Re: [Freeipa-devel] Re: [Freeipa-users] IPA license

2009-09-15 Thread Jason Gerard DeRose
On Tue, 2009-09-15 at 18:09 -0400, Dmitri Pal wrote: > Andrea Modesto Rossi wrote: > > On Mar, 15 Settembre 2009 9:55 pm, Dmitri Pal wrote: > > > >> We are considering to release freeIPA v2 under a less restrictive > >> license than we used in IPA v1. > >> It was "GPLv2 only" in v1.x and we thin

Re: [Freeipa-devel] Re: [Freeipa-users] IPA license

2009-09-15 Thread Dmitri Pal
Andrea Modesto Rossi wrote: > On Mar, 15 Settembre 2009 9:55 pm, Dmitri Pal wrote: > >> We are considering to release freeIPA v2 under a less restrictive >> license than we used in IPA v1. >> It was "GPLv2 only" in v1.x and we think about "GPLv2 and later" or >> "GPLv3 and later". >> Please resp

Re: [Freeipa-devel] [PATCH] 263 Tighten up upgrade detection

2009-09-15 Thread Rob Crittenden
Rob Crittenden wrote: Simo Sorce wrote: On Wed, 2009-09-02 at 18:03 -0400, Rob Crittenden wrote: We have an upgrade script that runs in rpm %post to see if an existing installation needs to be updated. This sometimes printed spurious error messages that were confusing. This patch attempts to t

[Freeipa-devel] [PATCH] 274 detect whether to uninstall the CA or not

2009-09-15 Thread Rob Crittenden
You had to pass --ca when uninstalling if you wanted the CA uninstalled. This was nuts, auto-detect it. rob freeipa-274-uninstall.patch Description: application/mbox smime.p7s Description: S/MIME Cryptographic Signature ___ Freeipa-devel mailing li

Re: [Freeipa-devel] Re: [PATCHES] Make plugins use baseldap classes.

2009-09-15 Thread Rob Crittenden
Rob Crittenden wrote: Pavel Zuna wrote: Rob Crittenden wrote: Pavel Zůna wrote: This is a series of patches that depends on patches: - Improve attribute printing in the CLI. - Improve ipalib.plugins.baseldap classes. All plugins are converted to extend baseldap classes. This makes things mor

[Freeipa-devel] Re: [Freeipa-users] IPA license

2009-09-15 Thread Andrea Modesto Rossi
On Mar, 15 Settembre 2009 9:55 pm, Dmitri Pal wrote: > > We are considering to release freeIPA v2 under a less restrictive > license than we used in IPA v1. > It was "GPLv2 only" in v1.x and we think about "GPLv2 and later" or > "GPLv3 and later". > Please respond to this mail if there are any sug

[Freeipa-devel] IPA license

2009-09-15 Thread Dmitri Pal
Hello, We are considering to release freeIPA v2 under a less restrictive license than we used in IPA v1. It was "GPLv2 only" in v1.x and we think about "GPLv2 and later" or "GPLv3 and later". Please respond to this mail if there are any suggestions, comments or concerns. -- Thank you, Dmitri Pal

[Freeipa-devel] FreeIPA v1.2.2 released

2009-09-15 Thread Rob Crittenden
The FreeIPA Project (http://freeipa.org) is proud to present FreeIPA version 1.22. FreeIPA is an integrated security information management solution combining Linux (Fedora), Fedora Directory Server, MIT Kerberos and NTP. FreeIPA binds together a number of technologies and adds a web interface an

Re: [Freeipa-devel] [PATCH] 271 handle certificate decode errors in service

2009-09-15 Thread Rob Crittenden
Pavel Zuna wrote: Rob Crittenden wrote: In the service plugin we will attempt to revoke a server cert when a service is deleted. Add some error handling around that effort. This fixes the self-tests. rob nack. Your "269 external CA signing, abstract RA" already handles them inside get_seri

Re: [Freeipa-devel] [PATCH] 269 external CA signing, abstract RA

2009-09-15 Thread Rob Crittenden
Pavel Zuna wrote: Rob Crittenden wrote: The RA plugin originally only supported dogtag. At some point I want to be able to do on-line replica creation and this means we need to be able to do remote cert requests. To support this I've abstracted the RA plugin and added basic self-signed CA supp

[Freeipa-devel] Re: [PATCHES] Make plugins use baseldap classes.

2009-09-15 Thread Rob Crittenden
Pavel Zuna wrote: Rob Crittenden wrote: Pavel Zůna wrote: This is a series of patches that depends on patches: - Improve attribute printing in the CLI. - Improve ipalib.plugins.baseldap classes. All plugins are converted to extend baseldap classes. This makes things more consistent, fixes som

[Freeipa-devel] Re: [PATCHES] Make plugins use baseldap classes.

2009-09-15 Thread Pavel Zuna
Rob Crittenden wrote: Pavel Zůna wrote: This is a series of patches that depends on patches: - Improve attribute printing in the CLI. - Improve ipalib.plugins.baseldap classes. All plugins are converted to extend baseldap classes. This makes things more consistent, fixes some general bugs (wit

Re: [Freeipa-devel] [PATCH] 273 join a host to an IPA domain

2009-09-15 Thread Pavel Zuna
Pavel Zuna wrote: Rob Crittenden wrote: NOTE, this patch replaces a previous patch to do the same thing. I fixed a few problems Simo pointed out and re-based it against the current master. This largish patch adds host enrollment. There are several scenarios that are covered. All of these ass

Re: [Freeipa-devel] [PATCH] 273 join a host to an IPA domain

2009-09-15 Thread Pavel Zuna
Rob Crittenden wrote: NOTE, this patch replaces a previous patch to do the same thing. I fixed a few problems Simo pointed out and re-based it against the current master. This largish patch adds host enrollment. There are several scenarios that are covered. All of these assume that the IPA cli

Re: [Freeipa-devel] [PATCH] 271 handle certificate decode errors in service

2009-09-15 Thread Pavel Zuna
Rob Crittenden wrote: In the service plugin we will attempt to revoke a server cert when a service is deleted. Add some error handling around that effort. This fixes the self-tests. rob nack. Your "269 external CA signing, abstract RA" already handles them inside get_serial(). However, ther

Re: [Freeipa-devel] [PATCH] 269 external CA signing, abstract RA

2009-09-15 Thread Pavel Zuna
Rob Crittenden wrote: The RA plugin originally only supported dogtag. At some point I want to be able to do on-line replica creation and this means we need to be able to do remote cert requests. To support this I've abstracted the RA plugin and added basic self-signed CA support. To do this I h