Re: [Freeipa-devel] FYI: Cert for https://www.freeipa.org/ is invalid

2014-06-26 Thread Rob Townley
StartSSL has free ssl certs. Very inexpensive wildcard certs ~$50.00. StartCom CA that has been trusted by browsers for years. On Jun 26, 2014 12:29 AM, James purplei...@gmail.com wrote: I think it's kind of funny that the cert for: https://www.freeipa.org/ is invalid, particularly since this

Re: [Freeipa-devel] FYI: Cert for https://www.freeipa.org/ is invalid

2014-06-26 Thread Alexander Bokovoy
On Thu, 26 Jun 2014, Rob Townley wrote: StartSSL has free ssl certs. Very inexpensive wildcard certs ~$50.00. StartCom CA that has been trusted by browsers for years. We have proper certificate in place. This looks like OpenShift's misconfiguration. -- / Alexander Bokovoy

Re: [Freeipa-devel] [PATCH 0236] ipaldap: Fallback to string if datetime conversion went wrong

2014-06-26 Thread Jan Cholasta
On 25.6.2014 18:25, Petr Viktorin wrote: On 06/25/2014 05:29 PM, Jan Cholasta wrote: Hi, On 25.6.2014 17:17, Tomas Babej wrote: Hi, Our datetime conversion does not support full LDAP Generalized time syntax. In the unsupported cases, we should fall back to string representation of the

Re: [Freeipa-devel] FYI: Cert for https://www.freeipa.org/ is invalid

2014-06-26 Thread Martin Kletzander
On Thu, Jun 26, 2014 at 01:23:44AM -0500, Rob Townley wrote: StartSSL has free ssl certs. Very inexpensive wildcard certs ~$50.00. StartCom CA that has been trusted by browsers for years. I've heard of free (or low-cost) SSL certs for open source software and there should be a company

Re: [Freeipa-devel] [PATCH 0236] ipaldap: Fallback to string if datetime conversion went wrong

2014-06-26 Thread Petr Viktorin
On 06/26/2014 08:30 AM, Jan Cholasta wrote: On 25.6.2014 18:25, Petr Viktorin wrote: On 06/25/2014 05:29 PM, Jan Cholasta wrote: Hi, On 25.6.2014 17:17, Tomas Babej wrote: Hi, Our datetime conversion does not support full LDAP Generalized time syntax. In the unsupported cases, we should

Re: [Freeipa-devel] [PATCHES 202-222] Ipaplatform refactoring

2014-06-26 Thread Petr Viktorin
On 06/25/2014 09:48 PM, Tomas Babej wrote: On 06/25/2014 09:35 PM, Petr Viktorin wrote: On 06/25/2014 07:16 PM, Tomas Babej wrote: On 06/25/2014 04:59 PM, Tomas Babej wrote: On 06/25/2014 04:13 PM, Tomas Babej wrote: On 06/25/2014 04:01 PM, Tomas Babej wrote: On 06/25/2014 10:48 AM,

Re: [Freeipa-devel] [PATCH 0236] ipaldap: Fallback to string if datetime conversion went wrong

2014-06-26 Thread Jan Cholasta
On 26.6.2014 09:21, Petr Viktorin wrote: On 06/26/2014 08:30 AM, Jan Cholasta wrote: On 25.6.2014 18:25, Petr Viktorin wrote: On 06/25/2014 05:29 PM, Jan Cholasta wrote: Hi, On 25.6.2014 17:17, Tomas Babej wrote: Hi, Our datetime conversion does not support full LDAP Generalized time

Re: [Freeipa-devel] [PATCH 0236] ipaldap: Fallback to string if datetime conversion went wrong

2014-06-26 Thread Petr Viktorin
On 06/26/2014 09:33 AM, Jan Cholasta wrote: On 26.6.2014 09:21, Petr Viktorin wrote: On 06/26/2014 08:30 AM, Jan Cholasta wrote: On 25.6.2014 18:25, Petr Viktorin wrote: On 06/25/2014 05:29 PM, Jan Cholasta wrote: Hi, On 25.6.2014 17:17, Tomas Babej wrote: Hi, Our datetime conversion does

Re: [Freeipa-devel] [PATCH 0229] dsinstance: Detect dynamic plugin support and restart server

2014-06-26 Thread Petr Viktorin
On 06/18/2014 05:14 PM, Tomas Babej wrote: Hi, With 389-ds-base 1.3.3. comes the dynamic plugin support. We need to restart the server right after modifying the schema, as the plugins will be enabled at the point they are added (and not at the next server restart). Properly handle both

Re: [Freeipa-devel] [PATCH 0236] ipaldap: Fallback to string if datetime conversion went wrong

2014-06-26 Thread Jan Cholasta
On 26.6.2014 09:40, Petr Viktorin wrote: On 06/26/2014 09:33 AM, Jan Cholasta wrote: On 26.6.2014 09:21, Petr Viktorin wrote: On 06/26/2014 08:30 AM, Jan Cholasta wrote: On 25.6.2014 18:25, Petr Viktorin wrote: On 06/25/2014 05:29 PM, Jan Cholasta wrote: Hi, On 25.6.2014 17:17, Tomas Babej

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-26 Thread Martin Kosek
On 06/26/2014 04:29 AM, Nathaniel McCallum wrote: On Mon, 2014-06-23 at 17:24 -0400, Nathaniel McCallum wrote: On Mon, 2014-06-23 at 14:35 -0400, Simo Sorce wrote: - Original Message - - Original Message - Can you check if ipaProtectedOperation is in the aci attribute in the

Re: [Freeipa-devel] [PATCH 0236] ipaldap: Fallback to string if datetime conversion went wrong

2014-06-26 Thread Petr Viktorin
On 06/26/2014 10:33 AM, Jan Cholasta wrote: On 26.6.2014 09:40, Petr Viktorin wrote: On 06/26/2014 09:33 AM, Jan Cholasta wrote: On 26.6.2014 09:21, Petr Viktorin wrote: On 06/26/2014 08:30 AM, Jan Cholasta wrote: On 25.6.2014 18:25, Petr Viktorin wrote: On 06/25/2014 05:29 PM, Jan Cholasta

Re: [Freeipa-devel] FYI: Cert for https://www.freeipa.org/ is invalid

2014-06-26 Thread Martin Kosek
On 06/26/2014 07:28 AM, James wrote: I think it's kind of funny that the cert for: https://www.freeipa.org/ is invalid, particularly since this is a security product. In any case, feel free to forward to whoever maintains this in case someone thinks it matters. Cheers, James You are of

Re: [Freeipa-devel] [PATCH 0236] ipaldap: Fallback to string if datetime conversion went wrong

2014-06-26 Thread Jan Cholasta
On 26.6.2014 10:39, Petr Viktorin wrote: On 06/26/2014 10:33 AM, Jan Cholasta wrote: On 26.6.2014 09:40, Petr Viktorin wrote: On 06/26/2014 09:33 AM, Jan Cholasta wrote: On 26.6.2014 09:21, Petr Viktorin wrote: On 06/26/2014 08:30 AM, Jan Cholasta wrote: On 25.6.2014 18:25, Petr Viktorin

[Freeipa-devel] [Freeipa-interest] Announcing bind-dyndb-ldap version 5.0

2014-06-26 Thread Petr Spacek
The FreeIPA team is proud to announce bind-dyndb-ldap version 5.0. It can be downloaded from https://fedorahosted.org/released/bind-dyndb-ldap/ The new version has also been built for Fedora 20 and and is on its way to updates-testing:

Re: [Freeipa-devel] [PATCH] 302 Do not corrupt sshd_config in client install when trailing newline is missing

2014-06-26 Thread Martin Kosek
On 06/18/2014 03:56 PM, Jan Cholasta wrote: Hi, the attached patch fixes https://fedorahosted.org/freeipa/ticket/4373. Honza Works fine, tested with # perl -i -pe 'chomp if eof' /etc/ssh/sshd_config trick. ACK, pushed to master. Martin ___

Re: [Freeipa-devel] [PATCH] 676 rpcserver: fix local vs utc time comparison

2014-06-26 Thread Petr Vobornik
On 25.6.2014 17:36, Jan Cholasta wrote: Hi, On 24.6.2014 16:02, Petr Vobornik wrote: login_password did not work properly in timezones other than +0h because local time was compared with utc time. ACK. pushed to master: 1c94edd3a09711d85ba099bd815c0bdd8f0210c1 rpcserver: fix local vs utc

Re: [Freeipa-devel] [PATCH] 302 Do not corrupt sshd_config in client install when trailing newline is missing

2014-06-26 Thread Petr Viktorin
On 06/26/2014 12:18 PM, Martin Kosek wrote: On 06/18/2014 03:56 PM, Jan Cholasta wrote: Hi, the attached patch fixes https://fedorahosted.org/freeipa/ticket/4373. Honza Works fine, tested with # perl -i -pe 'chomp if eof' /etc/ssh/sshd_config trick. ACK, pushed to master. Martin It

Re: [Freeipa-devel] [PATCH] 659-666 Support of password reset with OTP

2014-06-26 Thread Petr Vobornik
On 25.6.2014 19:41, Endi Sukma Dewata wrote: On 6/20/2014 10:18 AM, Petr Vobornik wrote: On 11.6.2014 15:19, Petr Vobornik wrote: Patch set contains both API/server and Web UI parts. [PATCH] 659 ldap2: add otp support to modify_password [PATCH] 660 rpcserver: add otp support to

Re: [Freeipa-devel] [PATCH 0058] Add the otptoken-add-yubikey command

2014-06-26 Thread Alexander Bokovoy
On Wed, 25 Jun 2014, Nathaniel McCallum wrote: On Wed, 2014-06-25 at 09:53 -0400, Nathaniel McCallum wrote: On Wed, 2014-06-25 at 13:35 +0300, Alexander Bokovoy wrote: On Mon, 23 Jun 2014, Nathaniel McCallum wrote: On Mon, 2014-06-23 at 10:29 +0300, Alexander Bokovoy wrote: On Fri, 20 Jun

Re: [Freeipa-devel] [PATCH 0055] Add /session/token_sync POST support

2014-06-26 Thread Alexander Bokovoy
On Wed, 25 Jun 2014, Nathaniel McCallum wrote: On Wed, 2014-06-25 at 13:21 +0300, Alexander Bokovoy wrote: On Tue, 24 Jun 2014, Nathaniel McCallum wrote: On Mon, 2014-06-02 at 23:07 -0400, Nathaniel McCallum wrote: This HTTP call takes the following parameters: * user * password *

Re: [Freeipa-devel] [PATCH 0056] Add otptoken-sync command

2014-06-26 Thread Alexander Bokovoy
On Wed, 25 Jun 2014, Nathaniel McCallum wrote: On Wed, 2014-06-25 at 13:18 +0300, Alexander Bokovoy wrote: On Tue, 24 Jun 2014, Nathaniel McCallum wrote: On Tue, 2014-06-03 at 09:18 -0400, Nathaniel McCallum wrote: On Tue, 2014-06-03 at 10:27 +0200, Petr Vobornik wrote: On 3.6.2014 05:08,

Re: [Freeipa-devel] [PATCH] 302 Do not corrupt sshd_config in client install when trailing newline is missing

2014-06-26 Thread Jan Cholasta
On 26.6.2014 12:43, Petr Viktorin wrote: On 06/26/2014 12:18 PM, Martin Kosek wrote: On 06/18/2014 03:56 PM, Jan Cholasta wrote: Hi, the attached patch fixes https://fedorahosted.org/freeipa/ticket/4373. Honza Works fine, tested with # perl -i -pe 'chomp if eof' /etc/ssh/sshd_config trick.

Re: [Freeipa-devel] [PATCH 0078-0079] DNSEC: Add TLSA record

2014-06-26 Thread Petr Vobornik
On 25.6.2014 14:35, Martin Basti wrote: On Wed, 2014-06-25 at 14:31 +0200, Martin Basti wrote: Ticket https://fedorahosted.org/freeipa/ticket/4328#comment:12 Patches attached. Note: ACI will be updated in another patch which fix ACIs in DNS plugin Patches are here What are patch 0078's

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-26 Thread Alexander Bokovoy
On Thu, 26 Jun 2014, Martin Kosek wrote: On 06/26/2014 04:29 AM, Nathaniel McCallum wrote: On Mon, 2014-06-23 at 17:24 -0400, Nathaniel McCallum wrote: On Mon, 2014-06-23 at 14:35 -0400, Simo Sorce wrote: - Original Message - - Original Message - Can you check if

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-26 Thread Tomas Babej
On 06/26/2014 02:33 PM, Alexander Bokovoy wrote: On Thu, 26 Jun 2014, Martin Kosek wrote: On 06/26/2014 04:29 AM, Nathaniel McCallum wrote: On Mon, 2014-06-23 at 17:24 -0400, Nathaniel McCallum wrote: On Mon, 2014-06-23 at 14:35 -0400, Simo Sorce wrote: - Original Message - -

Re: [Freeipa-devel] [PATCHES] 295-299 Allow changing chaining of the IPA CA certificate

2014-06-26 Thread Jan Cholasta
On 16.6.2014 15:35, Jan Cholasta wrote: Hi, the attached patches implement https://fedorahosted.org/freeipa/ticket/3737. My patches 241-253 and 262-294 are required for this (http://www.redhat.com/archives/freeipa-devel/2014-June/msg00276.html,

Re: [Freeipa-devel] [PATCH 0055] Add /session/token_sync POST support

2014-06-26 Thread Martin Kosek
On 06/26/2014 01:01 PM, Alexander Bokovoy wrote: On Wed, 25 Jun 2014, Nathaniel McCallum wrote: On Wed, 2014-06-25 at 13:21 +0300, Alexander Bokovoy wrote: On Tue, 24 Jun 2014, Nathaniel McCallum wrote: On Mon, 2014-06-02 at 23:07 -0400, Nathaniel McCallum wrote: This HTTP call takes the

[Freeipa-devel] [PATCH] 691 webui-ci: fix action list action visibility and enablement assertion

2014-06-26 Thread Petr Vobornik
Fixes CA-less CI test fail The new html structure was not addressed properly. -- Petr Vobornik From a0e2e83470d1ca2c5f6f286e59588b10eb5f75bc Mon Sep 17 00:00:00 2001 From: Petr Vobornik pvobo...@redhat.com Date: Thu, 26 Jun 2014 14:38:05 +0200 Subject: [PATCH] webui-ci: fix action list action

Re: [Freeipa-devel] [PATCH 0056] Add otptoken-sync command

2014-06-26 Thread Martin Kosek
On 06/26/2014 01:02 PM, Alexander Bokovoy wrote: On Wed, 25 Jun 2014, Nathaniel McCallum wrote: On Wed, 2014-06-25 at 13:18 +0300, Alexander Bokovoy wrote: On Tue, 24 Jun 2014, Nathaniel McCallum wrote: On Tue, 2014-06-03 at 09:18 -0400, Nathaniel McCallum wrote: On Tue, 2014-06-03 at 10:27

Re: [Freeipa-devel] [PATCH 0058] Add the otptoken-add-yubikey command

2014-06-26 Thread Martin Kosek
On 06/25/2014 03:53 PM, Nathaniel McCallum wrote: On Wed, 2014-06-25 at 13:35 +0300, Alexander Bokovoy wrote: On Mon, 23 Jun 2014, Nathaniel McCallum wrote: On Mon, 2014-06-23 at 10:29 +0300, Alexander Bokovoy wrote: On Fri, 20 Jun 2014, Nathaniel McCallum wrote: On Thu, 2014-06-19 at 16:30

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-26 Thread Simo Sorce
On Thu, 2014-06-26 at 15:33 +0300, Alexander Bokovoy wrote: On Thu, 26 Jun 2014, Martin Kosek wrote: On 06/26/2014 04:29 AM, Nathaniel McCallum wrote: On Mon, 2014-06-23 at 17:24 -0400, Nathaniel McCallum wrote: On Mon, 2014-06-23 at 14:35 -0400, Simo Sorce wrote: - Original Message

Re: [Freeipa-devel] [PATCHES] 267-294 Support multiple CA certificates in LDAP

2014-06-26 Thread Rob Crittenden
Comments buried deep inline. Jan Cholasta wrote: On 16.6.2014 22:36, Rob Crittenden wrote: Rob Crittenden wrote: Jan Cholasta wrote: Hi, the attached patches implement https://fedorahosted.org/freeipa/ticket/3259 and https://fedorahosted.org/freeipa/ticket/3520. This work depends on my

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-26 Thread Simo Sorce
On Thu, 2014-06-26 at 10:20 -0400, Simo Sorce wrote: On Thu, 2014-06-26 at 15:33 +0300, Alexander Bokovoy wrote: On Thu, 26 Jun 2014, Martin Kosek wrote: On 06/26/2014 04:29 AM, Nathaniel McCallum wrote: On Mon, 2014-06-23 at 17:24 -0400, Nathaniel McCallum wrote: On Mon, 2014-06-23 at

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-26 Thread Simo Sorce
On Thu, 2014-06-26 at 10:37 +0200, Martin Kosek wrote: On 06/26/2014 04:29 AM, Nathaniel McCallum wrote: On Mon, 2014-06-23 at 17:24 -0400, Nathaniel McCallum wrote: On Mon, 2014-06-23 at 14:35 -0400, Simo Sorce wrote: - Original Message - - Original Message - Can you

Re: [Freeipa-devel] [PATCHES] 295-299 Allow changing chaining of the IPA CA certificate

2014-06-26 Thread Rob Crittenden
Jan Cholasta wrote: On 16.6.2014 15:35, Jan Cholasta wrote: Hi, the attached patches implement https://fedorahosted.org/freeipa/ticket/3737. My patches 241-253 and 262-294 are required for this (http://www.redhat.com/archives/freeipa-devel/2014-June/msg00276.html,

Re: [Freeipa-devel] [PATCHES] 241-253 CA certificate renewal

2014-06-26 Thread Rob Crittenden
Jan Cholasta wrote: On 12.6.2014 09:49, Jan Cholasta wrote: On 20.5.2014 21:38, Rob Crittenden wrote: Jan Cholasta wrote: On 25.4.2014 10:51, Jan Cholasta wrote: On 24.4.2014 23:16, Rob Crittenden wrote: Jan Cholasta wrote: On 10.4.2014 22:06, Rob Crittenden wrote: Some in-line, a whole

Re: [Freeipa-devel] [PATCH] 678-679 webui: send API version in RPC requests and adapt to new response format

2014-06-26 Thread Endi Sukma Dewata
On 6/25/2014 8:51 AM, Petr Vobornik wrote: ticket: https://fedorahosted.org/freeipa/ticket/4394 == [PATCH] 678 webui: send API version in RPC requests == Currently there is an incorrect behavior that server doesn't send datetime and dnsname data in new format. This patch adds the version to

Re: [Freeipa-devel] [PATCH] 670-675 webui: dns forward zones

2014-06-26 Thread Endi Sukma Dewata
On 6/24/2014 9:39 AM, Petr Vobornik wrote: On 24.6.2014 13:02, Petr Vobornik wrote: ticket: https://fedorahosted.org/freeipa/ticket/4357 - patch 673 is compressed - CI patches functionally depends on #667, #668 == PATCH] 670 webui: add confirmation for dns zone permission actions == All