    1   2   3   4   5   6   7   8   9   10   >