Re: [Freeipa-devel] [PATCH] 0180-0190 oneway trust and other trust-related patches

2015-07-07 Thread Tomas Babej
array. Works fine for me, thanks. ACK. Pushed to master: 5017726ebaf6eea3dedb1325efe00c0d6c4b6187 During review, I also pushed the attached oneliner. Tomas From d011ca36f1db5d0cb76ab53ef07a33bec54d9003 Mon Sep 17 00:00:00 2001 From: Tomas Babej tba...@redhat.com Date: Wed, 8 Jul 2015 01

Re: [Freeipa-devel] [PATCH] 0024..0025 Add missing certprofile features

2015-07-07 Thread Tomas Babej
On 07/07/2015 07:30 PM, Martin Basti wrote: On 04/07/15 16:58, Fraser Tweedale wrote: On Fri, Jul 03, 2015 at 10:34:07PM +1000, Fraser Tweedale wrote: On Thu, Jul 02, 2015 at 08:12:12PM +1000, Fraser Tweedale wrote: On Thu, Jul 02, 2015 at 11:23:49AM +0200, Jan Cholasta wrote: Hi, Dne

Re: [Freeipa-devel] [PATCH 0055] ipa-replica-prepare: Do not create DNS zone it automatically.

2015-07-07 Thread Tomas Babej
On 07/07/2015 07:16 PM, Martin Basti wrote: On 03/07/15 06:17, David Kupka wrote: Since ipa-replica-* tools will be soon removed I think this simple check should be enough. ACK -- Martin Basti Pushed to master: 6a91893ff50fee6d7c71d9bc982d85a3ec8b7583 -- Manage your

Re: [Freeipa-devel] [PATCHES 330-331] Update translations and introduce Zanata configuration

2015-07-07 Thread Tomas Babej
On 07/07/2015 11:48 AM, Martin Basti wrote: On 07/07/15 10:37, Tomas Babej wrote: On 07/07/2015 09:09 AM, Tomas Babej wrote: On 06/24/2015 04:33 PM, Tomas Babej wrote: On 06/24/2015 04:29 PM, Martin Basti wrote: On 24/06/15 14:39, Tomas Babej wrote: +msgid Automount location name

Re: [Freeipa-devel] [PATCH 0051] Clear SSSD caches when uninstalling the client

2015-07-07 Thread Tomas Babej
On 06/30/2015 05:40 PM, Simo Sorce wrote: On Tue, 2015-06-30 at 16:10 +0200, Martin Basti wrote: On 30/06/15 15:18, Martin Basti wrote: On 30/06/15 14:47, Simo Sorce wrote: On Tue, 2015-06-30 at 13:19 +0200, Tomas Babej wrote: On 06/30/2015 01:08 PM, Martin Basti wrote: On 30/06/15 13:00

Re: [Freeipa-devel] [PATCH] 004 Improve error handling in ipa-httpd-kdcproxy

2015-07-07 Thread Tomas Babej
On 07/07/2015 04:28 PM, Alexander Bokovoy wrote: On Tue, 07 Jul 2015, Nathaniel McCallum wrote: This LGTM. However, I’ll let Alexander give the ACK. Looks good for me too. Pushed to master: 25d1afdc54284c6bcf1caf08beae2e66ceb7f4e8 -- Manage your subscription for the Freeipa-devel

Re: [Freeipa-devel] [PATCH] 886-890 webui: API browser

2015-07-03 Thread Tomas Babej
On 07/02/2015 04:55 PM, Martin Kosek wrote: On 07/01/2015 04:51 PM, Petr Vobornik wrote: For those of you who don't want to try the patches: * https://pvoborni.fedorapeople.org/images/api-user-show.png * https://pvoborni.fedorapeople.org/images/api-user-add.png On 07/01/2015 09:35 AM,

Re: [Freeipa-devel] [PATCH] 886-890 webui: API browser

2015-07-03 Thread Tomas Babej
On 07/03/2015 10:06 AM, Tomas Babej wrote: On 07/02/2015 04:55 PM, Martin Kosek wrote: On 07/01/2015 04:51 PM, Petr Vobornik wrote: For those of you who don't want to try the patches: * https://pvoborni.fedorapeople.org/images/api-user-show.png * https://pvoborni.fedorapeople.org/images

Re: [Freeipa-devel] [PATCH] 885 topology: make cn of new segment consistent with topology plugin

2015-07-03 Thread Tomas Babej
On 07/02/2015 07:42 PM, David Kupka wrote: On 30/06/15 16:16, Petr Vobornik wrote: SSIA Works for me, ACK. Pushed to master: 66ea322e7e01266cc916156860b684adb21c618d -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel

Re: [Freeipa-devel] [PATCH] 882 ipa-replica-manage del: relax segment deletement check if, topology is disconnected

2015-07-03 Thread Tomas Babej
On 07/02/2015 07:42 PM, David Kupka wrote: On 30/06/15 16:15, Petr Vobornik wrote: Comment from segment deletion check which describes the patch: Relax check if topology was or is disconnected. Disconnected topology can contain segments with already deleted servers. Check only if segments of

Re: [Freeipa-devel] [PATCH] 884 topologysegment: hide direction and enable options

2015-07-03 Thread Tomas Babej
On 07/02/2015 07:42 PM, David Kupka wrote: On 30/06/15 16:15, Petr Vobornik wrote: These options should not be touched by users yet. https://fedorahosted.org/freeipa/ticket/5061 Works for me, ACK. Pushed to master: 2b8e1caa7bfda5e540a94fe26fbcdbfd0ea68928 -- Manage your subscription

Re: [Freeipa-devel] [PATCH 0274] DNS: Check if dns package is installed

2015-07-03 Thread Tomas Babej
On 07/02/2015 02:03 PM, Petr Spacek wrote: On 2.7.2015 13:54, Jan Cholasta wrote: Dne 2.7.2015 v 13:34 Petr Spacek napsal(a): On 2.7.2015 12:57, Tomas Babej wrote: On 07/02/2015 08:50 AM, Petr Spacek wrote: On 1.7.2015 20:29, Tomas Babej wrote: On 07/01/2015 04:45 PM, Petr Spacek wrote

[Freeipa-devel] [PATCH 0333] ipaplatform: Remove redundant definitions

2015-07-02 Thread Tomas Babej
Hi, I noticed two variables are redundant in the base/paths.py and base/tasks.py in the ipaplatform module. git grep -E 'path_namespace|task_namespace' ipaplatform/base/paths.py:path_namespace = BasePathNamespace ipaplatform/base/tasks.py:task_namespace = BaseTaskNamespace() This

Re: [Freeipa-devel] [PATCH 0018] allow deletion of segment, if not both nodes are managed

2015-07-02 Thread Tomas Babej
On 07/01/2015 08:59 PM, Simo Sorce wrote: On Wed, 2015-07-01 at 12:05 +0200, Ludwig Krispenz wrote: This fix allows the removal of segments, where not both endpoints of the segments are managed. These segments can exist after deliberately disconnecting a topology by removal of a central

Re: [Freeipa-devel] [PATCH 0274] DNS: Check if dns package is installed

2015-07-02 Thread Tomas Babej
On 07/02/2015 08:50 AM, Petr Spacek wrote: On 1.7.2015 20:29, Tomas Babej wrote: On 07/01/2015 04:45 PM, Petr Spacek wrote: On 1.7.2015 15:32, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/4058 Requires patch freeipa-pspacek-0052 ACK I must admit I don't really like

Re: [Freeipa-devel] [PATCH] 0016 user life cycle: Display the wrong attribute name when mandatory attribute is missing

2015-07-02 Thread Tomas Babej
On 07/02/2015 10:34 AM, thierry bordaz wrote: On 07/01/2015 05:39 PM, Tomas Babej wrote: Hi Thierry, I think it would be better to use: error=_('Entry has no \'%s\'') % attr or even better, use named substitution: error=_('Entry has no \'%(attribute)s\'') % dict(attribute=attr

Re: [Freeipa-devel] [PATCHES 306-316] Automated migration tool from Winsync

2015-07-02 Thread Tomas Babej
On 07/01/2015 07:32 PM, Martin Babinsky wrote: On 06/30/2015 05:55 PM, Tomas Babej wrote: On 06/16/2015 01:01 PM, Jan Cholasta wrote: Dne 16.6.2015 v 10:14 Martin Babinsky napsal(a): On 05/06/2015 10:12 AM, Tomas Babej wrote: On 05/05/2015 02:02 PM, Tomas Babej wrote: On 04/29/2015

Re: [Freeipa-devel] [PATCH 0275] DNS commands: do not show traceback if DNS is not installed

2015-07-01 Thread Tomas Babej
On 07/01/2015 05:53 PM, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/5017 Patch attached Repeated code hurts my eyes, but abstracting it seems like an overkill. ACK. Pushed to master: 96c23659fcb8adc64dd925556fb40f558fa7e37d -- Manage your subscription for the

Re: [Freeipa-devel] [PATCH 0274] DNS: Check if dns package is installed

2015-07-01 Thread Tomas Babej
On 07/01/2015 04:45 PM, Petr Spacek wrote: On 1.7.2015 15:32, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/4058 Requires patch freeipa-pspacek-0052 ACK I must admit I don't really like wrapping a constant in the method in the TaskNamespace object. We're interested in the

Re: [Freeipa-devel] [PATCH 0017] dirsrv crash on segment add if suffix does not exist

2015-07-01 Thread Tomas Babej
On 07/01/2015 12:11 PM, thierry bordaz wrote: On 06/30/2015 04:50 PM, Ludwig Krispenz wrote: new patch attached On 06/30/2015 03:37 PM, thierry bordaz wrote: On 06/30/2015 12:07 PM, Ludwig Krispenz wrote: added verification for issue reported in ticket 5088 and sanity checks requested in

Re: [Freeipa-devel] [PATCH 0046] DNSSEC: Store time date key metadata in UTC

2015-07-01 Thread Tomas Babej
On 07/01/2015 10:37 AM, Martin Basti wrote: On 30/06/15 14:36, Petr Spacek wrote: Hello, DNSSEC: Store time date key metadata in UTC. OpenDNSSEC stores key metadata in local time zone but BIND needs timestamps in UTC. UTC will be stored in LDAP.

Re: [Freeipa-devel] [PATCHES 326-328] ID Views improvements

2015-07-01 Thread Tomas Babej
On 05/28/2015 12:59 PM, Tomas Babej wrote: Hi, this couple of patches improves ID Views and ID overrides handling. See commit messages for details. Tomas Bump. Can this sad, forgotten patch set get a review? -- Manage your subscription for the Freeipa-devel mailing list: https

Re: [Freeipa-devel] [PATCHES 326-328] ID Views improvements

2015-07-01 Thread Tomas Babej
On 07/01/2015 12:50 PM, Alexander Bokovoy wrote: On Thu, 28 May 2015, Tomas Babej wrote: From c4ad3ba829ab2816c6ddb64da8d5c6ceb8789340 Mon Sep 17 00:00:00 2001 From: Tomas Babej tba...@redhat.com Date: Wed, 27 May 2015 16:30:48 +0200 Subject: [PATCH] idviews: Remove ID overrides

Re: [Freeipa-devel] [PATCH] 0016 user life cycle: Display the wrong attribute name when mandatory attribute is missing

2015-07-01 Thread Tomas Babej
Hi Thierry, I think it would be better to use: error=_('Entry has no \'%s\'') % attr or even better, use named substitution: error=_('Entry has no \'%(attribute)s\'') % dict(attribute=attr) This way will generate a more readable strings for translators. Tomas -- Manage your subscription

Re: [Freeipa-devel] [PATCH] 891 replication: fix regression in get_agreement_type

2015-07-01 Thread Tomas Babej
On 07/01/2015 06:32 PM, Petr Vobornik wrote: dcb6916a3b0601e33b08e12aeb25357efed6812b introduced a regression where get_agreement_type does not raise NotFound error if an agreement for host does not exist. The exception was swallowed by get_replication_agreement. ACK. Pushed to master:

Re: [Freeipa-devel] [PATCH 0270] Sanitize CA replica install

2015-06-30 Thread Tomas Babej
On 06/30/2015 01:40 PM, Tomas Babej wrote: On 06/30/2015 01:25 PM, Martin Basti wrote: Check if cafile exists first, before using it. Patch attached. ACK Pushed to master: b2f0a018b6f2226106ec811cf01f9bcebb770126 -- Manage your subscription for the Freeipa-devel mailing list

Re: [Freeipa-devel] [PATCHES 306-316] Automated migration tool from Winsync

2015-06-30 Thread Tomas Babej
On 06/16/2015 01:01 PM, Jan Cholasta wrote: Dne 16.6.2015 v 10:14 Martin Babinsky napsal(a): On 05/06/2015 10:12 AM, Tomas Babej wrote: On 05/05/2015 02:02 PM, Tomas Babej wrote: On 04/29/2015 12:28 PM, Tomas Babej wrote: On 03/11/2015 04:20 PM, Jan Cholasta wrote: Hi, Dne

Re: [Freeipa-devel] [PATCH 0016] clear start attr from segment after initialization

2015-06-30 Thread Tomas Babej
On 06/30/2015 12:45 PM, thierry bordaz wrote: On 06/30/2015 12:05 PM, Ludwig Krispenz wrote: new patch with comments attached On 06/30/2015 10:43 AM, thierry bordaz wrote: On 06/30/2015 09:19 AM, Ludwig Krispenz wrote: On 06/26/2015 02:14 PM, thierry bordaz wrote: On 06/22/2015 11:35 AM,

Re: [Freeipa-devel] [PATCH 0038] increase NSS memcache timeout for IPA server

2015-06-30 Thread Tomas Babej
On 06/30/2015 09:47 AM, Martin Basti wrote: On 27/05/15 13:40, Martin Babinsky wrote: On 05/27/2015 01:33 PM, Lukas Slebodnik wrote: On (27/05/15 13:25), Martin Babinsky wrote: https://fedorahosted.org/freeipa/ticket/4964 -- Martin^3 Babinsky From

Re: [Freeipa-devel] [PATCH 0051] Clear SSSD caches when uninstalling the client

2015-06-30 Thread Tomas Babej
On 06/29/2015 03:50 PM, Martin Basti wrote: On 29/06/15 13:46, Jakub Hrozek wrote: On Fri, Jun 05, 2015 at 11:31:54AM -0600, Gabe Alford wrote: Thanks. Updated patch attached. On Fri, Jun 5, 2015 at 9:53 AM, Jakub Hrozek jhro...@redhat.com wrote: On Fri, Jun 05, 2015 at 09:46:05AM -0600,

Re: [Freeipa-devel] [PATCH 0051] Clear SSSD caches when uninstalling the client

2015-06-30 Thread Tomas Babej
On 06/30/2015 01:08 PM, Martin Basti wrote: On 30/06/15 13:00, Tomas Babej wrote: On 06/29/2015 03:50 PM, Martin Basti wrote: On 29/06/15 13:46, Jakub Hrozek wrote: On Fri, Jun 05, 2015 at 11:31:54AM -0600, Gabe Alford wrote: Thanks. Updated patch attached. On Fri, Jun 5, 2015 at 9:53 AM

Re: [Freeipa-devel] [PATCH] 1114 don't rely on positional arguments in pykerberos calls

2015-06-30 Thread Tomas Babej
On 06/26/2015 05:56 PM, Rob Crittenden wrote: I'm working on rebasing python-kerberos (PyKerberos) in rawhide and when upstream accepted our patch which added the ability to pass in flags to authGSSClientInit() they changed the ordering such that the IPA call will fail as it relies on

Re: [Freeipa-devel] [PATCH 0270] Sanitize CA replica install

2015-06-30 Thread Tomas Babej
On 06/30/2015 01:25 PM, Martin Basti wrote: Check if cafile exists first, before using it. Patch attached. ACK -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

Re: [Freeipa-devel] [PATCH 0053] upgrade: Raise error when certmonger is not running.

2015-06-29 Thread Tomas Babej
On 06/29/2015 11:05 AM, Petr Spacek wrote: On 29.6.2015 09:22, David Kupka wrote: On 26/06/15 19:45, Rob Crittenden wrote: Petr Vobornik wrote: On 06/26/2015 10:54 AM, David Kupka wrote: https://fedorahosted.org/freeipa/ticket/5080 ACK Is there a reason we don't simply start

Re: [Freeipa-devel] [PATCH 0040-0045] DNSSEC improvements

2015-06-29 Thread Tomas Babej
On 06/29/2015 01:36 PM, Tomas Babej wrote: On 06/29/2015 01:14 PM, Martin Basti wrote: On 26/06/15 18:55, Petr Spacek wrote: Hello, attached patches implement a portion of improvements for ticket https://fedorahosted.org/freeipa/ticket/4657 It came to my mind that it will be better

Re: [Freeipa-devel] [PATCH] 865 fix handling of ldap.LDAPError in installer

2015-06-29 Thread Tomas Babej
On 06/04/2015 05:19 PM, Petr Vobornik wrote: based on: http://fpaste.org/228856/25049143/ The patch is not tested. Description: 'info' is optional component in LDAPError http://www.python-ldap.org/doc/html/ldap.html#exceptions Pushed to master:

Re: [Freeipa-devel] [PATCH 0039] Rate-limit while loop in SystemdService.is_active()

2015-06-29 Thread Tomas Babej
On 06/29/2015 01:28 PM, Martin Basti wrote: On 26/06/15 15:58, Petr Spacek wrote: Hello, Rate-limit while loop in SystemdService.is_active(). Previously is_active() was frenetically calling systemctl is_active in tight loop which in fact made the process slower. ACK Pushed to master:

Re: [Freeipa-devel] [PATCH 0040-0045] DNSSEC improvements

2015-06-29 Thread Tomas Babej
On 06/29/2015 01:14 PM, Martin Basti wrote: On 26/06/15 18:55, Petr Spacek wrote: Hello, attached patches implement a portion of improvements for ticket https://fedorahosted.org/freeipa/ticket/4657 It came to my mind that it will be better to review them at once - the previous threads

Re: [Freeipa-devel] [PATCH] 881 add python-setuptools to requires

2015-06-29 Thread Tomas Babej
On 06/26/2015 01:18 PM, Martin Basti wrote: On 19/06/15 14:06, Petr Vobornik wrote: Commit 9f049ca14403f3696d54d186e6b1b15181f055df introduced dependency on python-setuptools on line: from pkg_resources import parse_version This dependency is missing on *minimal* installation and then

Re: [Freeipa-devel] [PATCH 0038] Add hint how to re-run IPA upgrade

2015-06-29 Thread Tomas Babej
On 06/26/2015 06:05 PM, Petr Vobornik wrote: On 06/26/2015 12:41 PM, Petr Spacek wrote: Hello, Add hint how to re-run IPA upgrade. ACK Pushed to master: d5a07b50b4d8900c16dd8672e21de34647fff9ec -- Manage your subscription for the Freeipa-devel mailing list:

Re: [Freeipa-devel] [PATCH 0267] Fix broken indicies

2015-06-29 Thread Tomas Babej
On 06/29/2015 01:23 PM, Martin Babinsky wrote: On 06/26/2015 05:50 PM, Martin Basti wrote: Patch fixes wrong value for ntUserDomainId and ntUniqueId indicies. Patch attached. ACK Pushed to master: 16f47ed4520d4f89db39d1dc58be7a8efb1d8612 -- Manage your subscription for the

Re: [Freeipa-devel] [PATCH] 00015 User life cycle: permission to delete a preserved user

2015-06-29 Thread Tomas Babej
On 06/29/2015 10:44 AM, Martin Basti wrote: On 22/06/15 17:08, thierry bordaz wrote: Add the permission to Stage users administrators to delete already preserved user ACK -- Martin Basti Pushed to master: ffd6b039a755016c3de22a11fec037eca7180a79 -- Manage your

Re: [Freeipa-devel] [PATCH 0036] Bump minimal BIND version for CentOS

2015-06-29 Thread Tomas Babej
On 06/26/2015 09:43 AM, Martin Basti wrote: On 23/06/15 14:14, Petr Spacek wrote: Hello, Bump minimal BIND version for CentOS. DNSSEC support added dependency on bind-pkcs11 sub-package. https://fedorahosted.org/freeipa/ticket/4657 ACK -- Martin Basti Pushed to master:

Re: [Freeipa-devel] [PATCH] 1113 Hosts add their own services

2015-06-29 Thread Tomas Babej
On 06/29/2015 12:24 PM, Martin Basti wrote: On 22/06/15 19:48, Rob Crittenden wrote: Add an ACI to allow a host to add its own services. This only grants add access. It can't subsequently delete or modify the entry. This requires 389-ds-1.3.4.0 GA. rob ACK -- Martin Basti

Re: [Freeipa-devel] [PATCH 0014] correct handling of one directional segments

2015-06-29 Thread Tomas Babej
On 06/29/2015 01:50 PM, thierry bordaz wrote: On 06/29/2015 12:47 PM, Martin Basti wrote: On 17/06/15 11:05, Ludwig Krispenz wrote: On 06/17/2015 10:35 AM, thierry bordaz wrote: On 06/17/2015 09:25 AM, Ludwig Krispenz wrote: Hi, thanks for review, see answers inline. On 06/16/2015 05:17

[Freeipa-devel] Notice: FreeIPA localization strings updated, deadline 2015-07-01

2015-06-24 Thread Tomas Babej
Hello, FreeIPA translators! Updated translation strings are available for localization at the fedora.zanata.org Zanata server instance: https://fedora.zanata.org/iteration/view/freeipa/master Please update the translations at your leisure in the next 7 days, we plan to pull the translations for

Re: [Freeipa-devel] [PATCHES 330-331] Update translations and introduce Zanata configuration

2015-06-24 Thread Tomas Babej
On 06/24/2015 04:29 PM, Martin Basti wrote: On 24/06/15 14:39, Tomas Babej wrote: +msgid Automount location name. +msgstr Job Title + in german po file +msgid Automount location name. +msgstr Job Title + AFAIK, this is not german language. Nice catch! You can show off your

Re: [Freeipa-devel] SkipPluginModule error raised during new code installation

2015-06-04 Thread Tomas Babej
On 06/04/2015 03:55 PM, Oleg Fayans wrote: Hi everybody The following error was raised during the installation of the freeipa packages built from the current master branch: ofayans@f22master:~/freeipa/dist/rpms]$ sudo rpm -ihv *.rpm Preparing... # [100%]

[Freeipa-devel] [PATCH 0329] ipa-replica-manage: Do not allow topology altering commands

2015-06-02 Thread Tomas Babej
of: https://fedorahosted.org/freeipa/ticket/4302 From e96c3b045ced1773def444ffee9a45f813abb954 Mon Sep 17 00:00:00 2001 From: Tomas Babej tba...@redhat.com Date: Tue, 2 Jun 2015 14:06:26 +0200 Subject: [PATCH] ipa-replica-manage: Do not allow topology altering commands from DL 1 With Domain Level

Re: [Freeipa-devel] Domain level change failed

2015-06-01 Thread Tomas Babej
On 06/01/2015 04:13 PM, Oleg Fayans wrote: Hi, In my installation of the freeipa built with the latest topology patches applied, I was unable to reset domain level to 0 on neither of nodes: ofayans@testmaster:~/ldap]$ ipa domainlevel-set 0 ipa: ERROR: Domain Level cannot be lowered.

[Freeipa-devel] [PATCHES 326-328] ID Views improvements

2015-05-28 Thread Tomas Babej
Hi, this couple of patches improves ID Views and ID overrides handling. See commit messages for details. Tomas From 8acc50c10d9886668a0147b46f311f9aa83294bb Mon Sep 17 00:00:00 2001 From: Tomas Babej tba...@redhat.com Date: Wed, 27 May 2015 14:31:13 +0200 Subject: [PATCH] idviews: Set dcerpc

Re: [Freeipa-devel] [PATCH 0325] Add Domain Level feature

2015-05-26 Thread Tomas Babej
On 05/26/2015 11:57 AM, Jan Cholasta wrote: Dne 25.5.2015 v 17:15 Tomas Babej napsal(a): On 05/25/2015 12:42 PM, Tomas Babej wrote: On 05/25/2015 07:30 AM, Jan Cholasta wrote: Dne 22.5.2015 v 12:36 Petr Vobornik napsal(a): On 05/22/2015 07:08 AM, Jan Cholasta wrote: Dne 21.5.2015 v 18

Re: [Freeipa-devel] [PATCH 0325] Add Domain Level feature

2015-05-26 Thread Tomas Babej
On 05/26/2015 12:39 PM, Tomas Babej wrote: On 05/26/2015 11:57 AM, Jan Cholasta wrote: Dne 25.5.2015 v 17:15 Tomas Babej napsal(a): On 05/25/2015 12:42 PM, Tomas Babej wrote: On 05/25/2015 07:30 AM, Jan Cholasta wrote: Dne 22.5.2015 v 12:36 Petr Vobornik napsal(a): On 05/22/2015 07

Re: [Freeipa-devel] [PATCH 0325] Add Domain Level feature

2015-05-26 Thread Tomas Babej
On 05/26/2015 01:51 PM, Tomas Babej wrote: On 05/26/2015 12:39 PM, Tomas Babej wrote: On 05/26/2015 11:57 AM, Jan Cholasta wrote: Dne 25.5.2015 v 17:15 Tomas Babej napsal(a): On 05/25/2015 12:42 PM, Tomas Babej wrote: On 05/25/2015 07:30 AM, Jan Cholasta wrote: Dne 22.5.2015 v 12

Re: [Freeipa-devel] [PATCH 0325] Add Domain Level feature

2015-05-25 Thread Tomas Babej
On 05/25/2015 07:30 AM, Jan Cholasta wrote: Dne 22.5.2015 v 12:36 Petr Vobornik napsal(a): On 05/22/2015 07:08 AM, Jan Cholasta wrote: Dne 21.5.2015 v 18:18 Tomas Babej napsal(a): On 05/19/2015 04:07 PM, Tomas Babej wrote: On 05/19/2015 03:59 PM, Martin Kosek wrote: On 05/19/2015 03:56

Re: [Freeipa-devel] [PATCH] 0178 Fix AD trusts in Fedora 22

2015-05-25 Thread Tomas Babej
On 05/12/2015 04:03 PM, Alexander Bokovoy wrote: On Tue, 12 May 2015, Alexander Bokovoy wrote: On Tue, 12 May 2015, Alexander Bokovoy wrote: On Fri, 08 May 2015, Alexander Bokovoy wrote: Hi, attached patch fixes issues with Samba 4.2 in Fedora 22. See commit message for the details. Note

Re: [Freeipa-devel] [PATCH 0325] Add Domain Level feature

2015-05-25 Thread Tomas Babej
On 05/25/2015 12:42 PM, Tomas Babej wrote: On 05/25/2015 07:30 AM, Jan Cholasta wrote: Dne 22.5.2015 v 12:36 Petr Vobornik napsal(a): On 05/22/2015 07:08 AM, Jan Cholasta wrote: Dne 21.5.2015 v 18:18 Tomas Babej napsal(a): On 05/19/2015 04:07 PM, Tomas Babej wrote: On 05/19/2015 03

Re: [Freeipa-devel] [PATCH 0325] Add Domain Level feature

2015-05-22 Thread Tomas Babej
On 05/22/2015 12:36 PM, Petr Vobornik wrote: On 05/22/2015 07:08 AM, Jan Cholasta wrote: Dne 21.5.2015 v 18:18 Tomas Babej napsal(a): On 05/19/2015 04:07 PM, Tomas Babej wrote: On 05/19/2015 03:59 PM, Martin Kosek wrote: On 05/19/2015 03:56 PM, Tomas Babej wrote: On 05/19/2015 03:51

Re: [Freeipa-devel] [PATCH 0325] Add Domain Level feature

2015-05-22 Thread Tomas Babej
On 05/22/2015 03:32 PM, Petr Vobornik wrote: On 05/22/2015 03:18 PM, Petr Vobornik wrote: On 05/22/2015 01:08 PM, Tomas Babej wrote: snip 1) https://www.redhat.com/archives/freeipa-devel/2015-May/msg00228.html - I still don't agree that the plugin should be based on LDAPObject

Re: [Freeipa-devel] [PATCH 0325] Add Domain Level feature

2015-05-22 Thread Tomas Babej
On 05/22/2015 03:52 PM, Tomas Babej wrote: On 05/22/2015 03:32 PM, Petr Vobornik wrote: On 05/22/2015 03:18 PM, Petr Vobornik wrote: On 05/22/2015 01:08 PM, Tomas Babej wrote: snip 1) https://www.redhat.com/archives/freeipa-devel/2015-May/msg00228.html - I still don't agree

Re: [Freeipa-devel] [PATCH 0325] Add Domain Level feature

2015-05-21 Thread Tomas Babej
On 05/19/2015 04:07 PM, Tomas Babej wrote: On 05/19/2015 03:59 PM, Martin Kosek wrote: On 05/19/2015 03:56 PM, Tomas Babej wrote: On 05/19/2015 03:51 PM, Martin Kosek wrote: On 05/19/2015 03:49 PM, Ludwig Krispenz wrote: On 05/19/2015 03:36 PM, Martin Kosek wrote: On 05/19/2015 03:22

Re: [Freeipa-devel] [PATCH 0325] Add Domain Level feature

2015-05-19 Thread Tomas Babej
On 05/14/2015 11:48 AM, Jan Cholasta wrote: Hi, Dne 14.5.2015 v 11:00 Tomas Babej napsal(a): Hi, this patch implements the domain level feature. https://fedorahosted.org/freeipa/ticket/5018 Tomas 1) +# Create entry proclaiming Domain Level support of this master +# This will update

Re: [Freeipa-devel] [PATCH 0325] Add Domain Level feature

2015-05-19 Thread Tomas Babej
On 05/19/2015 03:51 PM, Martin Kosek wrote: On 05/19/2015 03:49 PM, Ludwig Krispenz wrote: On 05/19/2015 03:36 PM, Martin Kosek wrote: On 05/19/2015 03:22 PM, Tomas Babej wrote: ... 3) Domain level is just a single integer and it should be treated as such, there's no need for an LDAPObject

Re: [Freeipa-devel] [PATCH 0325] Add Domain Level feature

2015-05-19 Thread Tomas Babej
On 05/19/2015 03:59 PM, Martin Kosek wrote: On 05/19/2015 03:56 PM, Tomas Babej wrote: On 05/19/2015 03:51 PM, Martin Kosek wrote: On 05/19/2015 03:49 PM, Ludwig Krispenz wrote: On 05/19/2015 03:36 PM, Martin Kosek wrote: On 05/19/2015 03:22 PM, Tomas Babej wrote: ... 3) Domain level

[Freeipa-devel] [PATCH 0325] Add Domain Level feature

2015-05-14 Thread Tomas Babej
Hi, this patch implements the domain level feature. https://fedorahosted.org/freeipa/ticket/5018 Tomas From 409961b882ff7b04e4b3193627f4677b01a902f0 Mon Sep 17 00:00:00 2001 From: Tomas Babej tba...@redhat.com Date: Thu, 14 May 2015 10:49:55 +0200 Subject: [PATCH] Add Domain Level feature

Re: [Freeipa-devel] [PATCHES 306-316] Automated migration tool from Winsync

2015-05-06 Thread Tomas Babej
On 05/05/2015 02:02 PM, Tomas Babej wrote: On 04/29/2015 12:28 PM, Tomas Babej wrote: On 03/11/2015 04:20 PM, Jan Cholasta wrote: Hi, Dne 10.3.2015 v 16:35 Tomas Babej napsal(a): On 03/09/2015 12:26 PM, Tomas Babej wrote: Hi, this couple of patches provides a initial implementation

Re: [Freeipa-devel] [PATCHES 306-316] Automated migration tool from Winsync

2015-05-05 Thread Tomas Babej
On 04/29/2015 12:28 PM, Tomas Babej wrote: On 03/11/2015 04:20 PM, Jan Cholasta wrote: Hi, Dne 10.3.2015 v 16:35 Tomas Babej napsal(a): On 03/09/2015 12:26 PM, Tomas Babej wrote: Hi, this couple of patches provides a initial implementation of the winsync migration tool: https

Re: [Freeipa-devel] [PATCHES 306-316] Automated migration tool from Winsync

2015-04-29 Thread Tomas Babej
On 03/11/2015 04:20 PM, Jan Cholasta wrote: Hi, Dne 10.3.2015 v 16:35 Tomas Babej napsal(a): On 03/09/2015 12:26 PM, Tomas Babej wrote: Hi, this couple of patches provides a initial implementation of the winsync migration tool: https://fedorahosted.org/freeipa/ticket/4524 Some parts

Re: [Freeipa-devel] [PATCH 0042] Make lint work on Fedora 22.

2015-04-24 Thread Tomas Babej
On 04/24/2015 03:50 PM, Martin Basti wrote: On 24/04/15 15:22, David Kupka wrote: On 04/24/2015 03:17 PM, Martin Basti wrote: On 23/04/15 15:26, David Kupka wrote: On 04/13/2015 01:23 PM, David Kupka wrote: On 04/10/2015 02:55 PM, Simo Sorce wrote: On Fri, 2015-04-10 at 12:55 +0200, Lukas

Re: [Freeipa-devel] OOO 2015-03-31-2015-04-01

2015-03-31 Thread Tomas Babej
Sorry about the noise. On 03/31/2015 07:23 AM, Tomas Babej wrote: Hours already accumulated this month. Tomas -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute

[Freeipa-devel] OOO 2015-03-31-2015-04-01

2015-03-30 Thread Tomas Babej
Hours already accumulated this month. Tomas -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Re: [Freeipa-devel] [PATCH 0208] Remove --test option from upgrade

2015-03-23 Thread Tomas Babej
On 03/19/2015 12:25 PM, David Kupka wrote: On 03/17/2015 01:07 PM, Martin Basti wrote: On 12/03/15 16:10, David Kupka wrote: On 03/06/2015 06:00 PM, Martin Basti wrote: Upgrade plugins which modify LDAP data directly should not be executed in --test mode. This patch is a workaround, to

Re: [Freeipa-devel] [PATCHES 0204-0207, 0211] Server upgrade: Make LDAP data upgrade deterministic

2015-03-19 Thread Tomas Babej
On 03/19/2015 12:20 PM, David Kupka wrote: On 03/13/2015 03:08 PM, Martin Basti wrote: On 12/03/15 16:21, Rob Crittenden wrote: Martin Basti wrote: The patchset ensure, the upgrade order will respect ordering of entries in *.update files. Required for:

Re: [Freeipa-devel] [PATCH] 0041 Always reload StateFile before getting or modifying the, stored values.

2015-03-18 Thread Tomas Babej
On 03/17/2015 10:29 AM, Martin Basti wrote: On 16/03/15 13:54, David Kupka wrote: https://fedorahosted.org/freeipa/ticket/4901 ACK, it works as expected Pushed to master: 082c55fb9cf87263f1f585a1adeda464a9d7328a -- Manage your subscription for the Freeipa-devel mailing list:

Re: [Freeipa-devel] [PATCHES] SPEC: Require python2 version of sssd bindings

2015-03-18 Thread Tomas Babej
On 03/12/2015 01:58 PM, Alexander Bokovoy wrote: On Thu, 12 Mar 2015, Alexander Bokovoy wrote: On Thu, 12 Mar 2015, Petr Vobornik wrote: On 03/06/2015 03:13 PM, Alexander Bokovoy wrote: On Fri, 06 Mar 2015, Lukas Slebodnik wrote: On (05/03/15 16:20), Petr Vobornik wrote: On 03/05/2015

Re: [Freeipa-devel] [PATCHES 137-139] extdom: add err_msg member to request context

2015-03-18 Thread Tomas Babej
On 03/18/2015 11:23 AM, Jakub Hrozek wrote: On Wed, Mar 18, 2015 at 10:58:51AM +0100, Sumit Bose wrote: Please find attached a new version where the typo is fixed. bye, Sumit ACK I think the IPA gatekeepers shoudl feel free to just fix these trivial errors before pushing in the future.

Re: [Freeipa-devel] [PATCHES] SPEC: Require python2 version of sssd bindings

2015-03-18 Thread Tomas Babej
On 03/18/2015 01:10 PM, Alexander Bokovoy wrote: On Wed, 18 Mar 2015, Tomas Babej wrote: On 03/12/2015 01:58 PM, Alexander Bokovoy wrote: On Thu, 12 Mar 2015, Alexander Bokovoy wrote: On Thu, 12 Mar 2015, Petr Vobornik wrote: On 03/06/2015 03:13 PM, Alexander Bokovoy wrote: On Fri, 06

Re: [Freeipa-devel] [PATCHES 0018-0020] ipa-dns-install: Use LDAPI for all DS connections

2015-03-18 Thread Tomas Babej
On 03/16/2015 05:01 PM, Martin Basti wrote: On 16/03/15 14:26, Martin Babinsky wrote: On 03/16/2015 01:44 PM, Martin Basti wrote: On 12/03/15 17:15, Martin Babinsky wrote: On 03/12/2015 03:59 PM, Martin Babinsky wrote: On 03/11/2015 03:13 PM, Martin Basti wrote: On 11/03/15 13:00, Martin

Re: [Freeipa-devel] [PATCH 0209] Fix logically dead code in ipap11helper module

2015-03-11 Thread Tomas Babej
On 03/11/2015 11:28 AM, Petr Spacek wrote: On 9.3.2015 13:52, Martin Basti wrote: Patch attached. ACK for this patch. When you are at it, it would be good to fix other warnings too. GCC on Fedora 21 is yelling at me: p11helper.c: In function ‘P11_Helper_find_keys’: p11helper.c:1062:23:

Re: [Freeipa-devel] [PATCH] Use curl instead of wget

2015-03-10 Thread Tomas Babej
On 01/22/2015 04:01 PM, Alexander Bokovoy wrote: On Thu, 22 Jan 2015, Colin Walters wrote: On Thu, Jan 22, 2015, at 08:45 AM, Alexander Bokovoy wrote: We have abstraction layer to take care of different platforms on a wider scale than just this particular binary. We are gradually moving

Re: [Freeipa-devel] [PATCH] extdom: return LDAP_NO_SUCH_OBJECT to the client

2015-03-10 Thread Tomas Babej
On 03/05/2015 07:28 AM, Alexander Bokovoy wrote: On Wed, 04 Mar 2015, Sumit Bose wrote: Hi, with this patch the extdom plugin will properly indicate to a client if the search object does not exist instead of returning a generic error. This is important for the client to act accordingly and

Re: [Freeipa-devel] [PATCH 142] extdom: fix memory leak

2015-03-10 Thread Tomas Babej
On 03/10/2015 12:10 PM, Sumit Bose wrote: On Tue, Mar 10, 2015 at 11:59:45AM +0100, Tomas Babej wrote: On 03/05/2015 08:00 AM, Alexander Bokovoy wrote: On Wed, 04 Mar 2015, Nathan Kinder wrote: On 03/04/2015 10:34 PM, Alexander Bokovoy wrote: On Wed, 04 Mar 2015, Sumit Bose wrote: Hi

Re: [Freeipa-devel] [PATCHES 306-316] Automated migration tool from Winsync

2015-03-10 Thread Tomas Babej
On 03/09/2015 12:26 PM, Tomas Babej wrote: Hi, this couple of patches provides a initial implementation of the winsync migration tool: https://fedorahosted.org/freeipa/ticket/4524 Some parts could use some polishing, but this is a sound foundation. Tomas Attaching one more patch

Re: [Freeipa-devel] [PATCHES 0200-0202] DNS fixes related to unsupported records

2015-03-09 Thread Tomas Babej
On 03/06/2015 01:30 PM, Petr Spacek wrote: On 4.3.2015 16:35, Martin Basti wrote: On 04/03/15 16:17, Martin Basti wrote: Ticket: https://fedorahosted.org/freeipa/ticket/4930 0200: 4.1, master Fixes traceback, which was raised if LDAP contained a record that was marked as unsupported. Now

Re: [Freeipa-devel] [PATCH 0199] Remove unused disable-betxn.ldif file

2015-03-09 Thread Tomas Babej
On 03/09/2015 11:56 AM, David Kupka wrote: On 02/25/2015 02:45 PM, Martin Basti wrote: Hello, the file 'disable-betxn.ldif' is not used in code in IPA master branch. There is 10-enable-betxn.update which is used. If I'm right we can remove it. Patch attached. Please correct me if the file

[Freeipa-devel] [PATCHES 306-316] Automated migration tool from Winsync

2015-03-09 Thread Tomas Babej
: Tomas Babej tba...@redhat.com Date: Mon, 2 Mar 2015 16:30:56 +0100 Subject: [PATCH] winsync-migrate: Add initial plumbing --- install/tools/ipa-winsync-migrate | 23 ipaserver/winsync_migrate/__init__.py | 22 ipaserver/winsync_migrate/base.py | 67

Re: [Freeipa-devel] [PATCHES 134-136] extdom: handle ERANGE return code for getXXYYY_r()

2015-03-09 Thread Tomas Babej
On 03/06/2015 01:08 PM, Alexander Bokovoy wrote: On Thu, 05 Mar 2015, Sumit Bose wrote: On Thu, Mar 05, 2015 at 09:16:36AM +0100, Sumit Bose wrote: On Wed, Mar 04, 2015 at 06:14:53PM +0100, Sumit Bose wrote: On Wed, Mar 04, 2015 at 04:17:55PM +0200, Alexander Bokovoy wrote: On Mon, 02 Mar

Re: [Freeipa-devel] [PATCH 0190] DNSSEC: add support for CKM_RSA_PKCS_OAEP mechanism

2015-03-06 Thread Tomas Babej
On 03/05/2015 02:45 PM, Petr Spacek wrote: On 26.2.2015 16:59, Martin Basti wrote: On 26/02/15 12:47, Petr Spacek wrote: On 11.2.2015 14:10, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/4657#comment:13 Patch attached. -- Martin Basti

Re: [Freeipa-devel] [PATCH 0194] Remove unused method to export secret key from ipapkcs11helper module

2015-03-06 Thread Tomas Babej
On 03/05/2015 02:45 PM, Petr Spacek wrote: On 25.2.2015 14:24, Martin Basti wrote: The method never been used, and never will be, because we do not want to export secrets. Ticket: https://fedorahosted.org/freeipa/ticket/4657 Patch attached (may require mbasti-0195, mbasti-0190) ACK, it

Re: [Freeipa-devel] [PATCH 0023-0025] p11helper improvements

2015-03-06 Thread Tomas Babej
On 03/05/2015 04:10 PM, Martin Basti wrote: On 05/03/15 15:37, Petr Spacek wrote: On 5.3.2015 14:50, Petr Spacek wrote: Hello, please review this patch set. It should be applied on top of your previous p11helper patch set. Thank you! Reviewer requested reworded version of the error

Re: [Freeipa-devel] [PATCH 0195] Fix memory leaks in ipapkcs11helper module

2015-03-06 Thread Tomas Babej
On 03/05/2015 02:45 PM, Petr Spacek wrote: On 26.2.2015 17:01, Martin Basti wrote: On 26/02/15 13:06, Petr Spacek wrote: Hello Martin, thank you for patch! This NACK is only aesthetic :-) On 25.2.2015 14:21, Martin Basti wrote: if (!check_return_value(rv, import_wrapped_key: key

Re: [Freeipa-devel] [PATCHES 399-401] Allow multiple API instances

2015-03-05 Thread Tomas Babej
On 03/04/2015 11:55 AM, Martin Kosek wrote: On 03/04/2015 11:13 AM, Jan Cholasta wrote: Dne 3.3.2015 v 16:11 Martin Kosek napsal(a): On 03/03/2015 04:09 PM, Jan Cholasta wrote: Dne 3.3.2015 v 16:04 Tomas Babej napsal(a): On 03/03/2015 04:01 PM, Martin Kosek wrote: On 03/03/2015 03:49 PM

Re: [Freeipa-devel] [PATCHES 0197-0198] Fix uniqueness plugins upgrade

2015-03-05 Thread Tomas Babej
On 03/04/2015 02:33 PM, Alexander Bokovoy wrote: On Wed, 25 Feb 2015, Martin Basti wrote: Modifications: * All plugins are migrated into new configuration style. * I left attribute uniqueness plugin disabled, cn=uid uniqueness,cn=plugins,cn=config is checking the same attribute. * POST_UPDATE

Re: [Freeipa-devel] [PATCHES 399-401] Allow multiple API instances

2015-03-03 Thread Tomas Babej
On 03/03/2015 04:01 PM, Martin Kosek wrote: On 03/03/2015 03:49 PM, Jan Cholasta wrote: Hi, the attached patches provide an attempt to fix https://fedorahosted.org/freeipa/ticket/3090. Patch 401 serves as an example and modifies ipa-advise to use its own API instance for Advice plugins.

Re: [Freeipa-devel] [PATCH 0039] Add test case for unsupported arg for ipa-advise

2015-02-26 Thread Tomas Babej
ACK. Pushed to: ipa-4-1: ddd7fb6a68fd413b1561eab9c29bac18882e5efd master: ae4ee6b53376bb7f3d1b4707c4e105c91b5cd8ab On 02/26/2015 05:58 PM, Gabe Alford wrote: Yeah. That makes more sense. Updated patch attached. Thanks, Gabe On Wed, Feb 25, 2015 at 3:55 PM, Tomas Babej tba...@redhat.com

Re: [Freeipa-devel] [PATCH 0042] ipa-replica-prepare should document ipv6 options

2015-02-25 Thread Tomas Babej
On 02/25/2015 09:26 PM, Gabe Alford wrote: Hello, Fix for https://fedorahosted.org/freeipa/ticket/4877. I just took what was in the ticket. Thanks, Gabe ___ Freeipa-devel mailing list Freeipa-devel@redhat.com

Re: [Freeipa-devel] [PATCH 0039] Add test case for unsupported arg for ipa-advise

2015-02-25 Thread Tomas Babej
. Thanks, Gabe On Tue, Feb 24, 2015 at 11:03 AM, Tomas Babej tba...@redhat.com mailto:tba...@redhat.com wrote: Hi Gabe, sorry for the delay. Here comes the review! 1.) All the tests fail, since the IPA master is not installed at all: def test_advice(self

Re: [Freeipa-devel] [PATCH] 808 webui: service: add ipakrbrequirespreauth checkbox

2015-02-25 Thread Tomas Babej
On 02/25/2015 05:22 PM, Petr Vobornik wrote: Allow to configure missing krb ticket flag - ipakrbrequirespreauth from Web UI. ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel ACK, works

Re: [Freeipa-devel] [PATCH 133] ipa-range-check: do not treat missing objects as error

2015-02-24 Thread Tomas Babej
On 02/24/2015 06:47 PM, Sumit Bose wrote: Hi, this patch changes a return code and should fix https://fedorahosted.org/freeipa/ticket/4924 . bye, Sumit ___ Freeipa-devel mailing list Freeipa-devel@redhat.com

Re: [Freeipa-devel] [PATCH 0039] Add test case for unsupported arg for ipa-advise

2015-02-24 Thread Tomas Babej
mailto:redhatri...@gmail.com wrote: Hello, Here is a patch for https://fedorahosted.org/freeipa/ticket/4029 I added test cases for valid and invalid advice. Thanks, Gabe On Wed, Jan 14, 2015 at 10:23 AM, Tomas Babej tba...@redhat.com javascript:_e(%7B%7D

<    1   2   3   4   5   6   7   8   9   10   >