[Freeipa-devel] [freeipa PR#746][edited] KDC proxy URI records

2017-04-28 Thread MartinBasti
URL: https://github.com/freeipa/freeipa/pull/746 Author: MartinBasti Title: #746: KDC proxy URI records Action: edited Changed field: body Original value: """ Automatic creation of KDC proxy URI records Enables creation of following KDC proxy URL records per each replica: ```

[Freeipa-devel] [freeipa PR#746][comment] KDC proxy URI records

2017-04-28 Thread MartinBasti
URL: https://github.com/freeipa/freeipa/pull/746 Title: #746: KDC proxy URI records MartinBasti commented: """ @simo5 not really a 4.5 material then """ See the full comment at https://github.com/freeipa/freeipa/pull/746#issuecomment-298039065 -- Manage your subscription for the

[Freeipa-devel] [freeipa PR#746][synchronized] KDC proxy URI records

2017-04-28 Thread MartinBasti
URL: https://github.com/freeipa/freeipa/pull/746 Author: MartinBasti Title: #746: KDC proxy URI records Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/746/head:pr746 git checkout pr746 From

[Freeipa-devel] [freeipa PR#746][comment] KDC proxy URI records

2017-04-28 Thread simo5
URL: https://github.com/freeipa/freeipa/pull/746 Title: #746: KDC proxy URI records simo5 commented: """ We can probably defer. """ See the full comment at https://github.com/freeipa/freeipa/pull/746#issuecomment-298087667 -- Manage your subscription for the Freeipa-devel mailing list:

[Freeipa-devel] Blog post: Debugging FreeIPA 4.5 privilege separation code

2017-04-28 Thread Alexander Bokovoy
Hi, Simo and I wrote an article on how to debug FreeIPA 4.5 privilege separation code. It is not about debugging, in fact, but on where to look for various types of logs and how to interpret them. The article also provides a high level explanation of how privilege separation in FreeIPA works and

[Freeipa-devel] Automated Fedora update testing

2017-04-28 Thread Adam Williamson
Hi folks! I thought this might be of interest to the FreeIPA community, so I thought I'd write it up here in case anyone missed it elsewhere. I work on the Fedora QA team, and we have been using the openQA automated test system (developed by our friends at SUSE) to run various functional tests on

[Freeipa-devel] [freeipa PR#738][+rejected] restore: restart gssproxy after restore

2017-04-28 Thread pvoborni
URL: https://github.com/freeipa/freeipa/pull/738 Title: #738: restore: restart gssproxy after restore Label: +rejected -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#729][synchronized] Turn on NSSOCSP check in mod_nss conf

2017-04-28 Thread pvomacka
URL: https://github.com/freeipa/freeipa/pull/729 Author: pvomacka Title: #729: Turn on NSSOCSP check in mod_nss conf Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/729/head:pr729 git checkout pr729 From

[Freeipa-devel] [freeipa PR#747][closed] vault: piped input for ipa vault-add fails

2017-04-28 Thread MartinBasti
URL: https://github.com/freeipa/freeipa/pull/747 Author: flo-renaud Title: #747: vault: piped input for ipa vault-add fails Action: closed To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/747/head:pr747 git checkout pr747 --

[Freeipa-devel] [freeipa PR#747][+pushed] vault: piped input for ipa vault-add fails

2017-04-28 Thread MartinBasti
URL: https://github.com/freeipa/freeipa/pull/747 Title: #747: vault: piped input for ipa vault-add fails Label: +pushed -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#735][+ack] automount install: do not wait for sssd restart on uninstallation

2017-04-28 Thread tomaskrizek
URL: https://github.com/freeipa/freeipa/pull/735 Title: #735: automount install: do not wait for sssd restart on uninstallation Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#747][comment] vault: piped input for ipa vault-add fails

2017-04-28 Thread MartinBasti
URL: https://github.com/freeipa/freeipa/pull/747 Title: #747: vault: piped input for ipa vault-add fails MartinBasti commented: """ master: * d5c41ed4ad370c7d74296a830993a5bd3fd32e5f vault: piped input for ipa vault-add fails ipa-4-5: * c8ca0f89a68b5d57c56344fdeb12fd436976c726 vault: piped

[Freeipa-devel] [freeipa PR#741][comment] 6.9 -> 7.4 migration fixes

2017-04-28 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/741 Title: #741: 6.9 -> 7.4 migration fixes stlaz commented: """ For the record - the tests are passing on my machine, etwas stimmt hier nicht. """ See the full comment at https://github.com/freeipa/freeipa/pull/741#issuecomment-297969953 --

[Freeipa-devel] [freeipa PR#733][synchronized] [4.5] Fix CA/server cert validation in FIPS

2017-04-28 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/733 Author: stlaz Title: #733: [4.5] Fix CA/server cert validation in FIPS Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/733/head:pr733 git checkout pr733

[Freeipa-devel] [freeipa PR#735][closed] automount install: do not wait for sssd restart on uninstallation

2017-04-28 Thread MartinBasti
URL: https://github.com/freeipa/freeipa/pull/735 Author: pvoborni Title: #735: automount install: do not wait for sssd restart on uninstallation Action: closed To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/735/head:pr735 git

[Freeipa-devel] [freeipa PR#735][+pushed] automount install: do not wait for sssd restart on uninstallation

2017-04-28 Thread MartinBasti
URL: https://github.com/freeipa/freeipa/pull/735 Title: #735: automount install: do not wait for sssd restart on uninstallation Label: +pushed -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#735][comment] automount install: do not wait for sssd restart on uninstallation

2017-04-28 Thread MartinBasti
URL: https://github.com/freeipa/freeipa/pull/735 Title: #735: automount install: do not wait for sssd restart on uninstallation MartinBasti commented: """ master: * b4e447fa6fc7d659ae6a3b6285d4ddda0baa0be4 automount install: fix checking of SSSD functionality on uninstall ipa-4-5: *

[Freeipa-devel] [freeipa PR#748][comment] restore: restart/reload gssproxy after restore

2017-04-28 Thread pvoborni
URL: https://github.com/freeipa/freeipa/pull/748 Title: #748: restore: restart/reload gssproxy after restore pvoborni commented: """ Obsoletes PR #738 """ See the full comment at https://github.com/freeipa/freeipa/pull/748#issuecomment-297962322 -- Manage your subscription for the

[Freeipa-devel] [freeipa PR#738][closed] restore: restart gssproxy after restore

2017-04-28 Thread pvoborni
URL: https://github.com/freeipa/freeipa/pull/738 Author: pvoborni Title: #738: restore: restart gssproxy after restore Action: closed To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/738/head:pr738 git checkout pr738 -- Manage

[Freeipa-devel] [freeipa PR#738][comment] restore: restart gssproxy after restore

2017-04-28 Thread pvoborni
URL: https://github.com/freeipa/freeipa/pull/738 Title: #738: restore: restart gssproxy after restore pvoborni commented: """ PR #748 obsoletes this one - this PR was created badly and so I cannot force update it. New one uses reload-or-restart """ See the full comment at

[Freeipa-devel] [freeipa PR#748][opened] restore: restart/reload gssproxy after restore

2017-04-28 Thread pvoborni
URL: https://github.com/freeipa/freeipa/pull/748 Author: pvoborni Title: #748: restore: restart/reload gssproxy after restore Action: opened PR body: """ So that gssproxy picks up new configuration and therefore related usages like authentication of CLI against server works

[Freeipa-devel] [freeipa PR#749][opened] Added plugins directory to python2-ipaclient subpackage

2017-04-28 Thread olivergs
URL: https://github.com/freeipa/freeipa/pull/749 Author: olivergs Title: #749: Added plugins directory to python2-ipaclient subpackage Action: opened PR body: """ Subpackage does not own that directory and could create conflicts if a plugin creates it on its onwn """ To pull the PR as Git

Re: [Freeipa-devel] "blocker" tag for pull request

2017-04-28 Thread Tomas Krizek
On 04/28/2017 10:15 AM, Petr Vobornik wrote: > Hi all, > > I created "blocker" tag for FreeIPA Git Hub PRs. > > It is should be used to mark PRs which solves test blocker or other > functional blockers - e.g. blocks creation of demo. I.e. should be > used rather rarely. > > I don't like the tag

[Freeipa-devel] [freeipa PR#733][comment] [4.5] Fix CA/server cert validation in FIPS

2017-04-28 Thread MartinBasti
URL: https://github.com/freeipa/freeipa/pull/733 Title: #733: [4.5] Fix CA/server cert validation in FIPS MartinBasti commented: """ ipa-4-5: * 651d132b701b773b2bbeb41496d6c5ddbf6d19b3 Fix CA/server cert validation in FIPS """ See the full comment at

[Freeipa-devel] [freeipa PR#733][closed] [4.5] Fix CA/server cert validation in FIPS

2017-04-28 Thread MartinBasti
URL: https://github.com/freeipa/freeipa/pull/733 Author: stlaz Title: #733: [4.5] Fix CA/server cert validation in FIPS Action: closed To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/733/head:pr733 git checkout pr733 --

[Freeipa-devel] [freeipa PR#733][+pushed] [4.5] Fix CA/server cert validation in FIPS

2017-04-28 Thread MartinBasti
URL: https://github.com/freeipa/freeipa/pull/733 Title: #733: [4.5] Fix CA/server cert validation in FIPS Label: +pushed -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#732][+postponed] ipa-custodia: use Dogtag's alias/pwdfile.txt

2017-04-28 Thread MartinBasti
URL: https://github.com/freeipa/freeipa/pull/732 Title: #732: ipa-custodia: use Dogtag's alias/pwdfile.txt Label: +postponed -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#744][closed] [4.5] Correct PyPI package dependencies

2017-04-28 Thread tomaskrizek
URL: https://github.com/freeipa/freeipa/pull/744 Author: tiran Title: #744: [4.5] Correct PyPI package dependencies Action: closed To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/744/head:pr744 git checkout pr744 -- Manage

[Freeipa-devel] [freeipa PR#744][+pushed] [4.5] Correct PyPI package dependencies

2017-04-28 Thread tomaskrizek
URL: https://github.com/freeipa/freeipa/pull/744 Title: #744: [4.5] Correct PyPI package dependencies Label: +pushed -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#744][comment] [4.5] Correct PyPI package dependencies

2017-04-28 Thread tomaskrizek
URL: https://github.com/freeipa/freeipa/pull/744 Title: #744: [4.5] Correct PyPI package dependencies tomaskrizek commented: """ ipa-4-5: * b91ee1294bb3139f3d9df62c75dd429a5821bf40 Correct PyPI package dependencies """ See the full comment at

[Freeipa-devel] [freeipa PR#732][comment] ipa-custodia: use Dogtag's alias/pwdfile.txt

2017-04-28 Thread MartinBasti
URL: https://github.com/freeipa/freeipa/pull/732 Title: #732: ipa-custodia: use Dogtag's alias/pwdfile.txt MartinBasti commented: """ Postponing, ticket milestone is 4.7 """ See the full comment at https://github.com/freeipa/freeipa/pull/732#issuecomment-297988800 -- Manage your subscription

[Freeipa-devel] [freeipa PR#744][+ack] [4.5] Correct PyPI package dependencies

2017-04-28 Thread MartinBasti
URL: https://github.com/freeipa/freeipa/pull/744 Title: #744: [4.5] Correct PyPI package dependencies Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#748][comment] restore: restart/reload gssproxy after restore

2017-04-28 Thread tomaskrizek
URL: https://github.com/freeipa/freeipa/pull/748 Title: #748: restore: restart/reload gssproxy after restore tomaskrizek commented: """ Ok, everything looks good then. """ See the full comment at https://github.com/freeipa/freeipa/pull/748#issuecomment-297990127 -- Manage your subscription

[Freeipa-devel] [freeipa PR#748][closed] restore: restart/reload gssproxy after restore

2017-04-28 Thread tomaskrizek
URL: https://github.com/freeipa/freeipa/pull/748 Author: pvoborni Title: #748: restore: restart/reload gssproxy after restore Action: closed To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/748/head:pr748 git checkout pr748 --

[Freeipa-devel] [freeipa PR#748][+pushed] restore: restart/reload gssproxy after restore

2017-04-28 Thread tomaskrizek
URL: https://github.com/freeipa/freeipa/pull/748 Title: #748: restore: restart/reload gssproxy after restore Label: +pushed -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#748][comment] restore: restart/reload gssproxy after restore

2017-04-28 Thread tomaskrizek
URL: https://github.com/freeipa/freeipa/pull/748 Title: #748: restore: restart/reload gssproxy after restore tomaskrizek commented: """ How is this patch going to work for Debian? Shouldn't we also implement `reload_or_restart` for `DebianSysvService`? """ See the full comment at

[Freeipa-devel] [freeipa PR#729][synchronized] Turn on NSSOCSP check in mod_nss conf

2017-04-28 Thread pvomacka
URL: https://github.com/freeipa/freeipa/pull/729 Author: pvomacka Title: #729: Turn on NSSOCSP check in mod_nss conf Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/729/head:pr729 git checkout pr729 From

[Freeipa-devel] [freeipa PR#748][comment] restore: restart/reload gssproxy after restore

2017-04-28 Thread pvoborni
URL: https://github.com/freeipa/freeipa/pull/748 Title: #748: restore: restart/reload gssproxy after restore pvoborni commented: """ Should work: ``` def debian_service_class_factory(name, api=None): if name == 'dirsrv': return redhat_services.RedHatDirectoryService(name, api)

Re: [Freeipa-devel] "blocker" tag for pull request

2017-04-28 Thread Martin Bašti
On 28.04.2017 14:17, Tomas Krizek wrote: On 04/28/2017 10:15 AM, Petr Vobornik wrote: Hi all, I created "blocker" tag for FreeIPA Git Hub PRs. It is should be used to mark PRs which solves test blocker or other functional blockers - e.g. blocks creation of demo. I.e. should be used rather

[Freeipa-devel] [freeipa PR#748][+ack] restore: restart/reload gssproxy after restore

2017-04-28 Thread tomaskrizek
URL: https://github.com/freeipa/freeipa/pull/748 Title: #748: restore: restart/reload gssproxy after restore Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#748][comment] restore: restart/reload gssproxy after restore

2017-04-28 Thread tomaskrizek
URL: https://github.com/freeipa/freeipa/pull/748 Title: #748: restore: restart/reload gssproxy after restore tomaskrizek commented: """ master: * 3a4c8e39c3e38ec651cfcbb3cac59e0e92e04fe0 restore: restart/reload gssproxy after restore ipa-4-5: * 04ed1fa3acdf002ecc37dde4f5d226c0fbe5aa30

[Freeipa-devel] [freeipa PR#750][+ack] Fixed typo in ipa-client-install help output

2017-04-28 Thread MartinBasti
URL: https://github.com/freeipa/freeipa/pull/750 Title: #750: Fixed typo in ipa-client-install help output Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#746][synchronized] KDC proxy URI records

2017-04-28 Thread MartinBasti
URL: https://github.com/freeipa/freeipa/pull/746 Author: MartinBasti Title: #746: KDC proxy URI records Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/746/head:pr746 git checkout pr746 From

[Freeipa-devel] [freeipa PR#750][opened] Fixed typo in ipa-client-install help output

2017-04-28 Thread tscherf
URL: https://github.com/freeipa/freeipa/pull/750 Author: tscherf Title: #750: Fixed typo in ipa-client-install help output Action: opened PR body: """ Fixed typo in option "--all-ip-addresses" from "ipa-client-install". """ To pull the PR as Git branch: git remote add ghfreeipa

[Freeipa-devel] [freeipa PR#746][synchronized] KDC proxy URI records

2017-04-28 Thread MartinBasti
URL: https://github.com/freeipa/freeipa/pull/746 Author: MartinBasti Title: #746: KDC proxy URI records Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/746/head:pr746 git checkout pr746 From

[Freeipa-devel] [freeipa PR#746][edited] KDC proxy URI records

2017-04-28 Thread MartinBasti
URL: https://github.com/freeipa/freeipa/pull/746 Author: MartinBasti Title: #746: KDC proxy URI records Action: edited Changed field: body Original value: """ Automatic creation of KDC proxy URI records Enables creation of following KDC proxy URL records per each replica: ```

[Freeipa-devel] [freeipa PR#746][comment] KDC proxy URI records

2017-04-28 Thread simo5
URL: https://github.com/freeipa/freeipa/pull/746 Title: #746: KDC proxy URI records simo5 commented: """ I am not entirely sure we want to care for the cse where an admin disables KDC Proxy in an automatic fashion; otherwise we would also need to check if TCP or UDP are disabled and change

[Freeipa-devel] [freeipa PR#746][comment] KDC proxy URI records

2017-04-28 Thread MartinBasti
URL: https://github.com/freeipa/freeipa/pull/746 Title: #746: KDC proxy URI records MartinBasti commented: """ @simo5 we don't support manual changes of IPA system records, it is regenerated automatically, so any manual changes are overwritten when: new replica is added/replica is

[Freeipa-devel] [freeipa PR#746][comment] KDC proxy URI records

2017-04-28 Thread simo5
URL: https://github.com/freeipa/freeipa/pull/746 Title: #746: KDC proxy URI records simo5 commented: """ @MartinBasti In this case we need a way to tell the system what are the priorities and which protocols are enabled, priorities are important too, admins need to be able to change them as

[Freeipa-devel] [freeipa PR#694][comment] RFC: implement local PKINIT deployment in server/replica install

2017-04-28 Thread HonzaCholasta
URL: https://github.com/freeipa/freeipa/pull/694 Title: #694: RFC: implement local PKINIT deployment in server/replica install HonzaCholasta commented: """ Works for me, ACK. """ See the full comment at https://github.com/freeipa/freeipa/pull/694#issuecomment-297940885 -- Manage your

Re: [Freeipa-devel] KDC proxy URI records

2017-04-28 Thread Christian Heimes
On 2017-04-27 14:00, Martin Bašti wrote: > > > On 26.04.2017 20:41, Simo Sorce wrote: >> On Wed, 2017-04-26 at 12:57 +0200, Martin Bašti wrote: >>> On 25.04.2017 16:57, Martin Bašti wrote: Hello all, I'm going to implement automatic URI records for kdc proxy and I'd like to

[Freeipa-devel] [freeipa PR#694][+ack] RFC: implement local PKINIT deployment in server/replica install

2017-04-28 Thread HonzaCholasta
URL: https://github.com/freeipa/freeipa/pull/694 Title: #694: RFC: implement local PKINIT deployment in server/replica install Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#694][+pushed] RFC: implement local PKINIT deployment in server/replica install

2017-04-28 Thread HonzaCholasta
URL: https://github.com/freeipa/freeipa/pull/694 Title: #694: RFC: implement local PKINIT deployment in server/replica install Label: +pushed -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#694][comment] RFC: implement local PKINIT deployment in server/replica install

2017-04-28 Thread HonzaCholasta
URL: https://github.com/freeipa/freeipa/pull/694 Title: #694: RFC: implement local PKINIT deployment in server/replica install HonzaCholasta commented: """ master: * b1a1e104391c84cb9af7b0a7c8748c8652442ddb separate function to set ipaConfigString values on service entry *

[Freeipa-devel] [freeipa PR#694][closed] RFC: implement local PKINIT deployment in server/replica install

2017-04-28 Thread HonzaCholasta
URL: https://github.com/freeipa/freeipa/pull/694 Author: martbab Title: #694: RFC: implement local PKINIT deployment in server/replica install Action: closed To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/694/head:pr694 git

[Freeipa-devel] [freeipa PR#729][comment] Turn on NSSOCSP check in mod_nss conf

2017-04-28 Thread HonzaCholasta
URL: https://github.com/freeipa/freeipa/pull/729 Title: #729: Turn on NSSOCSP check in mod_nss conf HonzaCholasta commented: """ @pvomacka, CI fails because you forgot to include python-augeas in lint BuildRequires. """ See the full comment at

[Freeipa-devel] [freeipa PR#729][comment] Turn on NSSOCSP check in mod_nss conf

2017-04-28 Thread HonzaCholasta
URL: https://github.com/freeipa/freeipa/pull/729 Title: #729: Turn on NSSOCSP check in mod_nss conf HonzaCholasta commented: """ @pvomacka, CI fails because you forgot to include python-augeas in lint BuildRequires. """ See the full comment at

Re: [Freeipa-devel] KDC proxy URI records

2017-04-28 Thread Martin Kosek
On 04/27/2017 04:16 PM, Simo Sorce wrote: > On Thu, 2017-04-27 at 15:56 +0200, Petr Vobornik wrote: >> On 04/27/2017 02:19 PM, Christian Heimes wrote: >>> On 2017-04-27 14:00, Martin Bašti wrote: I would like to discuss consequences of adding kdc URI records: 1. basically all ipa

Re: [Freeipa-devel] KDC proxy URI records

2017-04-28 Thread Martin Bašti
On 28.04.2017 09:32, Martin Kosek wrote: On 04/27/2017 04:16 PM, Simo Sorce wrote: On Thu, 2017-04-27 at 15:56 +0200, Petr Vobornik wrote: On 04/27/2017 02:19 PM, Christian Heimes wrote: On 2017-04-27 14:00, Martin Bašti wrote: I would like to discuss consequences of adding kdc URI

[Freeipa-devel] [freeipa PR#741][synchronized] 6.9 -> 7.4 migration fixes

2017-04-28 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/741 Author: stlaz Title: #741: 6.9 -> 7.4 migration fixes Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/741/head:pr741 git checkout pr741 From

[Freeipa-devel] [freeipa PR#694][+blocker] RFC: implement local PKINIT deployment in server/replica install

2017-04-28 Thread pvoborni
URL: https://github.com/freeipa/freeipa/pull/694 Title: #694: RFC: implement local PKINIT deployment in server/replica install Label: +blocker -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#747][-ack] vault: piped input for ipa vault-add fails

2017-04-28 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/747 Title: #747: vault: piped input for ipa vault-add fails Label: -ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#747][comment] vault: piped input for ipa vault-add fails

2017-04-28 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/747 Title: #747: vault: piped input for ipa vault-add fails stlaz commented: """ @Akasurde: Don't add ACK label when the PR is not OK! @flo-renaud: You will need to specify a ticket for this PR. """ See the full comment at

[Freeipa-devel] [freeipa PR#741][+blocker] 6.9 -> 7.4 migration fixes

2017-04-28 Thread pvoborni
URL: https://github.com/freeipa/freeipa/pull/741 Title: #741: 6.9 -> 7.4 migration fixes Label: +blocker -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

[Freeipa-devel] [freeipa PR#747][synchronized] vault: piped input for ipa vault-add fails

2017-04-28 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/747 Author: flo-renaud Title: #747: vault: piped input for ipa vault-add fails Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/747/head:pr747 git checkout pr747

[Freeipa-devel] [freeipa PR#747][comment] vault: piped input for ipa vault-add fails

2017-04-28 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/747 Title: #747: vault: piped input for ipa vault-add fails flo-renaud commented: """ @stlaz Thank you for the reminder. Commit msg updated with issue 6907 """ See the full comment at

[Freeipa-devel] [freeipa PR#747][comment] vault: piped input for ipa vault-add fails

2017-04-28 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/747 Title: #747: vault: piped input for ipa vault-add fails stlaz commented: """ Thank you for the brief action taken. Re-adding the ACK label. """ See the full comment at https://github.com/freeipa/freeipa/pull/747#issuecomment-297935390 --

[Freeipa-devel] [freeipa PR#747][+ack] vault: piped input for ipa vault-add fails

2017-04-28 Thread stlaz
URL: https://github.com/freeipa/freeipa/pull/747 Title: #747: vault: piped input for ipa vault-add fails Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#723][-pushed] Store GSSAPI session key in /var/run/httpd

2017-04-28 Thread pvoborni
URL: https://github.com/freeipa/freeipa/pull/723 Title: #723: Store GSSAPI session key in /var/run/httpd Label: -pushed -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#723][-ack] Store GSSAPI session key in /var/run/httpd

2017-04-28 Thread pvoborni
URL: https://github.com/freeipa/freeipa/pull/723 Title: #723: Store GSSAPI session key in /var/run/httpd Label: -ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] "blocker" tag for pull request

2017-04-28 Thread Petr Vobornik
Hi all, I created "blocker" tag for FreeIPA Git Hub PRs. It is should be used to mark PRs which solves test blocker or other functional blockers - e.g. blocks creation of demo. I.e. should be used rather rarely. I don't like the tag name, but I couldn't find better. Note: blocker priority

[Freeipa-devel] [freeipa PR#737][closed] Vault: Explicitly default to 3DES CBC

2017-04-28 Thread MartinBasti
URL: https://github.com/freeipa/freeipa/pull/737 Author: tiran Title: #737: Vault: Explicitly default to 3DES CBC Action: closed To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/737/head:pr737 git checkout pr737 -- Manage your

[Freeipa-devel] [freeipa PR#737][+pushed] Vault: Explicitly default to 3DES CBC

2017-04-28 Thread MartinBasti
URL: https://github.com/freeipa/freeipa/pull/737 Title: #737: Vault: Explicitly default to 3DES CBC Label: +pushed -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#737][comment] Vault: Explicitly default to 3DES CBC

2017-04-28 Thread MartinBasti
URL: https://github.com/freeipa/freeipa/pull/737 Title: #737: Vault: Explicitly default to 3DES CBC MartinBasti commented: """ master: * 5197422ef65e7239fc56c562ab87d99388a38a8d Vault: Explicitly default to 3DES CBC ipa-4-5: * e94a1d18653fe2e9558ac0b70bdf2ddd1f78d150 Vault: Explicitly