Re: [Freeipa-devel] "blocker" tag for pull request

2017-05-16 Thread Tomas Krizek
On 05/02/2017 12:57 PM, Standa Laznicka wrote: > On 04/28/2017 02:41 PM, Martin Bašti wrote: >> >> On 28.04.2017 14:17, Tomas Krizek wrote: >>> On 04/28/2017 10:15 AM, Petr Vobornik wrote: >>>> Hi all, >>>> >>>> I created "blo

Re: [Freeipa-devel] [WIKI DRAFT] Files to be attached to bug reports

2017-05-12 Thread Tomas Krizek
ng and someone might post an old/unrelated error by accident. Using '-r' will ensure the user will see the most recent and relevant log output. -- Tomas Krizek PGP: 4A8B A48C 2AED 933B D495 C509 A1FB A5F7 EF8C 4869 signature.asc Description: OpenPGP digital signature -- Manage your subsc

Re: [Freeipa-devel] "blocker" tag for pull request

2017-04-28 Thread Tomas Krizek
in PR. But > testblocker tag in pagure does. Actually I'm thinking about changing > Pagure priority names to: "highest, high, medium, low, patchwelcome" > +1, but I'd prefer "critical" instead of "highest" -- Tomas Krizek PGP: 4A8B A48C 2AED 933B D495 C509

Re: [Freeipa-devel] Announcing FreeIPA 4.3.3

2017-03-27 Thread Tomas Krizek
=== > * Tests: fix test_forward_zones in test_xmlrpc/test_dns_plugin > * DNS server upgrade: do not fail when DNS server did not respond > * Fix ipa-replica-prepare's error message about missing local CA instance > > === Petr Vobornik (1) === > * ca-less tests: fix getting cert in p

Re: [Freeipa-devel] Announcing FreeIPA 4.4.4

2017-03-27 Thread Tomas Krizek
t; * Wait until HTTPS principal entry is replicated to replica > * wait_for_entry: use only DN as parameter > > === Stanislav Laznicka (2) === > * Add debug log in case cookie retrieval went wrong > * Fix cookie with Max-Age processing > > === Tomas Krizek (1) === > * server

[Freeipa-devel] Announcing bind-dyndb-ldap 11.1

2017-03-10 Thread Tomas Krizek
in the upcoming weeks. == Feedback == Please provide comments, report bugs, and send any other feedback via the freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users <http://www.redhat.com/mailman/listinfo/freeipa-users> -- Tomas Krizek PGP: 4A8B A48C 2AED 933

[Freeipa-devel] bind-dyndb-ldap git migration issue [resolved]

2017-03-10 Thread Tomas Krizek
ess. -- Tomas Krizek PGP: 4A8B A48C 2AED 933B D495 C509 A1FB A5F7 EF8C 4869 signature.asc Description: OpenPGP digital signature -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.

Re: [Freeipa-devel] [DISCUSSION] checking *lint at configure time

2017-03-06 Thread Tomas Krizek
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 03/06/2017 02:10 PM, Lukas Slebodnik wrote: > On (06/03/17 13:49), Tomas Krizek wrote: >> On 03/06/2017 01:44 PM, Lukas Slebodnik wrote: >>> On (06/03/17 13:35), Tomas Krizek wrote: >>>> On 03/03/2017 09:22 PM, Rob

Re: [Freeipa-devel] [DISCUSSION] checking *lint at configure time

2017-03-06 Thread Tomas Krizek
On 03/06/2017 01:44 PM, Lukas Slebodnik wrote: > On (06/03/17 13:35), Tomas Krizek wrote: >> On 03/03/2017 09:22 PM, Rob Crittenden wrote: >>> Lukas Slebodnik wrote: >>>> On (03/03/17 17:07), Lukas Slebodnik wrote: >>>>> ehlo, >>>>> >&

Re: [Freeipa-devel] [DISCUSSION] checking *lint at configure time

2017-03-06 Thread Tomas Krizek
> automation but I'd personally prefer Lukas's suggestion of requiring > them by default but providing clear output on how to disable them if > desired. This way the average user can easily work around it and it > won't impact current developers (unless they want it to). Is that as

Re: [Freeipa-devel] MD5 certificate fingerprints removal

2017-02-23 Thread Tomas Krizek
On 02/24/2017 08:34 AM, Standa Laznicka wrote: > On 02/24/2017 08:29 AM, Jan Cholasta wrote: >> On 23.2.2017 19:06, Martin Basti wrote: >>> >>> >>> On 23.02.2017 15:09, Tomas Krizek wrote: >>>> On 02/22/2017 01:44 PM, Fraser Tweedale wrote: >&

Re: [Freeipa-devel] MD5 certificate fingerprints removal

2017-02-23 Thread Tomas Krizek
On 02/22/2017 01:44 PM, Fraser Tweedale wrote: > On Wed, Feb 22, 2017 at 01:41:22PM +0100, Tomas Krizek wrote: >> On 02/22/2017 12:28 AM, Fraser Tweedale wrote: >>> On Tue, Feb 21, 2017 at 05:23:07PM +0100, Standa Laznicka wrote: >>>> On 02/21/2017 04:24 PM, Tomas Kri

Re: [Freeipa-devel] MD5 certificate fingerprints removal

2017-02-22 Thread Tomas Krizek
On 02/22/2017 12:28 AM, Fraser Tweedale wrote: > On Tue, Feb 21, 2017 at 05:23:07PM +0100, Standa Laznicka wrote: >> On 02/21/2017 04:24 PM, Tomas Krizek wrote: >>> On 02/21/2017 03:23 PM, Rob Crittenden wrote: >>>> Standa Laznicka wrote: >>>>> Hello, &

Re: [Freeipa-devel] MD5 certificate fingerprints removal

2017-02-21 Thread Tomas Krizek
ngerprints. The > OpenSSL equivalent doesn't include them by default. > > You may be able to deprecate fingerprints altogether. > > rob I think it's useful to display the certificate's fingerprint. I'm in favor of removing md5 and adding sha256 instead. -- Tomas Krizek signatu

Re: [Freeipa-devel] [DESIGN] FreeIPA on FIPS + NSS question

2017-01-25 Thread Tomas Krizek
On 01/25/2017 12:46 PM, Tomas Krizek wrote: > On 01/13/2017 05:44 PM, Petr Vobornik wrote: >> On 01/13/2017 03:49 PM, Rob Crittenden wrote: >>> Tomas Krizek wrote: >>>> On 01/12/2017 04:17 PM, Rob Crittenden wrote: >>>>> Tomas Krizek wrote: >>

Re: [Freeipa-devel] [DESIGN] FreeIPA on FIPS + NSS question

2017-01-25 Thread Tomas Krizek
On 01/13/2017 05:44 PM, Petr Vobornik wrote: > On 01/13/2017 03:49 PM, Rob Crittenden wrote: >> Tomas Krizek wrote: >>> On 01/12/2017 04:17 PM, Rob Crittenden wrote: >>>> Tomas Krizek wrote: >>>>> On 12/19/2016 04:41 PM, Standa Laznicka wrote: >

Re: [Freeipa-devel] [DESIGN] FreeIPA on FIPS + NSS question

2017-01-13 Thread Tomas Krizek
On 01/12/2017 04:17 PM, Rob Crittenden wrote: > Tomas Krizek wrote: >> On 12/19/2016 04:41 PM, Standa Laznicka wrote: >>> On 12/19/2016 03:07 PM, John Dennis wrote: >>>> On 12/19/2016 03:12 AM, Standa Laznicka wrote: >>>>> On 12/16/2016 03:23 PM, Rob C

Re: [Freeipa-devel] CI: exporting test runner output

2017-01-05 Thread Tomas Krizek
t; 4. Should we continue to `tail -n 5000` the log as we currently do, >>>or just rely on exported log? If you're talking about the log in the travis web interface, I would keep it. It's easily accessible from the browser. >>> Thanks, >>> Fraser >> Fraser, are you OK wit

Re: [Freeipa-devel] bind-dyndb-ldap: [PATCH] Handle termination of SyncRepl watcher thread

2016-12-19 Thread Tomas Krizek
y for the signal handler to retrieve/set the > 'existing' flag. Do you think we could move 'ldap_inst->exiting=TRUE' > and pthread_kill in a same wrapper function (for example > watcher_shutdown). > > thanks > thierry > > On 12/19/2016 01:04 PM, Tomas Krizek wrote

[Freeipa-devel] bind-dyndb-ldap: [PATCH] Handle termination of SyncRepl watcher thread

2016-12-19 Thread Tomas Krizek
ing the REQUIRE and logging an error instead. Thanks. -- Tomas Krizek From b801fb06a77f2ec8867884bc769d5bb1db0e1c2e Mon Sep 17 00:00:00 2001 From: Tomas Krizek <tkri...@redhat.com> Date: Mon, 19 Dec 2016 12:39:07 +0100 Subject: [PATCH] handle termination of syncrepl watcher thread In some cases, t

[Freeipa-devel] Announcing bind-dyndb-ldap version 11.0

2016-12-16 Thread Tomas Krizek
list: http://www.redhat.com/mailman/listinfo/freeipa-users -- Tomas Krizek -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Re: [Freeipa-devel] pylint: remove unused variables

2016-09-22 Thread Tomas Krizek
On 09/22/2016 06:00 PM, Martin Basti wrote: On 22.09.2016 17:59, Tomas Krizek wrote: On 09/22/2016 04:39 PM, Martin Basti wrote: Hello all, In 4.5, I would like to remove all unused variables from code and enable pylint check. Due to big amount of unused variables in the code

Re: [Freeipa-devel] pylint: remove unused variables

2016-09-22 Thread Tomas Krizek
to write than _dummy and it also provides a better readability, because I can immediately identify the symbol as special. Unlike _dummy which I have to read to understand (simply because I'm used to _something to indicate a 'protected' variable). -- Tomas Krizek -- Manage your subscription

Re: [Freeipa-devel] [PATCH] 0014

2016-09-05 Thread Tomas Krizek
On 09/02/2016 09:05 AM, Florence Blanc-Renaud wrote: On 09/02/2016 08:08 AM, Jan Cholasta wrote: On 1.9.2016 19:37, Tomas Krizek wrote: On 09/01/2016 03:58 PM, Florence Blanc-Renaud wrote: Hi, please find attached a patch for ipa-certupdate in CA-less deployment. https://fedorahosted.org

Re: [Freeipa-devel] [PATCH] 0014

2016-09-01 Thread Tomas Krizek
works as expected -> ACK. -- Tomas Krizek -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Re: [Freeipa-devel] [PATCH] 0003 Validate key in otptoken-add

2016-08-24 Thread Tomas Krizek
Fixed the typo in error message. On 08/23/2016 12:15 PM, Tomas Krizek wrote: In that case, the first version of the patch solves the issue. I'm attaching the patch once again, but it's the same as the one in the original message. On 08/23/2016 11:53 AM, Jan Cholasta wrote: On 22.8.2016 19

Re: [Freeipa-devel] [PATCH] 0003 Validate key in otptoken-add

2016-08-22 Thread Tomas Krizek
I've attached the updated patch. Hopefully I didn't forget anything else this time. On 08/22/2016 05:48 PM, Martin Basti wrote: On 22.08.2016 10:22, Tomas Krizek wrote: Seems like a good idea, I'm attaching the updated patch. Autofill does work when the param is required. On 08/19/2016

[Freeipa-devel] [PATCH] 0004 Fix ipa-server-install in pure IPv6 environment

2016-08-19 Thread Tomas Krizek
Hi, please review the attached patch. Make sure the hostname isn't resolved to link local IPv6(feXX:...) during testing, which doesn't work (and isn't supposed to). -- Tomas Krizek From d4a7a4e637951fca5331e9dc0622df912e828a26 Mon Sep 17 00:00:00 2001 From: Tomas Krizek <tkri...@redhat.

Re: [Freeipa-devel] [PATCH 0004] [Test] Test for caacl-add-service: incorrect error message when service does not exists

2016-08-18 Thread Tomas Krizek
rvice does not exists https://fedorahosted.org/freeipa/ticket/6171 Best regards, Ganna Kaihorodova Associate Software Quality Engineer : -- Tomas Krizek -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to Fre

Re: [Freeipa-devel] [PATCH 0562] Fix: container owner should be able to add vault

2016-08-18 Thread Tomas Krizek
oneliner rule -- Tomas Krizek -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Re: [Freeipa-devel] [PATCH] 0106, 0107: webui: add warning that only one CA server exists

2016-08-17 Thread Tomas Krizek
ACK, works for me. On 08/16/2016 10:43 AM, Pavel Vomacka wrote: Hello, Please review attached patches which adds warning that only one CA server is installed. https://fedorahosted.org/freeipa/ticket/5828 -- Tomas Krizek -- Manage your subscription for the Freeipa-devel mailing list

[Freeipa-devel] [PATCH] 0003 Validate key in otptoken-add

2016-08-16 Thread Tomas Krizek
Hi, the attached patch fixes an error message when user provides an empty key while adding otp token. https://fedorahosted.org/freeipa/ticket/6200 -- Tomas Krizek From 806e0cf73dcc3ccbfd620b7865561682ea2e37f5 Mon Sep 17 00:00:00 2001 From: Tomas Krizek <tkri...@redhat.com> Date: Tue,

[Freeipa-devel] [PATCH 0002] Fix ipa-caacl-add-service error message

2016-08-09 Thread Tomas Krizek
Hi, please review the attached patch. Thanks, Tomas From 9787d13cd7f0f3b8ce65ca84a7759f180a74d6d8 Mon Sep 17 00:00:00 2001 From: Tomas Krizek <tkri...@redhat.com> Date: Tue, 9 Aug 2016 14:09:24 +0200 Subject: [PATCH] Fix ipa-caalc-add-service error message When service is not found

[Freeipa-devel] [PATCH] 0001 Update ipa-replica-install documentation

2016-08-05 Thread Tomas Krizek
Hi, attached a patch to update man page and doc. Tomas From 6aae0cca6e3347bd3b02af45aa27c61d25407f61 Mon Sep 17 00:00:00 2001 From: Tomas Krizek <tkri...@redhat.com> Date: Fri, 5 Aug 2016 09:25:05 +0200 Subject: [PATCH] Update ipa-replica-install documentation Update the ipa-replica-i