[Freeipa-devel] [PATCH 0368-0371] Support LDAP MODRDN for ordinary DNS records

2015-05-20 Thread Petr Spacek
Hello, this patchset implements support for MODRDN for ordinary records. As noted in ticket https://fedorahosted.org/bind-dyndb-ldap/ticket/123, we agreed yesterday that renaming zones is out of scope and seems unnecessarily complex. This patch set depends on 'metadb' branch. It is also

Re: [Freeipa-devel] [PATCHES 0001-0007] Profile management

2015-05-20 Thread Jan Cholasta
Dne 20.5.2015 v 07:56 Fraser Tweedale napsal(a): On Wed, May 20, 2015 at 07:40:44AM +0200, Jan Cholasta wrote: Dne 19.5.2015 v 13:50 Fraser Tweedale napsal(a): On Tue, May 19, 2015 at 10:52:49AM +0200, Jan Cholasta wrote: Dne 15.5.2015 v 14:27 Martin Basti napsal(a): On 15/05/15 10:24,

Re: [Freeipa-devel] [PATCH] Password vault

2015-05-20 Thread Jan Cholasta
Dne 19.5.2015 v 16:40 Endi Sukma Dewata napsal(a): Before I send another patch I have some questions below. On 5/19/2015 3:27 AM, Jan Cholasta wrote: I changed the 'host vaults' to become 'service vaults'. The interface will look like this: $ ipa vault-find --service HTTP/server.example.com $

Re: [Freeipa-devel] [PATCHES 0001-0007] Profile management

2015-05-20 Thread Fraser Tweedale
On Tue, May 19, 2015 at 10:52:49AM +0200, Jan Cholasta wrote: Dne 15.5.2015 v 14:27 Martin Basti napsal(a): On 15/05/15 10:24, Fraser Tweedale wrote: Please find attached latest patches including new patches: - 0006 enable LDAP-based profiles in Dogtag on upgrade - 0007 import included

Re: [Freeipa-devel] IPAUpgrade.create_instance causing ipa-server-install failure

2015-05-20 Thread Martin Basti
On 20/05/15 07:31, Fraser Tweedale wrote: I am experiencing ipa-server-install failure which seems to be caused by IPAUpgrade.__start_nowait() (upgradeinstance.py:174). It is claimed that the LDAP connection will wait for the (Unix) socket but it does not - instead it fails to connect. Did

Re: [Freeipa-devel] [PATCH] 832-850 Stage Users Web UI and its prerequisites

2015-05-20 Thread Petr Vobornik
On 05/19/2015 07:22 PM, Petr Vobornik wrote: On 05/19/2015 05:34 PM, thierry bordaz wrote: On 05/15/2015 05:38 PM, David Kupka wrote: On 05/15/2015 12:34 PM, Petr Vobornik wrote: On 05/15/2015 10:59 AM, Petr Vobornik wrote: Stage User Web UI is actually just the last four patches(847-850).

Re: [Freeipa-devel] [UPSTREAM_FAILURES] Latest changes affect freeipa builds and client configuration

2015-05-20 Thread Oleg Fayans
Hi Martin, On 05/19/2015 06:35 PM, Martin Basti wrote: On 19/05/15 17:21, Oleg Fayans wrote: Dear colleagues I would like to notify you, that: 1. some of the recent changes in the upstream repo have broken the freeipa-client configuration. The symptoms are as follows: at some point during

Re: [Freeipa-devel] [UPSTREAM_FAILURES] Latest changes affect freeipa builds and client configuration

2015-05-20 Thread Petr Vobornik
On 05/20/2015 10:13 AM, Oleg Fayans wrote: Hi Martin, On 05/19/2015 06:35 PM, Martin Basti wrote: On 19/05/15 17:21, Oleg Fayans wrote: Dear colleagues I would like to notify you, that: 1. some of the recent changes in the upstream repo have broken the freeipa-client configuration. The

Re: [Freeipa-devel] [PATCH] 0005 User life cycle: del/mod/find/show stageuser commands

2015-05-20 Thread Jan Cholasta
Dne 18.5.2015 v 10:33 thierry bordaz napsal(a): On 05/15/2015 04:44 PM, David Kupka wrote: Hello Thierry, thanks for the patch set. Overall functionality of ULC feature looks good to me and is definitely alpha ready. I found following issues but don't insist on fixing it right now: 1) When

Re: [Freeipa-devel] [UPSTREAM_FAILURES] Latest changes affect freeipa builds and client configuration

2015-05-20 Thread Oleg Fayans
Hi Martin, Thank you! On 05/19/2015 05:42 PM, Martin Babinsky wrote: Hello Oleg, On 05/19/2015 05:21 PM, Oleg Fayans wrote: Dear colleagues I would like to notify you, that: 1. some of the recent changes in the upstream repo have broken the freeipa-client configuration. The symptoms are

Re: [Freeipa-devel] [TEST PLAN] User lifecycle plugin

2015-05-20 Thread Martin Kosek
On 05/19/2015 05:54 PM, thierry bordaz wrote: On 05/13/2015 05:54 PM, Martin Basti wrote: On 13/05/15 17:44, David Kupka wrote: On 05/13/2015 02:57 PM, Lenka Ryznarova wrote: Hi, I've prepared test plan design for User Lifecycle Plugin - [1]. Please review and let me know if you have any

Re: [Freeipa-devel] [TEST PLAN] User lifecycle plugin

2015-05-20 Thread thierry bordaz
On 05/20/2015 10:38 AM, Martin Kosek wrote: On 05/19/2015 05:54 PM, thierry bordaz wrote: On 05/13/2015 05:54 PM, Martin Basti wrote: On 13/05/15 17:44, David Kupka wrote: On 05/13/2015 02:57 PM, Lenka Ryznarova wrote: Hi, I've prepared test plan design for User Lifecycle Plugin - [1].

Re: [Freeipa-devel] [PATCH] 830 webui: fix empty table border in Firefox

2015-05-20 Thread Petr Vobornik
On 05/19/2015 06:01 PM, Martin Babinsky wrote: On 05/15/2015 11:01 AM, Petr Vobornik wrote: Firefox suffers from: https://bugzilla.mozilla.org/show_bug.cgi?id=409254 This is a workaround to fix it. ACK Pushed to master: 9b5655607d1a777006721f12fc61de122e3ea4d6 -- Petr Vobornik -- Manage

Re: [Freeipa-devel] [PATCH] 851-852 webui: datetime widget with datepicker

2015-05-20 Thread Petr Vobornik
On 05/19/2015 06:01 PM, Martin Babinsky wrote: On 05/18/2015 03:40 PM, Petr Vobornik wrote: Datetime widget was transform from a simple text input to 3 separate inputs: - date with bootstrap-datepicker - hour - minute e.g.: Validity end[ 2015-05-18 ] [23]:[01] UTC Vendor[

[Freeipa-devel] [PATCH 0251] Fix uniqueness: exclude compat tree from uid uniquness plugin

2015-05-20 Thread Martin Basti
Enforcing uniqueness for uid attribute prevent to move users to delete users subtree. Patch attached. -- Martin Basti From 1445d6adaae9844c6f7f51e46e357dc9bfd8741b Mon Sep 17 00:00:00 2001 From: Martin Basti mba...@redhat.com Date: Wed, 20 May 2015 14:51:09 +0200 Subject: [PATCH] Uid

Re: [Freeipa-devel] [PATCH] 829 webui: option to not create user private group

2015-05-20 Thread Petr Vobornik
On 05/13/2015 01:08 PM, Martin Basti wrote: On 12/05/15 17:58, Petr Vobornik wrote: Web UI was not able to create a user without a private group. New field added to user adder dialog to allow that. https://fedorahosted.org/freeipa/ticket/4986 ACK Pushed to master:

Re: [Freeipa-devel] [PATCH] manage replication topology in the shared tree

2015-05-20 Thread Ludwig Krispenz
On 05/20/2015 02:52 PM, Oleg Fayans wrote: Is this patch to be applied on top of the vanilla upstream tree, or does it require your previous patches applied before? it requires the install (0005) and ipa-command (0006) patch as well, submitted on 05/12 On 05/19/2015 02:16 PM, Ludwig

Re: [Freeipa-devel] [PATCH 0035] do not check for directory manager password during KRA uninstall

2015-05-20 Thread Martin Basti
On 19/05/15 20:14, Martin Babinsky wrote: On 05/19/2015 05:55 PM, Martin Basti wrote: On 19/05/15 16:41, Martin Basti wrote: On 19/05/15 16:19, Martin Babinsky wrote: On 05/19/2015 01:17 PM, Martin Babinsky wrote: https://fedorahosted.org/freeipa/ticket/5028 updated patch attached

Re: [Freeipa-devel] [PATCH 0035] do not check for directory manager password during KRA uninstall

2015-05-20 Thread Jan Cholasta
Dne 20.5.2015 v 15:07 Martin Basti napsal(a): On 19/05/15 20:14, Martin Babinsky wrote: On 05/19/2015 05:55 PM, Martin Basti wrote: On 19/05/15 16:41, Martin Basti wrote: On 19/05/15 16:19, Martin Babinsky wrote: On 05/19/2015 01:17 PM, Martin Babinsky wrote:

Re: [Freeipa-devel] [PATCH] manage replication topology in the shared tree

2015-05-20 Thread Oleg Fayans
Is this patch to be applied on top of the vanilla upstream tree, or does it require your previous patches applied before? On 05/19/2015 02:16 PM, Ludwig Krispenz wrote: Hi, here is the latest patch for the plugin part, trying to address all problems found in the review Regards, Ludwig PS

Re: [Freeipa-devel] [PATCH] manage replication topology in the shared tree

2015-05-20 Thread Petr Vobornik
On 05/20/2015 02:58 PM, Ludwig Krispenz wrote: On 05/20/2015 02:52 PM, Oleg Fayans wrote: Is this patch to be applied on top of the vanilla upstream tree, or does it require your previous patches applied before? it requires the install (0005) and ipa-command (0006) patch as well, submitted on

[Freeipa-devel] [PATCH] 854 git ignore ipaplatform/__init__.py

2015-05-20 Thread Petr Vobornik
This file is generated in `make version-update` added in 9f049ca14403f3696d54d186e6b1b15181f055df -- Petr Vobornik From 9af7da77015eb4fee728144bd9502ee8a8a0555c Mon Sep 17 00:00:00 2001 From: Petr Vobornik pvobo...@redhat.com Date: Wed, 20 May 2015 15:51:26 +0200 Subject: [PATCH] git ignore

Re: [Freeipa-devel] [PATCH] manage replication topology in the shared tree

2015-05-20 Thread Ludwig Krispenz
On 05/20/2015 03:07 PM, Petr Vobornik wrote: On 05/20/2015 02:58 PM, Ludwig Krispenz wrote: On 05/20/2015 02:52 PM, Oleg Fayans wrote: Is this patch to be applied on top of the vanilla upstream tree, or does it require your previous patches applied before? it requires the install (0005) and

[Freeipa-devel] [PATCHES 0252-0253] DNSSEC: allow to move DNSSEC key master to another IPA server

2015-05-20 Thread Martin Basti
This patch allows to disable DNSSEC key master on IPA server, or replace current DNSSEC key master with another IPA server. Only for master branch. https://fedorahosted.org/freeipa/ticket/4657 Patches attached. -- Martin Basti From 68ce33509c3ea12a2af9401e6856ab14a812ddd0 Mon Sep 17

Re: [Freeipa-devel] [PATCH 428] client-install: Fix kinits with non-default Kerberos config file

2015-05-20 Thread Martin Babinsky
On 05/20/2015 04:28 PM, Jan Cholasta wrote: Hi, the attached patch fixes a bug introduced in the fix for https://fedorahosted.org/freeipa/ticket/4808 (reopened). Honza Works for me, ACK. -- Martin^3 Babinsky -- Manage your subscription for the Freeipa-devel mailing list:

Re: [Freeipa-devel] [PATCH] 1112 Add service constraint delegation plugin

2015-05-20 Thread Rob Crittenden
Rob Crittenden wrote: Rob Crittenden wrote: Add a plugin to manage service delegations, like the one allowing the HTTP service to obtain an ldap service ticket on behalf of the user. This does not include impersonation targets, so one cannot yet limit by user what tickets can be obtained.

[Freeipa-devel] [PATCH 428] client-install: Fix kinits with non-default Kerberos config file

2015-05-20 Thread Jan Cholasta
Hi, the attached patch fixes a bug introduced in the fix for https://fedorahosted.org/freeipa/ticket/4808 (reopened). Honza -- Jan Cholasta From c3bac104f2d04ff964e187e5f078d79ca3fb303f Mon Sep 17 00:00:00 2001 From: Jan Cholasta jchol...@redhat.com Date: Wed, 20 May 2015 14:23:30 +

Re: [Freeipa-devel] [PATCHES 0001-0011 v3] Profile management

2015-05-20 Thread Fraser Tweedale
Hi Honza, Martin et al, Latest patches attached. On top of previous patches (most review matters addressed**) patches 0008..0011 add support for profiles and user certificates to `ipa cert-request'. ** those that were not are being tracked at [1]; please add anything I missed. Some points