[Freeipa-devel] [PATCH] 0146: ipa-kdb: do not fetch client principal if it is the same

2014-03-06 Thread Alexander Bokovoy
Hi! Attached patch should fix the issue raised by Sumit when reviewing my patch 0145. Additionally, it fixes reverted condition check for case when we didn't find client_princ in the database, preventing a memory leak. Martin, you wanted to create a bug for this, so I didn't add the ticket

Re: [Freeipa-devel] [PATCH] 0488 tests: Create the testing service certificate on demand

2014-03-06 Thread Jan Cholasta
On 5.3.2014 17:38, Petr Viktorin wrote: Hello, This transforms the make-testcert command into a module that creates the certificate when it is first needed. As a result the tests are more self-contained, and can be run from a read-only location (such as from the freeipa-tests package). Works

Re: [Freeipa-devel] [PATCHES] [RFC] New getkeytab operation: why not to use kadmin protocol?

2014-03-06 Thread Petr Spacek
On 5.3.2014 23:18, Simo Sorce wrote: Thanks for reading this far :-) I will bikeshed this thread a little bit: Can we use kadmin protocol instead of the proprietary LDAP control? If I remember correctly one of objections was that we do not allow admin to read the key but it is not true

Re: [Freeipa-devel] [PATCHES] [RFC] New getkeytab operation: why not to use kadmin protocol?

2014-03-06 Thread Petr Spacek
On 5.3.2014 23:18, Simo Sorce wrote: Thanks for reading this far :-) I will bikeshed this thread a little bit: Can we use kadmin protocol instead of the proprietary LDAP control? If I remember correctly one of objections was that we do not allow admin to read the key but it is not true

Re: [Freeipa-devel] [PATCH] 0488 tests: Create the testing service certificate on demand

2014-03-06 Thread Petr Viktorin
On 03/06/2014 09:46 AM, Jan Cholasta wrote: On 5.3.2014 17:38, Petr Viktorin wrote: Hello, This transforms the make-testcert command into a module that creates the certificate when it is first needed. As a result the tests are more self-contained, and can be run from a read-only location (such

Re: [Freeipa-devel] [PATCH] 0146: ipa-kdb: do not fetch client principal if it is the same

2014-03-06 Thread Sumit Bose
On Thu, Mar 06, 2014 at 10:32:44AM +0200, Alexander Bokovoy wrote: Hi! Attached patch should fix the issue raised by Sumit when reviewing my patch 0145. Additionally, it fixes reverted condition check for case when we didn't find client_princ in the database, preventing a memory leak.

[Freeipa-devel] [PATCH] 0147: ipaserver/rpcserver: catch ACIError and return proper message for out-of-realm users

2014-03-06 Thread Alexander Bokovoy
Hi, we had similar issue in past, in jsonserver_session() class, fixed by 0292ebd1 which Tomas did for ticket https://fedorahosted.org/freeipa/ticket/3252 This one is for non-sessioned call: https://fedorahosted.org/freeipa/ticket/4225 -- / Alexander Bokovoy From

Re: [Freeipa-devel] [PATCH] 0146: ipa-kdb: do not fetch client principal if it is the same

2014-03-06 Thread Martin Kosek
On 03/06/2014 11:01 AM, Sumit Bose wrote: On Thu, Mar 06, 2014 at 10:32:44AM +0200, Alexander Bokovoy wrote: Hi! Attached patch should fix the issue raised by Sumit when reviewing my patch 0145. Additionally, it fixes reverted condition check for case when we didn't find client_princ in

Re: [Freeipa-devel] [PATCH] 546 webui: Datetime parsing and formatting

2014-03-06 Thread Misnyovszki Adam
On Tue, 25 Feb 2014 18:05:28 +0100 Petr Vobornik pvobo...@redhat.com wrote: prerequisite for patch 547, 548 depends on tbabej's datetime patch this patch implements: - output_formatter in field. It should be used in par with formatter. Formatter serves for datasource-widget conversion,

Re: [Freeipa-devel] [PATCH] 546 webui: Datetime parsing and formatting

2014-03-06 Thread Petr Vobornik
On 6.3.2014 13:01, Misnyovszki Adam wrote: On Tue, 25 Feb 2014 18:05:28 +0100 Petr Vobornik pvobo...@redhat.com wrote: prerequisite for patch 547, 548 depends on tbabej's datetime patch this patch implements: - output_formatter in field. It should be used in par with formatter. Formatter

Re: [Freeipa-devel] [PATCHES] [RFC] New getkeytab operation: why not to use kadmin protocol?

2014-03-06 Thread Simo Sorce
On Thu, 2014-03-06 at 09:50 +0100, Petr Spacek wrote: On 5.3.2014 23:18, Simo Sorce wrote: Thanks for reading this far :-) I will bikeshed this thread a little bit: Can we use kadmin protocol instead of the proprietary LDAP control? You know, you already made the same question last year

Re: [Freeipa-devel] DNSSEC design page: key wrapping

2014-03-06 Thread Jakub Hrozek
On Wed, Mar 05, 2014 at 05:56:25PM +0100, Jan Cholasta wrote: On 5.3.2014 16:02, Petr Spacek wrote: On 5.3.2014 14:21, Simo Sorce wrote: On Wed, 2014-03-05 at 10:53 +0100, Petr Spacek wrote: On 5.3.2014 08:48, Jan Cholasta wrote: On 5.3.2014 05:10, Simo Sorce wrote: On Tue, 2014-03-04 at