[Freeipa-devel] [freeipa PR#446][comment] No NSS database passwords in ipa-client-install

2017-02-15 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/446 Title: #446: No NSS database passwords in ipa-client-install stlaz commented: """ This patchset seems more like a cleanup after the privilege separation one, although adding a password to certutil calls is still the main topic

[Freeipa-devel] [freeipa PR#446][synchronized] No NSS database passwords in ipa-client-install

2017-02-15 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/446 Author: stlaz Title: #446: No NSS database passwords in ipa-client-install Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/446/head:pr446 git checkout pr446

[Freeipa-devel] [freeipa PR#397][comment] Improve wheel building and provide ipaserver wheel for local testing

2017-02-15 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/397 Title: #397: Improve wheel building and provide ipaserver wheel for local testing stlaz commented: """ @pvoborni The remaining usages are server/CA certificates verification in `certdb.py` and and apparently some encryption/dec

[Freeipa-devel] [freeipa PR#446][synchronized] No NSS database passwords in ipa-client-install

2017-02-14 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/446 Author: stlaz Title: #446: No NSS database passwords in ipa-client-install Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/446/head:pr446 git checkout pr446

[Freeipa-devel] [freeipa PR#446][comment] No NSS database passwords in ipa-client-install

2017-02-14 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/446 Title: #446: No NSS database passwords in ipa-client-install stlaz commented: """ NSSDatabase now defaults its `.password_file` to `.sec_dir + 'passwd.txt'`. It's necessary to create a pwdfile.txt in Dogtag cert store so that a

[Freeipa-devel] [freeipa PR#446][comment] No NSS database passwords in ipa-client-install

2017-02-14 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/446 Title: #446: No NSS database passwords in ipa-client-install stlaz commented: """ NSSDatabase now defaults its `.password_file` to `.sec_dir + 'passwd.txt'`. It's necessary to create a pwdfile.txt in Dogtag cert store so that a

[Freeipa-devel] [freeipa PR#446][comment] No NSS database passwords in ipa-client-install

2017-02-14 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/446 Title: #446: No NSS database passwords in ipa-client-install stlaz commented: """ NSSDatabase now defaults its `.password_file` to `.sec_dir + 'passwd.txt'`. It's necessary to create a pwdfile.txt in system-wide cert store so tha

[Freeipa-devel] [freeipa PR#396][synchronized] Explicitly remove support of SSLv2

2017-02-14 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/396 Author: stlaz Title: #396: Explicitly remove support of SSLv2 Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/396/head:pr396 git checkout pr396 From

[Freeipa-devel] [freeipa PR#446][synchronized] No NSS database passwords in ipa-client-install

2017-02-14 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/446 Author: stlaz Title: #446: No NSS database passwords in ipa-client-install Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/446/head:pr446 git checkout pr446

[Freeipa-devel] [freeipa PR#464][synchronized] Bump required python-cryptography version

2017-02-14 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/464 Author: stlaz Title: #464: Bump required python-cryptography version Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/464/head:pr464 git checkout pr464 From

[Freeipa-devel] [freeipa PR#464][opened] :arrow_up: Bump required python-cryptography version

2017-02-14 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/464 Author: stlaz Title: #464: :arrow_up: Bump required python-cryptography version Action: opened PR body: """ Since we started using `Certificate.serial_number` instead of `.serial` from python-cryptography (https://github.com/

[Freeipa-devel] [freeipa PR#464][edited] :arrow_up: Bump required python-cryptography version

2017-02-14 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/464 Author: stlaz Title: #464: :arrow_up: Bump required python-cryptography version Action: edited Changed field: title Original value: """ :arrow_up: Bump required python-cryptography version """ -- Manage you

[Freeipa-devel] [freeipa PR#446][reopened] No NSS database passwords in ipa-client-install

2017-02-14 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/446 Author: stlaz Title: #446: No NSS database passwords in ipa-client-install Action: reopened To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/446/head:pr446 git checkout pr446

[Freeipa-devel] [freeipa PR#446][closed] No NSS database passwords in ipa-client-install

2017-02-14 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/446 Author: stlaz Title: #446: No NSS database passwords in ipa-client-install Action: closed To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/446/head:pr446 git checkout pr446

[Freeipa-devel] [freeipa PR#446][synchronized] No NSS database passwords in ipa-client-install

2017-02-14 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/446 Author: stlaz Title: #446: No NSS database passwords in ipa-client-install Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/446/head:pr446 git checkout pr446

[Freeipa-devel] [freeipa PR#450][comment] Add FIPS-token password of HTTPD NSS database

2017-02-10 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/450 Title: #450: Add FIPS-token password of HTTPD NSS database stlaz commented: """ That was my original approach to it but we had offline talk with @HonzaCholasta and got to the point that it might be better to do it this way. From m

[Freeipa-devel] [freeipa PR#446][synchronized] No NSS database passwords in ipa-client-install

2017-02-10 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/446 Author: stlaz Title: #446: No NSS database passwords in ipa-client-install Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/446/head:pr446 git checkout pr446

[Freeipa-devel] [freeipa PR#455][+ack] Backup /root/kracert.p12

2017-02-10 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/455 Title: #455: Backup /root/kracert.p12 Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

[Freeipa-devel] [freeipa PR#455][comment] Backup /root/kracert.p12

2017-02-10 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/455 Title: #455: Backup /root/kracert.p12 stlaz commented: """ Works as expected, ACK. """ See the full comment at https://github.com/freeipa/freeipa/pull/455#issuecomment-278939314 -- Manage your subscription for

[Freeipa-devel] [freeipa PR#450][synchronized] Add FIPS-token password of HTTPD NSS database

2017-02-10 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/450 Author: stlaz Title: #450: Add FIPS-token password of HTTPD NSS database Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/450/head:pr450 git checkout pr450

[Freeipa-devel] [freeipa PR#450][synchronized] Add FIPS-token password of HTTPD NSS database

2017-02-10 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/450 Author: stlaz Title: #450: Add FIPS-token password of HTTPD NSS database Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/450/head:pr450 git checkout pr450

[Freeipa-devel] [freeipa PR#446][synchronized] No NSS database passwords in ipa-client-install

2017-02-09 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/446 Author: stlaz Title: #446: No NSS database passwords in ipa-client-install Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/446/head:pr446 git checkout pr446

[Freeipa-devel] [freeipa PR#446][synchronized] No NSS database passwords in ipa-client-install

2017-02-09 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/446 Author: stlaz Title: #446: No NSS database passwords in ipa-client-install Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/446/head:pr446 git checkout pr446

[Freeipa-devel] [freeipa PR#443][comment] Stronger check for DM password during server install

2017-02-09 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/443 Title: #443: Stronger check for DM password during server install stlaz commented: """ @HonzaCholasta: +1, you're right, I should investigate more on how to change this behavior, either we or Dogtag don't behave correctly

[Freeipa-devel] [freeipa PR#450][synchronized] Add FIPS-token password of HTTPD NSS database

2017-02-09 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/450 Author: stlaz Title: #450: Add FIPS-token password of HTTPD NSS database Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/450/head:pr450 git checkout pr450

[Freeipa-devel] [freeipa PR#451][comment] certdb: remove unused keysize property

2017-02-08 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/451 Title: #451: certdb: remove unused keysize property stlaz commented: """ If you want to remove them, you may want to check for other properties as well (I see `valid_months` at least). """ See the full comment

[Freeipa-devel] [freeipa PR#445][synchronized] Remove is_fips_enabled checks in installers and ipactl

2017-02-08 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/445 Author: stlaz Title: #445: Remove is_fips_enabled checks in installers and ipactl Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/445/head:pr445 git

[Freeipa-devel] [freeipa PR#450][opened] Add FIPS-token password of HTTPD NSS database

2017-02-08 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/450 Author: stlaz Title: #450: Add FIPS-token password of HTTPD NSS database Action: opened PR body: """ This change is required for httpd to function properly in FIPS https://fedorahosted.org/freeipa/ticket/5695 """

[Freeipa-devel] [freeipa PR#443][synchronized] Stronger check for DM password during server install

2017-02-08 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/443 Author: stlaz Title: #443: Stronger check for DM password during server install Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/443/head:pr443 git checkout

[Freeipa-devel] [freeipa PR#446][edited] No NSS database passwords in ipa-client-install

2017-02-08 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/446 Author: stlaz Title: #446: No NSS database passwords in ipa-client-install Action: edited Changed field: body Original value: """ With this patchset, ipa-client-install should not ask for NSS database password. Prer

[Freeipa-devel] [freeipa PR#446][edited] Certdb passwd

2017-02-08 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/446 Author: stlaz Title: #446: Certdb passwd Action: edited Changed field: title Original value: """ Certdb passwd """ -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/

[Freeipa-devel] [freeipa PR#445][opened] Remove is_fips_enabled checks in installers and ipactl

2017-02-08 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/445 Author: stlaz Title: #445: Remove is_fips_enabled checks in installers and ipactl Action: opened PR body: """ https://fedorahosted.org/freeipa/ticket/5695 """ To pull the PR as Git branch: git remote add ghfree

[Freeipa-devel] [freeipa PR#443][opened] Stronger check for DM password during server install

2017-02-08 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/443 Author: stlaz Title: #443: Stronger check for DM password during server install Action: opened PR body: """ DM password is used as an NSS database password during server installation, therefore it must comply to NSS databa

[Freeipa-devel] [freeipa PR#440][+ack] [Py3] fix various issues in tests related to BytesWarning

2017-02-08 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/440 Title: #440: [Py3] fix various issues in tests related to BytesWarning Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#437][comment] FIPS: replica install check

2017-02-08 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/437 Title: #437: FIPS: replica install check stlaz commented: """ LGTM """ See the full comment at https://github.com/freeipa/freeipa/pull/437#issuecomment-278279899 -- Manage your subscription for the Fre

[Freeipa-devel] [freeipa PR#396][synchronized] Explicitly remove support of SSLv2

2017-02-07 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/396 Author: stlaz Title: #396: Explicitly remove support of SSLv2 Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/396/head:pr396 git checkout pr396 From

[Freeipa-devel] [freeipa PR#396][synchronized] Explicitly remove support of SSLv2

2017-02-07 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/396 Author: stlaz Title: #396: Explicitly remove support of SSLv2 Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/396/head:pr396 git checkout pr396 From

[Freeipa-devel] [freeipa PR#396][comment] Explicitly remove support of SSLv2

2017-02-07 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/396 Title: #396: Explicitly remove support of SSLv2 stlaz commented: """ Did not realize merging to Env from default constants was happening in the end of `_finalize_core()`, moved the checks in config.py accordingly. Also, for some

[Freeipa-devel] [freeipa PR#396][synchronized] Explicitly remove support of SSLv2

2017-02-07 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/396 Author: stlaz Title: #396: Explicitly remove support of SSLv2 Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/396/head:pr396 git checkout pr396 From

[Freeipa-devel] [freeipa PR#396][synchronized] Explicitly remove support of SSLv2

2017-02-07 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/396 Author: stlaz Title: #396: Explicitly remove support of SSLv2 Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/396/head:pr396 git checkout pr396 From

[Freeipa-devel] [freeipa PR#435][+ack] py3: fix replica install regression

2017-02-07 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/435 Title: #435: py3: fix replica install regression Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

[Freeipa-devel] [freeipa PR#435][comment] py3: fix replica install regression

2017-02-07 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/435 Title: #435: py3: fix replica install regression stlaz commented: """ Works for me. """ See the full comment at https://github.com/freeipa/freeipa/pull/435#issuecomment-277948678 -- Manage your subscription for

[Freeipa-devel] [freeipa PR#416][comment] replica install: relax domain level check for promotion

2017-02-05 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/416 Title: #416: replica install: relax domain level check for promotion stlaz commented: """ @frasertweedale Alright. I am definitely not against having it separated since we came to the realization that replica install checks ca

[Freeipa-devel] [freeipa PR#416][comment] replica install: relax domain level check for promotion

2017-02-03 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/416 Title: #416: replica install: relax domain level check for promotion stlaz commented: """ The purpose of `check_domain_level()` was to have a unified means of checking whether the domain level in the rest of the dom

[Freeipa-devel] [freeipa PR#367][comment] Remove nsslib from IPA

2017-02-02 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/367 Title: #367: Remove nsslib from IPA stlaz commented: """ In the latest patchset, the "ipaCert" is removed from the "/etc/httpd/alias/" NSSDB and all the machinery around the certificate is moved accordingly.

[Freeipa-devel] [freeipa PR#367][edited] Remove nsslib from IPA

2017-02-02 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/367 Author: stlaz Title: #367: Remove nsslib from IPA Action: edited Changed field: body Original value: """ This batch of patches removes NSSConnection along with the whole ipapython.nsslib from IPA and replaces it wit

[Freeipa-devel] [freeipa PR#367][edited] Remove nsslib from IPA

2017-02-02 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/367 Author: stlaz Title: #367: Remove nsslib from IPA Action: edited Changed field: body Original value: """ This batch of patches removes NSSConnection along with the whole ipapython.nsslib from IPA and replaces it wit

[Freeipa-devel] [freeipa PR#402][+ack] [master] wait_for_entry improvements

2017-01-31 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/402 Title: #402: [master] wait_for_entry improvements Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#395][comment] Configure PKI ajp redirection to use "localhost" instead of "::1"

2017-01-24 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/395 Title: #395: Configure PKI ajp redirection to use "localhost" instead of "::1" stlaz commented: """ Removed the ACK label since this is not yet reviewed. """ See the full comment at https:

[Freeipa-devel] [freeipa PR#395][-ack] Configure PKI ajp redirection to use "localhost" instead of "::1"

2017-01-24 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/395 Title: #395: Configure PKI ajp redirection to use "localhost" instead of "::1" Label: -ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#401][+ack] [4.4] Wait until http principal entry is replicated to replica

2017-01-24 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/401 Title: #401: [4.4] Wait until http principal entry is replicated to replica Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#401][comment] [4.4] Wait until http principal entry is replicated to replica

2017-01-24 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/401 Title: #401: [4.4] Wait until http principal entry is replicated to replica stlaz commented: """ Seems to work in the problematic ca-less environment, ACK. """ See the full comment at https://github.com/freeipa

[Freeipa-devel] [freeipa PR#376][comment] client install: correctly report all failures

2017-01-20 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/376 Title: #376: client install: correctly report all failures stlaz commented: """ Alright, that's a known issue from the refactorings. Other than that the patch is fine. ACK. """ See the full comment at https://g

[Freeipa-devel] [freeipa PR#376][+ack] client install: correctly report all failures

2017-01-20 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/376 Title: #376: client install: correctly report all failures Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#376][comment] client install: correctly report all failures

2017-01-19 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/376 Title: #376: client install: correctly report all failures stlaz commented: """ I suspect we are suffering the same "always return 0" error as we've already got reported in other installers, right? "&quo

[Freeipa-devel] [freeipa PR#373][comment] ipaplatform: Add Debian platform module.

2017-01-19 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/373 Title: #373: ipaplatform: Add Debian platform module. stlaz commented: """ The patch seems fine, I could have some nitpicks but nothing really imporant. ACK. """ See the full comment at https://github.com/freeipa

[Freeipa-devel] [freeipa PR#373][+ack] ipaplatform: Add Debian platform module.

2017-01-19 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/373 Title: #373: ipaplatform: Add Debian platform module. Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#373][comment] ipaplatform: Add Debian platform module.

2017-01-19 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/373 Title: #373: ipaplatform: Add Debian platform module. stlaz commented: """ @tiran I would like to test this in a Vagrant box before pushing it """ See the full comment at https://github.com/freeipa/freeipa/p

[Freeipa-devel] [freeipa PR#373][comment] ipaplatform: Add Debian platform module.

2017-01-19 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/373 Title: #373: ipaplatform: Add Debian platform module. stlaz commented: """ @tiran I would like to test this in a Vagrant box before pushing it """ See the full comment at https://github.com/freeipa/freeipa/p

[Freeipa-devel] [freeipa PR#372][+rejected] Restore IPA 3.0 compatibility of copy-schema-to-ca.py

2017-01-19 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/372 Title: #372: Restore IPA 3.0 compatibility of copy-schema-to-ca.py Label: +rejected -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#396][comment] Explicitly remove support of SSLv2

2017-01-19 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/396 Title: #396: Explicitly remove support of SSLv2 stlaz commented: """ - I think we may need to discuss the support on Monday meeting, generally I think SSL 3.0 and TLS 1.0 should not be supported but there might be troubles wi

[Freeipa-devel] [freeipa PR#403][comment] Add new ipa passwd-generate command

2017-01-18 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/403 Title: #403: Add new ipa passwd-generate command stlaz commented: """ Hello and thank you for the contribution! However, I do not see what's in this for us. I do not think FreeIPA is intended to be used as a password generator.

[Freeipa-devel] [freeipa PR#372][comment] Restore IPA 3.0 compatibility of copy-schema-to-ca.py

2017-01-17 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/372 Title: #372: Restore IPA 3.0 compatibility of copy-schema-to-ca.py stlaz commented: """ +1, we need to fix the script first, though. """ See the full comment at https://github.com/freeipa/freeipa/pull/372#issuecom

[Freeipa-devel] [freeipa PR#372][comment] Restore IPA 3.0 compatibility of copy-schema-to-ca.py

2017-01-16 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/372 Title: #372: Restore IPA 3.0 compatibility of copy-schema-to-ca.py stlaz commented: """ +1, that was actually my original point. Just revert the change done to the file in https://git.fedorahosted.org/cgit/freeipa

[Freeipa-devel] [freeipa PR#377][comment] dogtaginstance: track server certificate with our renew agent

2017-01-13 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/377 Title: #377: dogtaginstance: track server certificate with our renew agent stlaz commented: """ This PR can be safely pushed, an unknown upstream contributor with the same github nick as me will later create a PR with the propo

[Freeipa-devel] [freeipa PR#367][comment] Remove nsslib from IPA

2017-01-12 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/367 Title: #367: Remove nsslib from IPA stlaz commented: """ @rcritten `tls_version_min/max` could have been set to "ssl2" just as well as "ssl3" but perhaps it's for the best to remove them. I will try to do t

[Freeipa-devel] [freeipa PR#367][comment] Remove nsslib from IPA

2017-01-12 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/367 Title: #367: Remove nsslib from IPA stlaz commented: """ @rcritten I spoke to the NSS people who assured me it's the intended behavior. But thanks for the remainder, I will open a Bugzilla for that as well, I was considering it b

[Freeipa-devel] [freeipa PR#367][synchronized] Remove nsslib from IPA

2017-01-12 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/367 Author: stlaz Title: #367: Remove nsslib from IPA Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/367/head:pr367 git checkout pr367 From

[Freeipa-devel] [freeipa PR#377][+ack] dogtaginstance: track server certificate with our renew agent

2017-01-12 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/377 Title: #377: dogtaginstance: track server certificate with our renew agent Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#377][comment] dogtaginstance: track server certificate with our renew agent

2017-01-12 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/377 Title: #377: dogtaginstance: track server certificate with our renew agent stlaz commented: """ I made a patch that makes is_renewal_master and set_renewal_master classmethods on @tiran recommendation. Feel free to push it

[Freeipa-devel] [freeipa PR#377][comment] dogtaginstance: track server certificate with our renew agent

2017-01-12 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/377 Title: #377: dogtaginstance: track server certificate with our renew agent stlaz commented: """ Works fine. """ See the full comment at https://github.com/freeipa/freeipa/pull/377#issuecomment-27213791

[Freeipa-devel] [freeipa PR#367][comment] Remove nsslib from IPA

2017-01-11 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/367 Title: #367: Remove nsslib from IPA stlaz commented: """ I created the design for this effort: http://www.freeipa.org/page/V4/Replace_NSS_with_OpenSSL """ See the full comment at https://github.com/freeipa

[Freeipa-devel] [freeipa PR#367][comment] Remove nsslib from IPA

2017-01-11 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/367 Title: #367: Remove nsslib from IPA stlaz commented: """ I created the design for this effort: http://www.freeipa.org/page/V4/Replace_NSS_with_OpenSSL """ See the full comment at https://github.com/freeipa

[Freeipa-devel] [freeipa PR#385][comment] Generate sha256 ssh pubkey fingerprints for hosts

2017-01-11 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/385 Title: #385: Generate sha256 ssh pubkey fingerprints for hosts stlaz commented: """ @tiran Yes, exactly, this is only a UI thing. """ See the full comment at https://github.com/freeipa/freeipa/pull/385#issuecom

[Freeipa-devel] [freeipa PR#367][edited] Remove nsslib from IPA

2017-01-11 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/367 Author: stlaz Title: #367: Remove nsslib from IPA Action: edited Changed field: body Original value: """ This batch of patches removes NSSConnection along with the whole ipapython.nsslib from IPA and replaces it wit

[Freeipa-devel] [freeipa PR#385][comment] Generate sha256 ssh pubkey fingerprints for hosts

2017-01-11 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/385 Title: #385: Generate sha256 ssh pubkey fingerprints for hosts stlaz commented: """ @tiran Which SSHFP records do you mean? """ See the full comment at https://github.com/freeipa/freeipa/pull/385#issuecom

[Freeipa-devel] [freeipa PR#385][synchronized] Generate sha256 ssh pubkey fingerprints for hosts

2017-01-10 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/385 Author: stlaz Title: #385: Generate sha256 ssh pubkey fingerprints for hosts Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/385/head:pr385 git checkout

[Freeipa-devel] [freeipa PR#383][comment] Remove duplicated step from DS install

2017-01-10 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/383 Title: #383: Remove duplicated step from DS install stlaz commented: """ The tests passed, ACK. """ See the full comment at https://github.com/freeipa/freeipa/pull/383#issuecomment-271622092 -- Manage your subs

[Freeipa-devel] [freeipa PR#383][+ack] Remove duplicated step from DS install

2017-01-10 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/383 Title: #383: Remove duplicated step from DS install Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#385][opened] Generate sha256 ssh pubkey fingerprints for hosts

2017-01-10 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/385 Author: stlaz Title: #385: Generate sha256 ssh pubkey fingerprints for hosts Action: opened PR body: """ Replace md5 with sha256 for host ssh pubkey fingerprints. MD5 is disabled in FIPS mode, newer versions of OpenSSH print SH

[Freeipa-devel] [freeipa PR#367][synchronized] Remove nsslib from IPA

2017-01-10 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/367 Author: stlaz Title: #367: Remove nsslib from IPA Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/367/head:pr367 git checkout pr367 From

[Freeipa-devel] [freeipa PR#367][comment] Remove nsslib from IPA

2017-01-10 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/367 Title: #367: Remove nsslib from IPA stlaz commented: """ In the last update I added SSLv2 support in IPAHTTPSConnection for backward compatibility (https://goo.gl/images/gqh2D9). I also removed the Fedora crypto policie

[Freeipa-devel] [freeipa PR#367][synchronized] Remove nsslib from IPA

2017-01-10 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/367 Author: stlaz Title: #367: Remove nsslib from IPA Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/367/head:pr367 git checkout pr367 From

[Freeipa-devel] [freeipa PR#380][comment] Travis CI: actually return non-zero exit status when the test job fails

2017-01-09 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/380 Title: #380: Travis CI: actually return non-zero exit status when the test job fails stlaz commented: """ It works but for some reason there are many extra newlines in the failure log **edit:** nvm, displayes correctly now,

[Freeipa-devel] [freeipa PR#380][+ack] Travis CI: actually return non-zero exit status when the test job fails

2017-01-09 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/380 Title: #380: Travis CI: actually return non-zero exit status when the test job fails Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#380][comment] Travis CI: actually return non-zero exit status when the test job fails

2017-01-09 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/380 Title: #380: Travis CI: actually return non-zero exit status when the test job fails stlaz commented: """ It works but for some reason there are many extra newlines in the failure log """ See the full comment

[Freeipa-devel] [freeipa PR#380][comment] Travis CI: actually return non-zero exit status when the test job fails

2017-01-09 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/380 Title: #380: Travis CI: actually return non-zero exit status when the test job fails stlaz commented: """ It works but for some reason there are many extra newlines in the failure log """ See the full comment

[Freeipa-devel] [freeipa PR#181][comment] Tests : User Tracker creation of user with minimal values

2017-01-08 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/181 Title: #181: Tests : User Tracker creation of user with minimal values stlaz commented: """ Thank you for the changes! """ See the full comment at https://github.com/freeipa/freeipa/pull/181#issuecomment-27122275

[Freeipa-devel] [freeipa PR#181][+ack] Tests : User Tracker creation of user with minimal values

2017-01-08 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/181 Title: #181: Tests : User Tracker creation of user with minimal values Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#210][+ack] Tests: Stage User Tracker implementation

2017-01-08 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/210 Title: #210: Tests: Stage User Tracker implementation Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#367][synchronized] Remove nsslib from IPA

2017-01-06 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/367 Author: stlaz Title: #367: Remove nsslib from IPA Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/367/head:pr367 git checkout pr367 From

[Freeipa-devel] [freeipa PR#367][edited] Remove nsslib from IPA

2017-01-06 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/367 Author: stlaz Title: #367: Remove nsslib from IPA Action: edited Changed field: body Original value: """ This batch of patches removes NSSConnection along with the whole ipapython.nsslib from IPA and replaces it wit

[Freeipa-devel] [freeipa PR#367][synchronized] Remove nsslib from IPA

2017-01-06 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/367 Author: stlaz Title: #367: Remove nsslib from IPA Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/367/head:pr367 git checkout pr367 From

[Freeipa-devel] [freeipa PR#317][comment] Unify password generation across FreeIPA

2017-01-06 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/317 Title: #317: Unify password generation across FreeIPA stlaz commented: """ I don't see any merge conflicts and the rebase was automatic so I don't see why, but ok. Just note that ipatool may be confused with me commiting @pspacek

[Freeipa-devel] [freeipa PR#317][synchronized] Unify password generation across FreeIPA

2017-01-06 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/317 Author: stlaz Title: #317: Unify password generation across FreeIPA Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/317/head:pr317 git checkout pr317 From

[Freeipa-devel] [freeipa PR#181][comment] Tests : User Tracker creation of user with minimal values

2017-01-05 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/181 Title: #181: Tests : User Tracker creation of user with minimal values stlaz commented: """ Seems fine + Travis is satisfied as well, ACK. """ See the full comment at https://github.com/freeipa/freeipa/pull/181#iss

[Freeipa-devel] [freeipa PR#181][comment] Tests : User Tracker creation of user with minimal values

2017-01-05 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/181 Title: #181: Tests : User Tracker creation of user with minimal values stlaz commented: """ Seems fine + Travis is satisfied as well, ACK. """ See the full comment at https://github.com/freeipa/freeipa/pull/181#iss

[Freeipa-devel] [freeipa PR#361][comment] This PR implements a number of improvements for our Travis CI:

2017-01-05 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/361 Title: #361: This PR implements a number of improvements for our Travis CI: stlaz commented: """ I have no more remarks on this, hopefully final ACK. """ See the full comment at https://github.com/freeipa/freeipa/p

[Freeipa-devel] [freeipa PR#361][+ack] This PR implements a number of improvements for our Travis CI:

2017-01-05 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/361 Title: #361: This PR implements a number of improvements for our Travis CI: Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#372][comment] Restore IPA 3.0 compatibility of copy-schema-to-ca.py

2017-01-05 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/372 Title: #372: Restore IPA 3.0 compatibility of copy-schema-to-ca.py stlaz commented: """ Is there a reason not to stick with the original `ipautil.SHARE_DIR` and without setting `confdir`? This script won't be run on servers t

<    1   2   3   4   5   6   7   >