Re: [Freeipa-devel] [RFE] Remove source hosts from HBAC

2013-04-08 Thread Petr Vobornik
On 04/05/2013 07:59 PM, Ana Krivokapic wrote: Hello list, I have been thinking about the possible implementation for a solution of ticket https://fedorahosted.org/freeipa/ticket/3528. There are several options: 1. Completely remove the commands and command options related to source hosts in

Re: [Freeipa-devel] [PATCH] 1094 fix 2 broken tests

2013-04-08 Thread Ana Krivokapic
On 04/05/2013 10:30 PM, Rob Crittenden wrote: Two tests are failing due to missing attributes since the krb ticket flags patch was pushed. rob ___ Freeipa-devel mailing list Freeipa-devel@redhat.com

Re: [Freeipa-devel] Confused by some messages

2013-04-08 Thread Petr Viktorin
On 04/06/2013 11:05 PM, Jérôme Fenal wrote: Same for: Issued on from Issued on to Revoked on from Revoked on to Valid not after from Valid not after to Valid not before from Valid not before to All inipalib/plugins/internal.py around line 330 These are UI labels for the options below.

Re: [Freeipa-devel] Order of updates

2013-04-08 Thread Martin Kosek
On 04/05/2013 10:38 PM, Rob Crittenden wrote: We've had a few problems with permissions come up over the last couple of months and I finally sat down to identify what the problem is (this can be seen sometimes where some unit tests fail). We do some membership manipulation in the updates

Re: [Freeipa-devel] Confused by some messages

2013-04-08 Thread Jérôme Fenal
Ah OK, in the context of a search, that indeed makes more sense ;) Thanks! J. 2013/4/8 Petr Viktorin pvikt...@redhat.com On 04/06/2013 11:05 PM, Jérôme Fenal wrote: Same for: Issued on from Issued on to Revoked on from Revoked on to Valid not after from Valid not after to Valid not

[Freeipa-devel] [PATCH] 123

2013-04-08 Thread Jan Cholasta
Hi, this patch fixes https://fedorahosted.org/freeipa/ticket/3552. Honza -- Jan Cholasta From 629ac8ce5471c9fb92403cfb8b2f1feceae91a0d Mon Sep 17 00:00:00 2001 From: Jan Cholasta jchol...@redhat.com Date: Mon, 8 Apr 2013 10:20:00 +0200 Subject: [PATCH] Use http instead of https for OCSP and

Re: [Freeipa-devel] [PATCH 0027] Add checks for SELinux in install scripts

2013-04-08 Thread Tomas Babej
On 04/05/2013 07:43 PM, Rob Crittenden wrote: Tomas Babej wrote: On 04/04/2013 04:25 PM, Rob Crittenden wrote: Tomas Babej wrote: On Tue 02 Apr 2013 10:05:06 AM CEST, Tomas Babej wrote: On Mon 01 Apr 2013 10:01:14 PM CEST, Rob Crittenden wrote: Tomas Babej wrote: On Tue 19 Feb 2013

[Freeipa-devel] [PATCH] 0012 Fix output for some CLI commands

2013-04-08 Thread Ana Krivokapic
Hello, This patch addresses https://fedorahosted.org/freeipa/ticket/3503. See the commit message for details. -- Regards, Ana Krivokapic Associate Software Engineer FreeIPA team Red Hat Inc. From 25b94d35f4958bda8bc435494a357be13d209f26 Mon Sep 17 00:00:00 2001 From: Ana Krivokapic

Re: [Freeipa-devel] [RFE] Remove source hosts from HBAC

2013-04-08 Thread Rob Crittenden
Petr Vobornik wrote: On 04/05/2013 07:59 PM, Ana Krivokapic wrote: Hello list, I have been thinking about the possible implementation for a solution of ticket https://fedorahosted.org/freeipa/ticket/3528. There are several options: 1. Completely remove the commands and command options related

Re: [Freeipa-devel] [RFE] Remove source hosts from HBAC

2013-04-08 Thread Martin Kosek
On 04/08/2013 03:03 PM, Rob Crittenden wrote: Petr Vobornik wrote: On 04/05/2013 07:59 PM, Ana Krivokapic wrote: Hello list, I have been thinking about the possible implementation for a solution of ticket https://fedorahosted.org/freeipa/ticket/3528. There are several options: 1.

Re: [Freeipa-devel] [RFE] Remove source hosts from HBAC

2013-04-08 Thread Petr Vobornik
On 04/08/2013 03:03 PM, Rob Crittenden wrote: Petr Vobornik wrote: On 04/05/2013 07:59 PM, Ana Krivokapic wrote: Hello list, I have been thinking about the possible implementation for a solution of ticket https://fedorahosted.org/freeipa/ticket/3528. There are several options: 1. Completely

Re: [Freeipa-devel] [RFE] Remove source hosts from HBAC

2013-04-08 Thread Rob Crittenden
Petr Vobornik wrote: On 04/08/2013 03:03 PM, Rob Crittenden wrote: Petr Vobornik wrote: On 04/05/2013 07:59 PM, Ana Krivokapic wrote: Hello list, I have been thinking about the possible implementation for a solution of ticket https://fedorahosted.org/freeipa/ticket/3528. There are several

Re: [Freeipa-devel] [PATCH] 0012 Fix output for some CLI commands

2013-04-08 Thread Jan Cholasta
Hi, On 8.4.2013 13:40, Ana Krivokapic wrote: Hello, This patch addresses https://fedorahosted.org/freeipa/ticket/3503. See the commit message for details. the patch seems OK, I will just run the test suite to make sure you didn't miss anything. Honza -- Jan Cholasta

Re: [Freeipa-devel] [PATCH] WIP backup and restore

2013-04-08 Thread Petr Viktorin
On 04/05/2013 10:54 PM, Rob Crittenden wrote: Petr Viktorin wrote: On 04/04/2013 03:04 PM, Rob Crittenden wrote: Rob Crittenden wrote: Petr Viktorin wrote: On 03/23/2013 05:06 AM, Rob Crittenden wrote: There are strict limits on what can be restored where. Only exact matching hostnames and

Re: [Freeipa-devel] [PATCH] 0012 Fix output for some CLI commands

2013-04-08 Thread Petr Viktorin
On 04/08/2013 01:40 PM, Ana Krivokapic wrote: Hello, This patch addresseshttps://fedorahosted.org/freeipa/ticket/3503. See the commit message for details. -- Regards, Ana Krivokapic Associate Software Engineer FreeIPA team Red Hat Inc.

Re: [Freeipa-devel] [PATCH] 123 Use http instead of https for OCSP and CRL URLs in IPA certificate profile

2013-04-08 Thread Dmitri Pal
On 04/08/2013 08:42 AM, Martin Kosek wrote: On 04/08/2013 10:48 AM, Jan Cholasta wrote: On 8.4.2013 10:47, Jan Cholasta wrote: Hi, this patch fixes https://fedorahosted.org/freeipa/ticket/3552. Honza Re-sending with correct subject. I tested the change both for upgrades and for fresh

Re: [Freeipa-devel] [PATCH 0034] Deny LDAP binds for user accounts with expired principal

2013-04-08 Thread Martin Kosek
On 04/01/2013 09:52 PM, Rob Crittenden wrote: Tomas Babej wrote: On 02/12/2013 06:23 PM, Simo Sorce wrote: On Tue, 2013-02-12 at 18:03 +0100, Tomas Babej wrote: On 02/12/2013 05:50 PM, Tomas Babej wrote: Hi, This patch adds a check for krbprincipalexpiration attribute to pre_bind operation

[Freeipa-devel] [PATCH 0044] Update only selected attributes for winsync agreement

2013-04-08 Thread Tomas Babej
Hi, Trying to insert nsDS5ReplicatedAttributeListTotal and nsds5ReplicaStripAttrs to winsync agreements caused upgrade errors. With this patch, these attributes are skipped for winsync agreements. Made find_ipa_replication_agreements() in replication.py more corresponding to

Re: [Freeipa-devel] [RFE] Remove source hosts from HBAC

2013-04-08 Thread Dmitri Pal
On 04/08/2013 09:37 AM, Rob Crittenden wrote: Petr Vobornik wrote: On 04/08/2013 03:03 PM, Rob Crittenden wrote: Petr Vobornik wrote: On 04/05/2013 07:59 PM, Ana Krivokapic wrote: Hello list, I have been thinking about the possible implementation for a solution of ticket

Re: [Freeipa-devel] [PATCH] 0012 Fix output for some CLI commands

2013-04-08 Thread Jan Cholasta
On 8.4.2013 15:41, Jan Cholasta wrote: Hi, On 8.4.2013 13:40, Ana Krivokapic wrote: Hello, This patch addresses https://fedorahosted.org/freeipa/ticket/3503. See the commit message for details. the patch seems OK, I will just run the test suite to make sure you didn't miss anything. Honza

Re: [Freeipa-devel] [PATCH] 123 Use http instead of https for OCSP and CRL URLs in IPA certificate profile

2013-04-08 Thread Martin Kosek
On 04/08/2013 03:47 PM, Dmitri Pal wrote: On 04/08/2013 08:42 AM, Martin Kosek wrote: On 04/08/2013 10:48 AM, Jan Cholasta wrote: On 8.4.2013 10:47, Jan Cholasta wrote: Hi, this patch fixes https://fedorahosted.org/freeipa/ticket/3552. Honza Re-sending with correct subject. I tested

Re: [Freeipa-devel] [PATCH] 122 Enable SASL mapping fallback

2013-04-08 Thread Jan Cholasta
On 4.4.2013 22:44, Rob Crittenden wrote: This patch works well enough against a devel build at http://nkinder.fedorapeople.org/389-devel/ without the Requires on 1.3.1 (the devel build still claims to be 1.3.0.5). I bumped Requires because https://fedorahosted.org/389/ticket/534 says it is

Re: [Freeipa-devel] [PATCH] 122 Enable SASL mapping fallback

2013-04-08 Thread Rob Crittenden
Jan Cholasta wrote: On 4.4.2013 22:44, Rob Crittenden wrote: This patch works well enough against a devel build at http://nkinder.fedorapeople.org/389-devel/ without the Requires on 1.3.1 (the devel build still claims to be 1.3.0.5). I bumped Requires because

[Freeipa-devel] FreeIPA string freeze

2013-04-08 Thread Petr Viktorin
Hello, FreeIPA translators! We wanted to give enough time for translations, so we made an upstream string freeze last week, giving about two weeks of translation time until the beta. We didn't expect most of the translations to be done already -- Ukrainian at 100% and French with 40 strings

Re: [Freeipa-devel] [PATCH] 0012 Fix output for some CLI commands

2013-04-08 Thread Ana Krivokapic
On 04/08/2013 04:33 PM, Jan Cholasta wrote: On 8.4.2013 15:41, Jan Cholasta wrote: Hi, On 8.4.2013 13:40, Ana Krivokapic wrote: Hello, This patch addresses https://fedorahosted.org/freeipa/ticket/3503. See the commit message for details. the patch seems OK, I will just run the test

Re: [Freeipa-devel] FreeIPA string freeze

2013-04-08 Thread Yuri Chornoivan
написане Mon, 08 Apr 2013 18:45:30 +0300, Petr Viktorin pvikt...@redhat.com: Hello, FreeIPA translators! We wanted to give enough time for translations, so we made an upstream string freeze last week, giving about two weeks of translation time until the beta. We didn't expect most of the

Re: [Freeipa-devel] [RFE] Remove source hosts from HBAC

2013-04-08 Thread Rob Crittenden
Dmitri Pal wrote: On 04/08/2013 09:37 AM, Rob Crittenden wrote: Petr Vobornik wrote: On 04/08/2013 03:03 PM, Rob Crittenden wrote: Petr Vobornik wrote: On 04/05/2013 07:59 PM, Ana Krivokapic wrote: Hello list, I have been thinking about the possible implementation for a solution of ticket

[Freeipa-devel] [PATCH 0140] Fix crash caused by zone deletion

2013-04-08 Thread Petr Spacek
Hello, Fix crash caused by zone deletion. I found that that I pushed patch bind-dyndb-ldap-pspacek-0126-Add-support-for-pure-forward-zones-idnsForwardZone-o.patch instead of bind-dyndb-ldap-pspacek-0126-2-Add-support-for-pure-forward-zones-idnsForwardZone-o.patch Attached patch is only

[Freeipa-devel] [PATCH 0141] Generalize attribute_name-rdata_type conversions.

2013-04-08 Thread Petr Spacek
Hello, Generalize attribute_name-rdata_type conversions. Attribute names are generated on-the-fly: String Record is appended to textual representation of DNS RDATA type. String Record is cut down from the attribute name during attribute name to rdata type conversion. From now, the plugin

Re: [Freeipa-devel] [RFE] Remove source hosts from HBAC

2013-04-08 Thread Dmitri Pal
On 04/08/2013 01:30 PM, Rob Crittenden wrote: Dmitri Pal wrote: On 04/08/2013 09:37 AM, Rob Crittenden wrote: Petr Vobornik wrote: On 04/08/2013 03:03 PM, Rob Crittenden wrote: Petr Vobornik wrote: On 04/05/2013 07:59 PM, Ana Krivokapic wrote: Hello list, I have been thinking about the