Re: [Freeipa-devel] [PATCH] 0056 Support requests for DOMAIN$ account for trusted domain in ipasam module

2012-06-28 Thread Martin Kosek
On 06/27/2012 05:59 PM, Sumit Bose wrote: On Wed, Jun 27, 2012 at 05:36:51PM +0300, Alexander Bokovoy wrote: Hi, Windows 2008R2 attempts to authenticate as DOMAIN$ with trust password when trust is established. Change ipasam module to consider DOMAIN$ when checking for trusted domain

Re: [Freeipa-devel] [PATCH] 0055 Add error condition handling to SASL bind callback in ipasam module

2012-06-28 Thread Martin Kosek
On 06/27/2012 06:12 PM, Sumit Bose wrote: On Wed, Jun 27, 2012 at 07:09:03PM +0300, Alexander Bokovoy wrote: On Wed, 27 Jun 2012, Sumit Bose wrote: On Wed, Jun 27, 2012 at 05:29:07PM +0300, Alexander Bokovoy wrote: Hi, attached patch adds comprehensive error condition handling to SASL bind

Re: [Freeipa-devel] [PATCH] Add sidgen postop and task

2012-06-28 Thread Martin Kosek
On 06/27/2012 06:27 PM, Alexander Bokovoy wrote: On Mon, 25 Jun 2012, Sumit Bose wrote: Hi, this patch added support to automatically create SIDs for local objects as described in ticket https://fedorahosted.org/freeipa/ticket/2825. The post-operation plugin adds the SID and if necessary

Re: [Freeipa-devel] [PATCH] Filter groups in the PAC

2012-06-28 Thread Martin Kosek
On 06/27/2012 06:28 PM, Alexander Bokovoy wrote: On Tue, 26 Jun 2012, Sumit Bose wrote: Hi, this patch contains the KDC part of the external groups handling. If group SIDs from the PAC can be found in the ipaExternalGroup objects and the external groups are member of local groups, the SIDs

Re: [Freeipa-devel] [PATCH] 18 Add external domain extop DS plugin

2012-06-28 Thread Martin Kosek
On 06/27/2012 06:38 PM, Alexander Bokovoy wrote: On Wed, 27 Jun 2012, Sumit Bose wrote: On Wed, Jun 13, 2012 at 12:37:49PM +0200, Sumit Bose wrote: On Wed, Jun 13, 2012 at 12:26:43PM +0200, Sumit Bose wrote: On Mon, Jun 11, 2012 at 05:46:17PM +0300, Alexander Bokovoy wrote: On Thu, 07 Jun

Re: [Freeipa-devel] [PATCH] 1030 Fedora 18 compatibility

2012-06-28 Thread Martin Kosek
On 06/27/2012 07:46 PM, Rob Crittenden wrote: I found a few minor issues when building and installing the master branch on Fedora 18. This patch should address it. rob 1) This will fail for on F17-F18 upgrades, we need to bump VERSION in ipa-rewrite.conf. Besides that, ipa-upgradeconfig

[Freeipa-devel] Build failure in ipa_sam

2012-06-28 Thread William Brown
Making all in ipa-sam make[4]: Entering directory `/home/william/development/freeipa/rpmbuild/BUILD/freeipa-2.99.0GIT8ce7330/daemons/ipa-sam' /bin/sh ../libtool --tag=CC --mode=compile gcc -DHAVE_CONFIG_H -I. -I.. -I. -I. -I/usr/include/samba-4.0 -DPREFIX=\/usr\ -DBINDIR=\/usr/bin\

Re: [Freeipa-devel] Build failure in ipa_sam

2012-06-28 Thread Alexander Bokovoy
On Thu, 28 Jun 2012, William Brown wrote: Making all in ipa-sam make[4]: Entering directory `/home/william/development/freeipa/rpmbuild/BUILD/freeipa-2.99.0GIT8ce7330/daemons/ipa-sam' /bin/sh ../libtool --tag=CC --mode=compile gcc -DHAVE_CONFIG_H -I. -I.. -I. -I. -I/usr/include/samba-4.0

Re: [Freeipa-devel] [DRAFT2] Per-domain DNS update permissions

2012-06-28 Thread Petr Viktorin
On 06/27/2012 06:01 PM, Petr Viktorin wrote: On 06/27/2012 02:50 PM, Martin Kosek wrote: On 06/25/2012 08:50 PM, Rob Crittenden wrote: Simo Sorce wrote: On Fri, 2012-06-22 at 14:25 +0200, Martin Kosek wrote: On 06/22/2012 02:23 PM, Simo Sorce wrote: On Fri, 2012-06-22 at 12:20 +0200, Martin

Re: [Freeipa-devel] Build failure in ipa_sam

2012-06-28 Thread William Brown
On 28/06/12 18:43, Alexander Bokovoy wrote: On Thu, 28 Jun 2012, William Brown wrote: Making all in ipa-sam make[4]: Entering directory `/home/william/development/freeipa/rpmbuild/BUILD/freeipa-2.99.0GIT8ce7330/daemons/ipa-sam' /bin/sh ../libtool --tag=CC --mode=compile gcc -DHAVE_CONFIG_H

Re: [Freeipa-devel] Build failure in ipa_sam

2012-06-28 Thread Alexander Bokovoy
On Thu, 28 Jun 2012, William Brown wrote: On 28/06/12 18:43, Alexander Bokovoy wrote: On Thu, 28 Jun 2012, William Brown wrote: Making all in ipa-sam make[4]: Entering directory `/home/william/development/freeipa/rpmbuild/BUILD/freeipa-2.99.0GIT8ce7330/daemons/ipa-sam' /bin/sh ../libtool

Re: [Freeipa-devel] [PATCH] Per-domain DNS update permissions

2012-06-28 Thread Martin Kosek
On 06/28/2012 11:20 AM, Petr Viktorin wrote: On 06/27/2012 06:01 PM, Petr Viktorin wrote: On 06/27/2012 02:50 PM, Martin Kosek wrote: On 06/25/2012 08:50 PM, Rob Crittenden wrote: Simo Sorce wrote: On Fri, 2012-06-22 at 14:25 +0200, Martin Kosek wrote: On 06/22/2012 02:23 PM, Simo Sorce

Re: [Freeipa-devel] [SOLVED] Build failure in ipa_sam

2012-06-28 Thread William Brown
On 28/06/12 19:35, Alexander Bokovoy wrote: On Thu, 28 Jun 2012, William Brown wrote: On 28/06/12 18:43, Alexander Bokovoy wrote: On Thu, 28 Jun 2012, William Brown wrote: Making all in ipa-sam make[4]: Entering directory

Re: [Freeipa-devel] [PATCH] 18 Add external domain extop DS plugin

2012-06-28 Thread Martin Kosek
On 06/28/2012 12:19 PM, Sumit Bose wrote: On Thu, Jun 28, 2012 at 09:52:14AM +0200, Martin Kosek wrote: On 06/27/2012 06:38 PM, Alexander Bokovoy wrote: On Wed, 27 Jun 2012, Sumit Bose wrote: On Wed, Jun 13, 2012 at 12:37:49PM +0200, Sumit Bose wrote: On Wed, Jun 13, 2012 at 12:26:43PM +0200,

Re: [Freeipa-devel] [PATCH] 18 Add external domain extop DS plugin

2012-06-28 Thread Martin Kosek
On 06/28/2012 01:09 PM, Martin Kosek wrote: On 06/28/2012 12:19 PM, Sumit Bose wrote: On Thu, Jun 28, 2012 at 09:52:14AM +0200, Martin Kosek wrote: On 06/27/2012 06:38 PM, Alexander Bokovoy wrote: On Wed, 27 Jun 2012, Sumit Bose wrote: On Wed, Jun 13, 2012 at 12:37:49PM +0200, Sumit Bose

Re: [Freeipa-devel] [PATCH] 18 Add external domain extop DS plugin

2012-06-28 Thread Sumit Bose
On Thu, Jun 28, 2012 at 01:51:28PM +0200, Martin Kosek wrote: On 06/28/2012 01:09 PM, Martin Kosek wrote: On 06/28/2012 12:19 PM, Sumit Bose wrote: On Thu, Jun 28, 2012 at 09:52:14AM +0200, Martin Kosek wrote: On 06/27/2012 06:38 PM, Alexander Bokovoy wrote: On Wed, 27 Jun 2012, Sumit

Re: [Freeipa-devel] [PATCH] External group membership for trusted domains

2012-06-28 Thread Alexander Bokovoy
On Wed, 27 Jun 2012, Alexander Bokovoy wrote: On Wed, 27 Jun 2012, Petr Viktorin wrote: On 06/27/2012 12:36 PM, Sumit Bose wrote: On Wed, Jun 27, 2012 at 12:56:56PM +0300, Alexander Bokovoy wrote: On Mon, 25 Jun 2012, Alexander Bokovoy wrote: On Mon, 25 Jun 2012, Sumit Bose wrote: Hi

Re: [Freeipa-devel] [PATCH] Filter groups in the PAC

2012-06-28 Thread Sumit Bose
On Wed, Jun 27, 2012 at 07:28:11PM +0300, Alexander Bokovoy wrote: On Tue, 26 Jun 2012, Sumit Bose wrote: Hi, this patch contains the KDC part of the external groups handling. If group SIDs from the PAC can be found in the ipaExternalGroup objects and the external groups are member of local

Re: [Freeipa-devel] [PATCH] External group membership for trusted domains

2012-06-28 Thread Petr Viktorin
On 06/28/2012 02:16 PM, Alexander Bokovoy wrote: On Wed, 27 Jun 2012, Alexander Bokovoy wrote: On Wed, 27 Jun 2012, Petr Viktorin wrote: On 06/27/2012 12:36 PM, Sumit Bose wrote: On Wed, Jun 27, 2012 at 12:56:56PM +0300, Alexander Bokovoy wrote: On Mon, 25 Jun 2012, Alexander Bokovoy wrote:

Re: [Freeipa-devel] [PATCH] External group membership for trusted domains

2012-06-28 Thread Alexander Bokovoy
On Thu, 28 Jun 2012, Petr Viktorin wrote: On 06/28/2012 02:16 PM, Alexander Bokovoy wrote: On Wed, 27 Jun 2012, Alexander Bokovoy wrote: On Wed, 27 Jun 2012, Petr Viktorin wrote: On 06/27/2012 12:36 PM, Sumit Bose wrote: On Wed, Jun 27, 2012 at 12:56:56PM +0300, Alexander Bokovoy wrote: On

Re: [Freeipa-devel] [PATCH] Per-domain DNS update permissions

2012-06-28 Thread Petr Viktorin
On 06/28/2012 12:53 PM, Martin Kosek wrote: On 06/28/2012 11:20 AM, Petr Viktorin wrote: On 06/27/2012 06:01 PM, Petr Viktorin wrote: On 06/27/2012 02:50 PM, Martin Kosek wrote: On 06/25/2012 08:50 PM, Rob Crittenden wrote: Simo Sorce wrote: On Fri, 2012-06-22 at 14:25 +0200, Martin Kosek

Re: [Freeipa-devel] [PATCH] Per-domain DNS update permissions

2012-06-28 Thread Martin Kosek
On 06/28/2012 03:20 PM, Petr Viktorin wrote: On 06/28/2012 12:53 PM, Martin Kosek wrote: On 06/28/2012 11:20 AM, Petr Viktorin wrote: On 06/27/2012 06:01 PM, Petr Viktorin wrote: On 06/27/2012 02:50 PM, Martin Kosek wrote: On 06/25/2012 08:50 PM, Rob Crittenden wrote: Simo Sorce wrote: On

Re: [Freeipa-devel] [PATCH] 162 Web UI password is going to expire in n days notification

2012-06-28 Thread Petr Vobornik
On 06/27/2012 04:33 PM, Petr Vobornik wrote: On 06/27/2012 03:54 AM, Endi Sukma Dewata wrote: On 6/26/2012 9:46 AM, Petr Vobornik wrote: This is patch is more like a draft. I'm not sure where to display the 'password is going to expire' notification. I was deciding between: 1) red bold text

Re: [Freeipa-devel] [PATCH] External group membership for trusted domains

2012-06-28 Thread Petr Viktorin
On 06/28/2012 02:58 PM, Alexander Bokovoy wrote: On Thu, 28 Jun 2012, Petr Viktorin wrote: On 06/28/2012 02:16 PM, Alexander Bokovoy wrote: On Wed, 27 Jun 2012, Alexander Bokovoy wrote: On Wed, 27 Jun 2012, Petr Viktorin wrote: On 06/27/2012 12:36 PM, Sumit Bose wrote: On Wed, Jun 27, 2012

Re: [Freeipa-devel] [PATCH] External group membership for trusted domains

2012-06-28 Thread Martin Kosek
On 06/28/2012 04:50 PM, Petr Viktorin wrote: On 06/28/2012 02:58 PM, Alexander Bokovoy wrote: On Thu, 28 Jun 2012, Petr Viktorin wrote: On 06/28/2012 02:16 PM, Alexander Bokovoy wrote: On Wed, 27 Jun 2012, Alexander Bokovoy wrote: On Wed, 27 Jun 2012, Petr Viktorin wrote: On 06/27/2012 12:36

[Freeipa-devel] [PATCH] [WIP] 281 Enable SOA serial autoincrement

2012-06-28 Thread Martin Kosek
This patch enables currently developed SOA serial autoincrement feature in bind-dyndb-ldap. The patch may be updated if any assumptions about this feature are changed (or somebody finds a bug). --- SOA serial autoincrement is a requirement for major DNS features, e.g. zone transfers or DNSSEC.

[Freeipa-devel] test_changepw is failing on master

2012-06-28 Thread John Dennis
tests/test_ipaserver/test_changepw.py is failing on master. Could someone who is familiar with the code take a look and see what's wrong. Thanks, John == FAIL:

Re: [Freeipa-devel] [PATCH] 163 Refactored association facet to use facet buttons with actions

2012-06-28 Thread Endi Sukma Dewata
On 6/27/2012 11:19 AM, Petr Vobornik wrote: Association facet was refactored to use new concept of control buttons. It is the last facet type which don't use this concept. It fixes regression introduced by previous refactoring of table facet (delete button was never enabled).

Re: [Freeipa-devel] [PATCH] 164 Continuation of removing of not supported command options from Web UI

2012-06-28 Thread Endi Sukma Dewata
On 6/27/2012 11:22 AM, Petr Vobornik wrote: This patch removes following non-existing command options: * all,rights in host_disable * record_type in dns_record_add * all,rights in various xxx_remove_xxx commands used in rule_association_table_field (removing association)

Re: [Freeipa-devel] [PATCH] 162 Web UI password is going to expire in n days notification

2012-06-28 Thread Endi Sukma Dewata
On 6/28/2012 8:59 AM, Petr Vobornik wrote: On 06/27/2012 04:33 PM, Petr Vobornik wrote: On 06/27/2012 03:54 AM, Endi Sukma Dewata wrote: On 6/26/2012 9:46 AM, Petr Vobornik wrote: This is patch is more like a draft. I'm not sure where to display the 'password is going to expire'

Re: [Freeipa-devel] [PATCH] 165 Display loginas information only after login

2012-06-28 Thread Endi Sukma Dewata
On 6/28/2012 9:07 AM, Petr Vobornik wrote: Message 'Logged in as: u...@freeipa.org' was displayed before user was logged in. It was wrong. Now 'Logged in as: XXX' is displayed only when user XXX is logged in. So no more u...@freeipa.org :) . https://fedorahosted.org/freeipa/ticket/2882 It