Re: [Freeipa-devel] Supported Staged entries

2014-05-28 Thread Martin Kosek
On 05/27/2014 08:18 PM, Simo Sorce wrote: On Tue, 2014-05-27 at 21:14 +0300, Alexander Bokovoy wrote: On Tue, 27 May 2014, Simo Sorce wrote: On Tue, 2014-05-27 at 19:59 +0200, thierry bordaz wrote: On 05/27/2014 06:56 PM, Simo Sorce wrote: On Tue, 2014-05-27 at 18:39 +0200, thierry bordaz

Re: [Freeipa-devel] [PATCH] 6 - Dogtag DRM -IPA plugin

2014-05-28 Thread Fraser Tweedale
On Tue, May 27, 2014 at 05:57:40PM -0400, Ade Lee wrote: There have been a couple of changes in the Dogtag interface, that require some changes in the IPA patches. Also, I had to add back a function in order to rebase to the latest IPA code. Most are the patches are as before, attached to

[Freeipa-devel] running out of entropy during ipa-server-install

2014-05-28 Thread Fraser Tweedale
Hi all, Today I hit the WARNING: Your system is running out of entropy, you may experience long delays message while testing Ade's ipa-server-install changes. I got a lot more entropy a lot faster by installing haveged(8), and I blogged about it here:

Re: [Freeipa-devel] Supported Staged entries

2014-05-28 Thread thierry bordaz
On 05/28/2014 08:22 AM, Martin Kosek wrote: On 05/27/2014 08:18 PM, Simo Sorce wrote: On Tue, 2014-05-27 at 21:14 +0300, Alexander Bokovoy wrote: On Tue, 27 May 2014, Simo Sorce wrote: On Tue, 2014-05-27 at 19:59 +0200, thierry bordaz wrote: On 05/27/2014 06:56 PM, Simo Sorce wrote: On Tue,

Re: [Freeipa-devel] running out of entropy during ipa-server-install

2014-05-28 Thread Petr Viktorin
On 05/28/2014 09:06 AM, Fraser Tweedale wrote: Hi all, Today I hit the WARNING: Your system is running out of entropy, you may experience long delays message while testing Ade's ipa-server-install changes. I got a lot more entropy a lot faster by installing haveged(8), and I blogged about it

Re: [Freeipa-devel] [PATCH 0257] Fix race condition during zone loading

2014-05-28 Thread Tomas Hozza
On 05/27/2014 03:59 PM, Petr Spacek wrote: On 27.5.2014 15:54, Petr Spacek wrote: Fix race condition during zone loading. DNS zone has to be added to DNS view before dns_zone_load() is called. It is necessary to prevent dns_zone_load() from racing with dns_zone_setview(). This race

Re: [Freeipa-devel] running out of entropy during ipa-server-install

2014-05-28 Thread Martin Kosek
On 05/28/2014 12:08 PM, Petr Viktorin wrote: On 05/28/2014 09:06 AM, Fraser Tweedale wrote: Hi all, Today I hit the WARNING: Your system is running out of entropy, you may experience long delays message while testing Ade's ipa-server-install changes. I got a lot more entropy a lot faster

Re: [Freeipa-devel] #4054 - ACIs for managing own hosts, users, groups...

2014-05-28 Thread Martin Kosek
On 04/16/2014 03:42 PM, Simo Sorce wrote: On Wed, 2014-04-16 at 14:55 +0200, Martin Kosek wrote: On 04/16/2014 02:49 PM, Petr Viktorin wrote: On 04/16/2014 02:45 PM, Simo Sorce wrote: On Wed, 2014-04-16 at 10:20 +0200, Petr Viktorin wrote: On 04/16/2014 10:02 AM, Martin Kosek wrote: I was

Re: [Freeipa-devel] [PATCH 0029-0046, 0047] Internationalized domain names in DNS plugin

2014-05-28 Thread Martin Basti
On Mon, 2014-05-26 at 10:33 +0200, Martin Kosek wrote: freeipa-server-foreman-smartproxy# [ 40%] It works for me. I install 3.5, upgrade to 4.0 and it works -- Martin^2 Basti ___ Freeipa-devel mailing list

Re: [Freeipa-devel] [PATCH 0029-0046, 0047] Internationalized domain names in DNS plugin

2014-05-28 Thread Martin Kosek
On 05/28/2014 01:50 PM, Martin Basti wrote: On Mon, 2014-05-26 at 10:33 +0200, Martin Kosek wrote: freeipa-server-foreman-smartproxy# [ 40%] It works for me. I install 3.5, upgrade to 4.0 and it works Ok, thanks for testing - I might have improperly

Re: [Freeipa-devel] [PATCH 0029-0046, 0047] Internationalized domain names in DNS plugin

2014-05-28 Thread Martin Basti
On Wed, 2014-05-28 at 13:56 +0200, Martin Kosek wrote: On 05/28/2014 01:50 PM, Martin Basti wrote: On Mon, 2014-05-26 at 10:33 +0200, Martin Kosek wrote: freeipa-server-foreman-smartproxy# [ 40%] It works for me. I install 3.5, upgrade to 4.0 and it

Re: [Freeipa-devel] [PATCH 0029-0046, 0047] Internationalized domain names in DNS plugin

2014-05-28 Thread Martin Basti
On Wed, 2014-05-28 at 13:56 +0200, Martin Kosek wrote: On 05/28/2014 01:50 PM, Martin Basti wrote: On Mon, 2014-05-26 at 10:33 +0200, Martin Kosek wrote: freeipa-server-foreman-smartproxy# [ 40%] It works for me. I install 3.5, upgrade to 4.0 and it

Re: [Freeipa-devel] [PATCH] 0557 pwpolicy-mod: Fix crash when priority is changed

2014-05-28 Thread Martin Kosek
On 05/27/2014 01:27 PM, Petr Viktorin wrote: See the ticket commit message. https://fedorahosted.org/freeipa/ticket/4309 Yup, this fixed the crash. ACK! Martin ___ Freeipa-devel mailing list Freeipa-devel@redhat.com

Re: [Freeipa-devel] [PATCH] 0543 - dns: Add idnsSecInlineSigning attribute, add --dnssec option to zone

2014-05-28 Thread Martin Kosek
On 05/26/2014 12:48 PM, Petr Viktorin wrote: On 05/14/2014 12:50 PM, Petr Viktorin wrote: On 04/30/2014 10:00 AM, thierry bordaz wrote: On 04/29/2014 10:07 PM, Martin Kosek wrote: On 04/29/2014 08:17 PM, Simo Sorce wrote: On Tue, 2014-04-29 at 20:00 +0200, Petr Viktorin wrote: This adds the

Re: [Freeipa-devel] Supported Staged entries

2014-05-28 Thread Simo Sorce
On Wed, 2014-05-28 at 09:38 +0200, thierry bordaz wrote: On 05/28/2014 08:22 AM, Martin Kosek wrote: On 05/27/2014 08:18 PM, Simo Sorce wrote: On Tue, 2014-05-27 at 21:14 +0300, Alexander Bokovoy wrote: On Tue, 27 May 2014, Simo Sorce wrote: On Tue, 2014-05-27 at 19:59 +0200, thierry

Re: [Freeipa-devel] Supported Staged entries

2014-05-28 Thread Rob Crittenden
Simo Sorce wrote: On Wed, 2014-05-28 at 09:38 +0200, thierry bordaz wrote: On 05/28/2014 08:22 AM, Martin Kosek wrote: On 05/27/2014 08:18 PM, Simo Sorce wrote: On Tue, 2014-05-27 at 21:14 +0300, Alexander Bokovoy wrote: On Tue, 27 May 2014, Simo Sorce wrote: On Tue, 2014-05-27 at 19:59

Re: [Freeipa-devel] Supported Staged entries

2014-05-28 Thread thierry bordaz
On 05/28/2014 02:55 PM, Rob Crittenden wrote: Simo Sorce wrote: On Wed, 2014-05-28 at 09:38 +0200, thierry bordaz wrote: On 05/28/2014 08:22 AM, Martin Kosek wrote: On 05/27/2014 08:18 PM, Simo Sorce wrote: On Tue, 2014-05-27 at 21:14 +0300, Alexander Bokovoy wrote: On Tue, 27 May 2014,

[Freeipa-devel] [PATCHES] 0558-0561 Read ACI fixes

2014-05-28 Thread Petr Viktorin
Hello, Some of IPA plugins assume that everyone has access to everything. Here are some fixes for that. Patch 0560 adds a new permission for the UPG Definition, which is required to add users correctly. -- PetrĀ³ From 1846d12939dbfc209aeca30820642d1565da6fd1 Mon Sep 17 00:00:00 2001 From:

Re: [Freeipa-devel] Supported Staged entries

2014-05-28 Thread Martin Kosek
On 05/28/2014 02:48 PM, Simo Sorce wrote: On Wed, 2014-05-28 at 09:38 +0200, thierry bordaz wrote: On 05/28/2014 08:22 AM, Martin Kosek wrote: On 05/27/2014 08:18 PM, Simo Sorce wrote: On Tue, 2014-05-27 at 21:14 +0300, Alexander Bokovoy wrote: On Tue, 27 May 2014, Simo Sorce wrote: On Tue,

Re: [Freeipa-devel] [PATCH] 0557 pwpolicy-mod: Fix crash when priority is changed

2014-05-28 Thread Petr Viktorin
On 05/28/2014 02:44 PM, Martin Kosek wrote: On 05/27/2014 01:27 PM, Petr Viktorin wrote: See the ticket commit message. https://fedorahosted.org/freeipa/ticket/4309 Yup, this fixed the crash. ACK! Martin Thanks, pushed to master: 8bbd52e347f3e6395d469528e1220fd9158e5609 -- PetrĀ³

Re: [Freeipa-devel] [PATCH] 6 - Dogtag DRM -IPA plugin

2014-05-28 Thread Petr Viktorin
On 05/28/2014 08:48 AM, Fraser Tweedale wrote: On Tue, May 27, 2014 at 05:57:40PM -0400, Ade Lee wrote: There have been a couple of changes in the Dogtag interface, that require some changes in the IPA patches. Also, I had to add back a function in order to rebase to the latest IPA code. Most

Re: [Freeipa-devel] [PATCH] 0543 - dns: Add idnsSecInlineSigning attribute, add --dnssec option to zone

2014-05-28 Thread Petr Viktorin
On 05/28/2014 02:45 PM, Martin Kosek wrote: On 05/26/2014 12:48 PM, Petr Viktorin wrote: On 05/14/2014 12:50 PM, Petr Viktorin wrote: On 04/30/2014 10:00 AM, thierry bordaz wrote: On 04/29/2014 10:07 PM, Martin Kosek wrote: On 04/29/2014 08:17 PM, Simo Sorce wrote: On Tue, 2014-04-29 at

Re: [Freeipa-devel] [PATCHES] 0540-0542 Add managed read permissions to user

2014-05-28 Thread Petr Viktorin
On 05/27/2014 05:13 PM, Simo Sorce wrote: On Tue, 2014-05-27 at 18:01 +0300, Alexander Bokovoy wrote: On Tue, 27 May 2014, Petr Viktorin wrote: On 05/26/2014 12:13 PM, Petr Viktorin wrote: [...] Thanks for the thorough review! Pushed to master: 63becae88c6c270b98f0432dc474b661b82f3119

Re: [Freeipa-devel] Supported Staged entries

2014-05-28 Thread Martin Kosek
On 05/28/2014 03:06 PM, thierry bordaz wrote: On 05/28/2014 02:55 PM, Rob Crittenden wrote: Simo Sorce wrote: On Wed, 2014-05-28 at 09:38 +0200, thierry bordaz wrote: On 05/28/2014 08:22 AM, Martin Kosek wrote: On 05/27/2014 08:18 PM, Simo Sorce wrote: On Tue, 2014-05-27 at 21:14 +0300,

Re: [Freeipa-devel] [PATCHES] 0552-0554 Upgrading write permissions

2014-05-28 Thread Petr Viktorin
On 05/27/2014 04:20 PM, Martin Kosek wrote: On 05/26/2014 04:44 PM, Petr Viktorin wrote: On 05/22/2014 03:07 PM, Petr Viktorin wrote: Hello, Here I start upgrading the existing default permissions to the new Managed style. https://fedorahosted.org/freeipa/ticket/4346 The patches rely on my

Re: [Freeipa-devel] Supported Staged entries

2014-05-28 Thread Simo Sorce
On Wed, 2014-05-28 at 15:56 +0200, Martin Kosek wrote: On 05/28/2014 02:48 PM, Simo Sorce wrote: On Wed, 2014-05-28 at 09:38 +0200, thierry bordaz wrote: On 05/28/2014 08:22 AM, Martin Kosek wrote: On 05/27/2014 08:18 PM, Simo Sorce wrote: On Tue, 2014-05-27 at 21:14 +0300, Alexander

Re: [Freeipa-devel] [PATCHES] 0552-0554 Upgrading write permissions

2014-05-28 Thread Simo Sorce
On Wed, 2014-05-28 at 16:27 +0200, Petr Viktorin wrote: Simo, I hazily remember discussing that we should only allow specific attributes on add, otherwise users can add entries with any extra objectclasses and attributes. Did we come to a conclusion? I might have confused targetattr with

Re: [Freeipa-devel] [PATCHES] 0552-0554 Upgrading write permissions

2014-05-28 Thread Martin Kosek
On 05/28/2014 04:50 PM, Simo Sorce wrote: On Wed, 2014-05-28 at 16:27 +0200, Petr Viktorin wrote: Simo, I hazily remember discussing that we should only allow specific attributes on add, otherwise users can add entries with any extra objectclasses and attributes. Did we come to a conclusion?

Re: [Freeipa-devel] [PATCHES] 0552-0554 Upgrading write permissions

2014-05-28 Thread Ludwig Krispenz
On 05/28/2014 04:56 PM, Martin Kosek wrote: On 05/28/2014 04:50 PM, Simo Sorce wrote: On Wed, 2014-05-28 at 16:27 +0200, Petr Viktorin wrote: Simo, I hazily remember discussing that we should only allow specific attributes on add, otherwise users can add entries with any extra objectclasses

Re: [Freeipa-devel] [PATCHES] 0552-0554 Upgrading write permissions

2014-05-28 Thread Martin Kosek
On 05/28/2014 05:03 PM, Ludwig Krispenz wrote: On 05/28/2014 04:56 PM, Martin Kosek wrote: On 05/28/2014 04:50 PM, Simo Sorce wrote: On Wed, 2014-05-28 at 16:27 +0200, Petr Viktorin wrote: Simo, I hazily remember discussing that we should only allow specific attributes on add, otherwise

Re: [Freeipa-devel] [PATCHES] 0552-0554 Upgrading write permissions

2014-05-28 Thread Ludwig Krispenz
On 05/28/2014 05:08 PM, Martin Kosek wrote: On 05/28/2014 05:03 PM, Ludwig Krispenz wrote: On 05/28/2014 04:56 PM, Martin Kosek wrote: On 05/28/2014 04:50 PM, Simo Sorce wrote: On Wed, 2014-05-28 at 16:27 +0200, Petr Viktorin wrote: Simo, I hazily remember discussing that we should only

Re: [Freeipa-devel] [PATCHES] 0552-0554 Upgrading write permissions

2014-05-28 Thread Martin Kosek
On 05/28/2014 05:13 PM, Ludwig Krispenz wrote: On 05/28/2014 05:08 PM, Martin Kosek wrote: On 05/28/2014 05:03 PM, Ludwig Krispenz wrote: On 05/28/2014 04:56 PM, Martin Kosek wrote: On 05/28/2014 04:50 PM, Simo Sorce wrote: On Wed, 2014-05-28 at 16:27 +0200, Petr Viktorin wrote: Simo, I

Re: [Freeipa-devel] [PATCHES] 0052-0055 Separate master and forward DNS zones to separate objectClasses

2014-05-28 Thread Martin Basti
On Wed, 2014-05-28 at 18:48 +0200, Martin Basti wrote: Ticket: https://fedorahosted.org/freeipa/ticket/3210 Patches attached. TODO: upgrade procedure http://www.freeipa.org/page/V4/Forward_zones#Updates_and_Upgrades WebUI ticket: https://fedorahosted.org/freeipa/ticket/4357

Re: [Freeipa-devel] Supported Staged entries

2014-05-28 Thread Rob Crittenden
Simo Sorce wrote: On Wed, 2014-05-28 at 15:56 +0200, Martin Kosek wrote: On 05/28/2014 02:48 PM, Simo Sorce wrote: On Wed, 2014-05-28 at 09:38 +0200, thierry bordaz wrote: On 05/28/2014 08:22 AM, Martin Kosek wrote: On 05/27/2014 08:18 PM, Simo Sorce wrote: On Tue, 2014-05-27 at 21:14 +0300,

Re: [Freeipa-devel] [PATCH 0257] Fix race condition during zone loading

2014-05-28 Thread Petr Spacek
On 28.5.2014 13:26, Tomas Hozza wrote: On 05/27/2014 03:59 PM, Petr Spacek wrote: On 27.5.2014 15:54, Petr Spacek wrote: Fix race condition during zone loading. DNS zone has to be added to DNS view before dns_zone_load() is called. It is necessary to prevent dns_zone_load() from racing with

Re: [Freeipa-devel] running out of entropy during ipa-server-install

2014-05-28 Thread Fraser Tweedale
On Wed, May 28, 2014 at 01:38:05PM +0200, Martin Kosek wrote: On 05/28/2014 12:08 PM, Petr Viktorin wrote: On 05/28/2014 09:06 AM, Fraser Tweedale wrote: Hi all, Today I hit the WARNING: Your system is running out of entropy, you may experience long delays message while testing Ade's

Re: [Freeipa-devel] [PATCH] 6 - Dogtag DRM -IPA plugin

2014-05-28 Thread Fraser Tweedale
On Wed, May 28, 2014 at 03:53:01PM +0200, Petr Viktorin wrote: On 05/28/2014 08:48 AM, Fraser Tweedale wrote: On Tue, May 27, 2014 at 05:57:40PM -0400, Ade Lee wrote: There have been a couple of changes in the Dogtag interface, that require some changes in the IPA patches. Also, I had to add

Re: [Freeipa-devel] User life cycle: plugins scope for staged users

2014-05-28 Thread Dmitri Pal
On 05/22/2014 10:33 AM, thierry bordaz wrote: Hello, In order to provision staged users (account inactivated) with there initial values: /usr/bin/ipa user-add tb20 --to-stage --first=tb20 --last=tb20 - Added user tb20 -

Re: [Freeipa-devel] Supported Staged entries

2014-05-28 Thread Dmitri Pal
On 05/27/2014 12:39 PM, thierry bordaz wrote: On 05/27/2014 06:06 PM, Simo Sorce wrote: On Tue, 2014-05-27 at 17:55 +0200, thierry bordaz wrote: On 05/27/2014 04:35 PM, Martin Kosek wrote: On 05/27/2014 04:27 PM, Simo Sorce wrote: On Tue, 2014-05-27 at 15:21 +0200, Martin Kosek wrote: This

Re: [Freeipa-devel] Supported Staged entries

2014-05-28 Thread Dmitri Pal
On 05/28/2014 01:18 PM, Rob Crittenden wrote: Simo Sorce wrote: On Wed, 2014-05-28 at 15:56 +0200, Martin Kosek wrote: On 05/28/2014 02:48 PM, Simo Sorce wrote: On Wed, 2014-05-28 at 09:38 +0200, thierry bordaz wrote: On 05/28/2014 08:22 AM, Martin Kosek wrote: On 05/27/2014 08:18 PM, Simo

Re: [Freeipa-devel] Supported Staged entries

2014-05-28 Thread Dmitri Pal
On 05/28/2014 10:50 PM, Dmitri Pal wrote: On 05/28/2014 01:18 PM, Rob Crittenden wrote: Simo Sorce wrote: On Wed, 2014-05-28 at 15:56 +0200, Martin Kosek wrote: On 05/28/2014 02:48 PM, Simo Sorce wrote: On Wed, 2014-05-28 at 09:38 +0200, thierry bordaz wrote: On 05/28/2014 08:22 AM, Martin

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-28 Thread Dmitri Pal
On 05/23/2014 01:01 PM, Simo Sorce wrote: On Fri, 2014-05-23 at 17:47 +0200, thierry bordaz wrote: About membership. I think it could be risky to keep membership in 'delete' or 'stage'. Those entries are not valid user and should not belong to any active group. Should we keep membership

Re: [Freeipa-devel] [RFC] Migrating existing environments to Trust

2014-05-28 Thread Simo Sorce
On Wed, 2014-05-28 at 23:15 -0400, Dmitri Pal wrote: On 05/27/2014 03:52 PM, Simo Sorce wrote: On Tue, 2014-05-27 at 16:01 +0200, Sumit Bose wrote: On Tue, Apr 15, 2014 at 11:13:38AM +0200, Sumit Bose wrote: Hi, I have started to write a design page for 'Migrating existing

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-28 Thread Dmitri Pal
On 05/26/2014 01:49 AM, Martin Kosek wrote: On 05/23/2014 04:55 PM, Simo Sorce wrote: On Fri, 2014-05-23 at 10:13 -0400, Rob Crittenden wrote: This, I believe, has already been covered, but I'm concerned with the (over)use of active/inactive in this discussion. I think use of inactive and

[Freeipa-devel] ipa-server-install error

2014-05-28 Thread James
Hi, Can anyone decipher this log and help me understand what is broken and how to fix it? What is more peculiar is that I don't get the problem on an older version of CentOS 6.5, but on the latest up to date version it breaks. Note that I am using the latest versions of all the ipa-server