Re: [Freeipa-devel] [PATCH 0238] ipaldap: Override conversion of nsds5replicalastupdatestart

2014-07-02 Thread Jan Cholasta
On 1.7.2014 16:45, Tomas Babej wrote: Hi, The replication related attributes nsds5replicalastupdatestart and nsds5replicalastupdateend have special behaviour implemented in 389, as follows: In case they are explicitly requested for and not set, 0 is returned. However, 0 is not a valid value

Re: [Freeipa-devel] [PATCH] 692 webui: capitalize labels of undo and undo all buttons

2014-07-02 Thread Martin Kosek
On 07/02/2014 07:11 AM, Fraser Tweedale wrote: On Mon, Jun 30, 2014 at 10:54:28AM +0200, Petr Vobornik wrote: On 30.6.2014 09:13, Fraser Tweedale wrote: On Fri, Jun 27, 2014 at 02:11:47PM +0200, Petr Vobornik wrote: Make the label of these buttons consistent with other buttons which have

Re: [Freeipa-devel] [PATCHES 0084-0086] NSEC3PARAM DNS record should be in DNS zone settings

2014-07-02 Thread Petr Viktorin
On 07/01/2014 03:15 PM, Martin Basti wrote: On Tue, 2014-07-01 at 14:24 +0200, Martin Basti wrote: Ticket: https://fedorahosted.org/freeipa/ticket/4413 Patches attached Rebased patches attached 0084: in dns.py, you'll also want to remove NSEC3PARAMRecord from _dns_records. Otherwise I

Re: [Freeipa-devel] [PATCH 0087] Fix: missing tlsarecord in 40-dns.update

2014-07-02 Thread Petr Spacek
On 1.7.2014 17:28, Martin Basti wrote: Patch attached I'm not able to apply it on top of current master (21e1e4ac3bd62c20c6331ea3dc09793e3a869c22). -- Petr^2 Spacek ___ Freeipa-devel mailing list Freeipa-devel@redhat.com

Re: [Freeipa-devel] [PATCH] 692 webui: capitalize labels of undo and undo all buttons

2014-07-02 Thread Petr Viktorin
On 07/02/2014 08:52 AM, Martin Kosek wrote: On 07/02/2014 07:11 AM, Fraser Tweedale wrote: On Mon, Jun 30, 2014 at 10:54:28AM +0200, Petr Vobornik wrote: On 30.6.2014 09:13, Fraser Tweedale wrote: On Fri, Jun 27, 2014 at 02:11:47PM +0200, Petr Vobornik wrote: Make the label of these buttons

Re: [Freeipa-devel] [PATCH 0087] Fix: missing tlsarecord in 40-dns.update

2014-07-02 Thread Martin Basti
On Wed, 2014-07-02 at 09:40 +0200, Petr Spacek wrote: On 1.7.2014 17:28, Martin Basti wrote: Patch attached I'm not able to apply it on top of current master (21e1e4ac3bd62c20c6331ea3dc09793e3a869c22). Sorry I lost myself in ACIs, it depends on the patch mbasti-0084-2 and 0085-2 --

Re: [Freeipa-devel] [PATCH 0087] Fix: missing tlsarecord in 40-dns.update

2014-07-02 Thread Petr Spacek
On 2.7.2014 10:23, Martin Basti wrote: On Wed, 2014-07-02 at 09:40 +0200, Petr Spacek wrote: On 1.7.2014 17:28, Martin Basti wrote: Patch attached I'm not able to apply it on top of current master (21e1e4ac3bd62c20c6331ea3dc09793e3a869c22). Sorry I lost myself in ACIs, it depends on the

Re: [Freeipa-devel] [PATCHES 0084-0086] NSEC3PARAM DNS record should be in DNS zone settings

2014-07-02 Thread Petr Vobornik
On 1.7.2014 15:15, Martin Basti wrote: On Tue, 2014-07-01 at 14:24 +0200, Martin Basti wrote: Ticket: https://fedorahosted.org/freeipa/ticket/4413 Patches attached Rebased patches attached Besides #1, mostly minor stuff. 1. The regex r'^\d+ \d+ \d+ ([0-9a-fA-F]+|-)$' should be extended to

Re: [Freeipa-devel] [PATCH 0238] ipaldap: Override conversion of nsds5replicalastupdatestart

2014-07-02 Thread Petr Viktorin
On 07/02/2014 08:14 AM, Jan Cholasta wrote: On 1.7.2014 16:45, Tomas Babej wrote: Hi, The replication related attributes nsds5replicalastupdatestart and nsds5replicalastupdateend have special behaviour implemented in 389, as follows: In case they are explicitly requested for and not set, 0 is

[Freeipa-devel] [PATCH 0088] Use documentation addresses in dns help

2014-07-02 Thread Martin Basti
Patch attached. (Forward zones help preparation) -- Martin^2 Basti From c27017724dcce01d3ba901dc81c129c699952a44 Mon Sep 17 00:00:00 2001 From: Martin Basti mba...@redhat.com Date: Wed, 2 Jul 2014 12:52:14 +0200 Subject: [PATCH] Use documentation addresses in dns help --- ipalib/plugins/dns.py

Re: [Freeipa-devel] [PATCH 0088] Use documentation addresses in dns help

2014-07-02 Thread Petr Viktorin
On 07/02/2014 01:02 PM, Martin Basti wrote: Patch attached. (Forward zones help preparation) /me sighs This will invalidate all translations of the DNS plugin help. Is it really necessary for 4.0? -- Petr³ ___ Freeipa-devel mailing list

Re: [Freeipa-devel] [PATCHES 0084-0086] NSEC3PARAM DNS record should be in DNS zone settings

2014-07-02 Thread Martin Basti
On Wed, 2014-07-02 at 09:39 +0200, Petr Viktorin wrote: On 07/01/2014 03:15 PM, Martin Basti wrote: On Tue, 2014-07-01 at 14:24 +0200, Martin Basti wrote: Ticket: https://fedorahosted.org/freeipa/ticket/4413 Patches attached Rebased patches attached 0084: in dns.py, you'll

Re: [Freeipa-devel] [PATCH 0088] Use documentation addresses in dns help

2014-07-02 Thread Martin Basti
On Wed, 2014-07-02 at 13:09 +0200, Petr Viktorin wrote: On 07/02/2014 01:02 PM, Martin Basti wrote: Patch attached. (Forward zones help preparation) /me sighs This will invalidate all translations of the DNS plugin help. Is it really necessary for 4.0? Ask petr2, but I have ticket

Re: [Freeipa-devel] [PATCH 0088] Use documentation addresses in dns help

2014-07-02 Thread Petr Viktorin
On 07/02/2014 01:43 PM, Martin Basti wrote: On Wed, 2014-07-02 at 13:09 +0200, Petr Viktorin wrote: On 07/02/2014 01:02 PM, Martin Basti wrote: Patch attached. (Forward zones help preparation) /me sighs This will invalidate all translations of the DNS plugin help. Is it really necessary

Re: [Freeipa-devel] [PATCHES 0084-0086] NSEC3PARAM DNS record should be in DNS zone settings

2014-07-02 Thread Martin Basti
On Wed, 2014-07-02 at 13:17 +0200, Martin Basti wrote: On Wed, 2014-07-02 at 09:39 +0200, Petr Viktorin wrote: On 07/01/2014 03:15 PM, Martin Basti wrote: On Tue, 2014-07-01 at 14:24 +0200, Martin Basti wrote: Ticket: https://fedorahosted.org/freeipa/ticket/4413 Patches attached

Re: [Freeipa-devel] [PATCHES 0084-0086] NSEC3PARAM DNS record should be in DNS zone settings

2014-07-02 Thread Petr Vobornik
On 2.7.2014 14:27, Martin Basti wrote: On Wed, 2014-07-02 at 13:17 +0200, Martin Basti wrote: On Wed, 2014-07-02 at 09:39 +0200, Petr Viktorin wrote: On 07/01/2014 03:15 PM, Martin Basti wrote: On Tue, 2014-07-01 at 14:24 +0200, Martin Basti wrote: Ticket:

Re: [Freeipa-devel] [PATCH 0083] Add DNSSEC experimental support warning message

2014-07-02 Thread Martin Basti
On Tue, 2014-07-01 at 12:23 +0200, Petr Spacek wrote: On 1.7.2014 12:20, Martin Kosek wrote: On 07/01/2014 10:55 AM, Petr Spacek wrote: On 1.7.2014 10:49, Petr Viktorin wrote: On 07/01/2014 10:43 AM, Petr Spacek wrote: On 30.6.2014 17:10, Martin Basti wrote: On Mon, 2014-06-30 at 16:57

[Freeipa-devel] [PATCH 0089] Add help about forward zones

2014-07-02 Thread Martin Basti
Required patch: mbasti-0088 Patch attached I will split docstring after ACK -- Martin^2 Basti From 52af35570fad39941a69952163b9a2d9e724746d Mon Sep 17 00:00:00 2001 From: Martin Basti mba...@redhat.com Date: Wed, 2 Jul 2014 12:16:48 +0200 Subject: [PATCH] Help for forward zones Ticket:

Re: [Freeipa-devel] [PATCH 0083] Add DNSSEC experimental support warning message

2014-07-02 Thread Petr Spacek
On 2.7.2014 14:57, Martin Basti wrote: On Tue, 2014-07-01 at 12:23 +0200, Petr Spacek wrote: On 1.7.2014 12:20, Martin Kosek wrote: On 07/01/2014 10:55 AM, Petr Spacek wrote: On 1.7.2014 10:49, Petr Viktorin wrote: On 07/01/2014 10:43 AM, Petr Spacek wrote: On 30.6.2014 17:10, Martin Basti

Re: [Freeipa-devel] [PATCH 0083] Add DNSSEC experimental support warning message

2014-07-02 Thread Martin Basti
On Wed, 2014-07-02 at 15:21 +0200, Petr Spacek wrote: On 2.7.2014 14:57, Martin Basti wrote: On Tue, 2014-07-01 at 12:23 +0200, Petr Spacek wrote: On 1.7.2014 12:20, Martin Kosek wrote: On 07/01/2014 10:55 AM, Petr Spacek wrote: On 1.7.2014 10:49, Petr Viktorin wrote: On 07/01/2014

Re: [Freeipa-devel] [PATCH 0089] Add help about forward zones

2014-07-02 Thread Petr Spacek
I have only few nitpicks I didn't notice in the first round: The original proposal contained also this header: SUPPORTED ZONE TYPES * Master zone (dnszone-*) contains authoritative data. * Forward zone (dnsforwardzone-*) forwards queries to configured forwarders (a set of DNS servers). I

[Freeipa-devel] [PATCH] 0153 ipa-ldap-updater does not work with hardened LDAP configuration

2014-07-02 Thread Alexander Bokovoy
When nsslapd-minssf is greater than 0, running as root ipa-ldap-updater [-l] will fail even if we force use of autobind for root over LDAPI. The reason for this is that schema updater doesn't get ldapi flag passed and attempts to connect to LDAP port instead and for hardened configurations

Re: [Freeipa-devel] [PATCH 0238] ipaldap: Override conversion of nsds5replicalastupdatestart

2014-07-02 Thread Martin Kosek
On 07/02/2014 08:14 AM, Jan Cholasta wrote: On 1.7.2014 16:45, Tomas Babej wrote: Hi, The replication related attributes nsds5replicalastupdatestart and nsds5replicalastupdateend have special behaviour implemented in 389, as follows: In case they are explicitly requested for and not set, 0

[Freeipa-devel] [PATCH] 694 webui: new navigation structure

2014-07-02 Thread Petr Vobornik
https://fedorahosted.org/freeipa/ticket/4418 according to latest proposal:http://www.redhat.com/archives/freeipa-devel/2014-June/msg00839.html -- Petr Vobornik From 97cc94163e8ae57058b07741c7d70e44697c113f Mon Sep 17 00:00:00 2001 From: Petr Vobornik pvobo...@redhat.com Date: Wed, 2 Jul 2014

Re: [Freeipa-devel] [PATCH 0238] ipaldap: Override conversion of nsds5replicalastupdatestart

2014-07-02 Thread Martin Kosek
On 07/02/2014 12:49 PM, Petr Viktorin wrote: On 07/02/2014 08:14 AM, Jan Cholasta wrote: On 1.7.2014 16:45, Tomas Babej wrote: Hi, The replication related attributes nsds5replicalastupdatestart and nsds5replicalastupdateend have special behaviour implemented in 389, as follows: In case

[Freeipa-devel] [PATCH 0090] Split dns.py doctring

2014-07-02 Thread Martin Basti
Required patches mbasti-0088, mbasti-0089-2 Patch attached -- Martin^2 Basti From f2b31bb820f6995d2b285f1f487afa4aca5139af Mon Sep 17 00:00:00 2001 From: Martin Basti mba...@redhat.com Date: Wed, 2 Jul 2014 15:56:29 +0200 Subject: [PATCH] Split dns docstring --- ipalib/plugins/dns.py | 94

Re: [Freeipa-devel] [PATCH 0089] Add help about forward zones

2014-07-02 Thread Martin Basti
On Wed, 2014-07-02 at 15:46 +0200, Petr Spacek wrote: I have only few nitpicks I didn't notice in the first round: The original proposal contained also this header: SUPPORTED ZONE TYPES * Master zone (dnszone-*) contains authoritative data. * Forward zone (dnsforwardzone-*) forwards

Re: [Freeipa-devel] [PATCH] 0589 Do not fail if there are multiple nsDS5ReplicaId values in cn=replication, cn=etc

2014-07-02 Thread Martin Kosek
On 06/18/2014 01:21 PM, Petr Viktorin wrote: https://fedorahosted.org/freeipa/ticket/4375 Yup, works like a charm, ACK. Pushed to master: 8c98561c209d0ccaa692a335e3e9a10aec23ee0e Martin ___ Freeipa-devel mailing list Freeipa-devel@redhat.com

Re: [Freeipa-devel] [PATCHES] 295-299 Allow changing chaining of the IPA CA certificate

2014-07-02 Thread Jan Cholasta
On 28.6.2014 00:19, Rob Crittenden wrote: I'm going to consolidate all reviews for 241 - 303 here. I'm not doing this in any particular order. OK, I will send further patches only in this thread. Missing man page for ipa-certupdate I did not want to delay the patch, so I have

[Freeipa-devel] [PATCH] test_ipaserver: Add OTP token test data to ipatests package

2014-07-02 Thread Petr Viktorin
Hello, Some data is not put in the ipatests package. This prevents OTP token import tests from passing when run out of tree. Fix included. -- Petr³ From 51b894668d4c940deca006d069335f8e446a954e Mon Sep 17 00:00:00 2001 From: Petr Viktorin pvikt...@redhat.com Date: Wed, 2 Jul 2014 16:35:27

Re: [Freeipa-devel] [PATCHES 0080-0081] DNSSEC: Add experimental support for DNSSEC

2014-07-02 Thread Petr Spacek
On 27.6.2014 17:11, Martin Basti wrote: Ticket: https://fedorahosted.org/freeipa/ticket/4408 Patches attached. Both patches works for me. I have tested clean installation and upgrade from 3.3.5. -- Petr^2 Spacek ___ Freeipa-devel mailing list

[Freeipa-devel] [PATCH] 0614 test_ipagetkeytab: Fix expected error message

2014-07-02 Thread Petr Viktorin
It looks like ipa-getkeytab error message for a non-existent service changed. Simo, is this expected? Is the new message final, or should we just check for the PrincipalName not found. substring? -- Petr³ From f4c2b789efcdc5c9c9f33de89040b042bfe2898d Mon Sep 17 00:00:00 2001 From: Petr

Re: [Freeipa-devel] [PATCHES 0080-0081] DNSSEC: Add experimental support for DNSSEC

2014-07-02 Thread Petr Viktorin
On 07/02/2014 06:25 PM, Petr Spacek wrote: On 27.6.2014 17:11, Martin Basti wrote: Ticket: https://fedorahosted.org/freeipa/ticket/4408 Patches attached. Both patches works for me. I have tested clean installation and upgrade from 3.3.5. Code looks okay, pushed to master:

Re: [Freeipa-devel] [PATCHES] 295-299 Allow changing chaining of the IPA CA certificate

2014-07-02 Thread Rob Crittenden
Jan Cholasta wrote: On 28.6.2014 00:19, Rob Crittenden wrote: I'm going to consolidate all reviews for 241 - 303 here. I'm not doing this in any particular order. Trimming to respond to your questions. Not sure if this is related: # pki cert-find PKIException: Internal Server Error I'm

Re: [Freeipa-devel] [PATCHES] 295-299 Allow changing chaining of the IPA CA certificate

2014-07-02 Thread Jan Cholasta
On 2.7.2014 19:08, Rob Crittenden wrote: Trimming to respond to your questions. Not sure if this is related: # pki cert-find PKIException: Internal Server Error I'm pretty sure the cert-find error is related to the fact that I had a test build of dogtag installed, so that can be ignored. It