Re: [Freeipa-devel] [PATCH] 0074 Add requires

2011-01-27 Thread Jan Zelený
Dmitri Pal wrote: > On 01/27/2011 05:27 AM, Jan Zelený wrote: > > Simo Sorce wrote: > >> First part of ticket #855 > >> > >> Add the requires we will need on F15, tested against jdennis ipa-devel > >> repo, works as expected. > >> > >> Simo. > > > > The patch is obviously ok, so ack from this

Re: [Freeipa-devel] [PATCH] 043 Fix API.txt

2011-01-27 Thread Simo Sorce
On Thu, 27 Jan 2011 19:03:40 +0100 Jakub Hrozek wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > One of the recent API patches didn't update API.txt Which patch ? I build master today a few times and never had a validation error. Simo. -- Simo Sorce * Red Hat, Inc * New York __

Re: [Freeipa-devel] [PATCH] 0015 block anonymous access to sudo info

2011-01-27 Thread Adam Young
On 01/27/2011 06:21 PM, JR Aquino wrote: Aci patch to block anonymous access to sudo info https://fedorahosted.org/freeipa/ticket/865 ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel ACK P

[Freeipa-devel] FreeIPA Logging (Not Auditing... )

2011-01-27 Thread JR Aquino
I have been working with the project for a while now and it has dawned on me that the FreeIPA ipalib plugins, don't really have a syslog library that they output with. So far I've really just been troubleshooting and getting around with: /var/log/httpd/access_log /var/log/httpd/error_log /var/lo

[Freeipa-devel] [PATCH] admiyo-0173-aci-rights-widget

2011-01-27 Thread Adam Young
From bfffe1930465ef7af23c1915e8c22719dc6751e0 Mon Sep 17 00:00:00 2001 From: Adam Young Date: Thu, 27 Jan 2011 20:30:22 -0500 Subject: [PATCH] aci rights widget Fixes is_dirty and save https://fedorahosted.org/freeipa/ticket/77 https://fedorahosted.org/freeipa/ticket/667 --- install/ui/aci.js

[Freeipa-devel] [PATCH] 0015 block anonymous access to sudo info

2011-01-27 Thread JR Aquino
Aci patch to block anonymous access to sudo info https://fedorahosted.org/freeipa/ticket/865 freeipa-jraquino-0015-block-anonymous-access-to-sudo-info.patch Description: freeipa-jraquino-0015-block-anonymous-access-to-sudo-info.patch ___ Freeipa-devel

Re: [Freeipa-devel] [PATCH] 0077 Fix ipactl script to manage all instances

2011-01-27 Thread Simo Sorce
On Thu, 27 Jan 2011 17:22:05 -0500 Rob Crittenden wrote: > Simo Sorce wrote: > > > > Ticket #860 > > > > Simo. > > > > ack. > pushed to master. Simo. -- Simo Sorce * Red Hat, Inc * New York ___ Freeipa-devel mailing list Freeipa-devel@redhat.com

[Freeipa-devel] [PATCH] 0078 Safeguard kdc account against misconfigurations

2011-01-27 Thread Simo Sorce
See ticket #862 Simo. -- Simo Sorce * Red Hat, Inc * New York >From 8c4e36edc4ab7965733aa82bd179cd1afc1aa85a Mon Sep 17 00:00:00 2001 From: Simo Sorce Date: Thu, 27 Jan 2011 15:15:19 -0500 Subject: [PATCH] Put some safeguards against misconfiguration on the kdc account Ticket: https://fedorah

Re: [Freeipa-devel] [PATCH] 0077 Fix ipactl script to manage all instances

2011-01-27 Thread Rob Crittenden
Simo Sorce wrote: Ticket #860 Simo. ack. ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel

[Freeipa-devel] [PATCH] 0077 Fix ipactl script to manage all instances

2011-01-27 Thread Simo Sorce
Ticket #860 Simo. -- Simo Sorce * Red Hat, Inc * New York >From 9a89ffcf05a59e92cec86f9a7b2b93f353ec2cb6 Mon Sep 17 00:00:00 2001 From: Simo Sorce Date: Thu, 27 Jan 2011 17:10:34 -0500 Subject: [PATCH] Make sure all DS instances are managed by ipactl Fixes: https://fedorahosted.org/freeipa/ti

[Freeipa-devel] [PATCH] 693 changes from Fedora review

2011-01-27 Thread Rob Crittenden
I pushed this patch that contains specfile changes pointed out in the Fedora package review process. rob >From 88e0d36d8ea341e4ac9a7733a66fae23917b07b2 Mon Sep 17 00:00:00 2001 From: Rob Crittenden Date: Thu, 27 Jan 2011 17:02:24 -0500 Subject: [PATCH] Apply changes discovered in Fedora package

Re: [Freeipa-devel] [PATCH] admiyo-0170-dirty

2011-01-27 Thread Adam Young
On 01/26/2011 10:03 PM, Adam Young wrote: Depends on 154, 154, 166, 167, 169 ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel ACKed in IRC by edewata and pushed to master __

Re: [Freeipa-devel] [PATCH] admiyo-0169-reset-target-section

2011-01-27 Thread Adam Young
On 01/27/2011 01:57 PM, Adam Young wrote: On 01/26/2011 04:52 PM, Adam Young wrote: ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel Rebased _

Re: [Freeipa-devel] [PATCH] admiyo-0167-adding-label-for-RBAC

2011-01-27 Thread Adam Young
On 01/27/2011 01:56 PM, Adam Young wrote: On 01/26/2011 04:14 PM, Kyle Baker wrote: ACK - Original Message - Role Based Access control is supposed to be spelled out in the tabs. An earlier patch also broke the Title for the RBAC Action Panel. This fixes both. Depends on all my previous

Re: [Freeipa-devel] [PATCH] 0008-Adjusted-aci-s-target-feilds-adjusted-action-panel-s

2011-01-27 Thread Adam Young
On 01/27/2011 03:18 PM, Kyle Baker wrote: ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel ACK and pushed to master ___ Freeipa-devel mailing list

Re: [Freeipa-devel] [PATCH] admiyo-0166-declarative-for-aci

2011-01-27 Thread Adam Young
On 01/27/2011 01:55 PM, Adam Young wrote: On 01/26/2011 04:18 PM, Adam Young wrote: On 01/26/2011 04:14 PM, Kyle Baker wrote: ACK - Original Message - Fixes https://fedorahosted.org/freeipa/ticket/772 Depends on freeipa-admiyo-0154-1-declarative-defintions.patch

Re: [Freeipa-devel] [PATCH] admiyo-0154-declarative-defintions

2011-01-27 Thread Adam Young
On 01/27/2011 12:12 PM, Adam Young wrote: On 01/26/2011 04:32 PM, Adam Young wrote: On 01/26/2011 12:37 PM, Adam Young wrote: Rebased on top of origin/master, and made changes. See comments below. On 01/20/2011 02:48 PM, Endi Sukma Dewata wrote: On 1/20/2011 11:10 PM, Adam Young wrote: If

[Freeipa-devel] [PATCH]admiyo-0172-default-disable-delete

2011-01-27 Thread Adam Young
For ticket https://fedorahosted.org/freeipa/ticket/668 From 664d5f27c9aa8954674bcab9ea89029b9f73d70c Mon Sep 17 00:00:00 2001 From: Adam Young Date: Thu, 27 Jan 2011 16:37:48 -0500 Subject: [PATCH 172/172] default disable delete --- install/ui/ipa.css | 16 install/ui/searc

[Freeipa-devel] [PATCH] admiyo-0171-entity-filter-text

2011-01-27 Thread Adam Young
Trivial patch, but want it to be reviewed. Just changes the text on the entity filter for select boxes From 7605b87e1136c40423bd7448bef2001fc8fbc117 Mon Sep 17 00:00:00 2001 From: Adam Young Date: Thu, 27 Jan 2011 15:21:35 -0500 Subject: [PATCH 171/172] entity filter text --- install/ui/aci.js

[Freeipa-devel] [PATCH] 0008-Adjusted-aci-s-target-feilds-adjusted-action-panel-s

2011-01-27 Thread Kyle Baker
From ec84d1de06ab1af5fdedc952695750efab4cd212 Mon Sep 17 00:00:00 2001 From: System Administrator Date: Thu, 27 Jan 2011 15:05:16 -0500 Subject: [PATCH] Adjusted aci's target feilds, adjusted action panel styles, adjusted Delegation and Configuration. --- install/ui/caution.png | Bin 438 -> 496

Re: [Freeipa-devel] [PATCH] Add support for account unlocking

2011-01-27 Thread Rob Crittenden
Jan Zelený wrote: Jan Zeleny wrote: This patch adds command ipa user-unlock and some LDAP modifications which are required by Kerberos for unlocking to work. Ticket: https://fedorahosted.org/freeipa/ticket/344 Jan Just a reminder that this patch needs a review. Thanks Jan This doesn't ap

Re: [Freeipa-devel] [PATCH] admiyo-0167-adding-label-for-RBAC

2011-01-27 Thread Adam Young
On 01/26/2011 04:14 PM, Kyle Baker wrote: ACK - Original Message - Role Based Access control is supposed to be spelled out in the tabs. An earlier patch also broke the Title for the RBAC Action Panel. This fixes both. Depends on all my previous patches _

Re: [Freeipa-devel] [PATCH] admiyo-0169-reset-target-section

2011-01-27 Thread Adam Young
On 01/26/2011 04:52 PM, Adam Young wrote: ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel Rebased From c37d4a2499281980c9a73034a91b012c8fc97fc5 Mon Sep 17 00:00:00 2001 From: Adam Young D

Re: [Freeipa-devel] [PATCH] admiyo-0166-declarative-for-aci

2011-01-27 Thread Adam Young
On 01/26/2011 04:18 PM, Adam Young wrote: On 01/26/2011 04:14 PM, Kyle Baker wrote: ACK - Original Message - Fixes https://fedorahosted.org/freeipa/ticket/772 Depends on freeipa-admiyo-0154-1-declarative-defintions.patch ___ Freeipa-devel m

[Freeipa-devel] [PATCH] 043 Fix API.txt

2011-01-27 Thread Jakub Hrozek
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 One of the recent API patches didn't update API.txt -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org/ iEYEARECAAYFAk1Bs3wACgkQHsardTLnvCVTmQCgy4fQy3n7x1XZuzZocyaNVfA3 3XIAoJ

[Freeipa-devel] [PATCH] 042 Enforce that all NS records are resolvable

2011-01-27 Thread Jakub Hrozek
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Bind cannot load a zone if any of its name server records is not resolvable. https://fedorahosted.org/freeipa/ticket/838 -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org/ i

Re: [Freeipa-devel] [PATCH] 0076 Fix ipa init script

2011-01-27 Thread Rob Crittenden
Simo Sorce wrote: When I created ipa.init I did it initially by copying the dirsrv init script. Remove any remaining reference to the dirsrv stuff. Ticket: #857 Simo. ack, pushed to master ___ Freeipa-devel mailing list Freeipa-devel@redhat.com htt

[Freeipa-devel] [PATCH] 0076 Fix ipa init script

2011-01-27 Thread Simo Sorce
When I created ipa.init I did it initially by copying the dirsrv init script. Remove any remaining reference to the dirsrv stuff. Ticket: #857 Simo. -- Simo Sorce * Red Hat, Inc * New York >From fc87f8d93bbd9dfeabd6301ef2b9ae7c67030703 Mon Sep 17 00:00:00 2001 From: Simo Sorce Date: Thu, 27 Ja

Re: [Freeipa-devel] [PATCH] 0074 Add requires

2011-01-27 Thread Dmitri Pal
On 01/27/2011 05:27 AM, Jan Zelený wrote: Simo Sorce wrote: First part of ticket #855 Add the requires we will need on F15, tested against jdennis ipa-devel repo, works as expected. Simo. The patch is obviously ok, so ack from this point of view. But I would just like to know if it is necess

Re: [Freeipa-devel] [PATCH] Fixed permission lookup

2011-01-27 Thread Jan Zelený
Rob Crittenden wrote: > Jan Zelený wrote: > > Martin Kosek wrote: > >> On Thu, 2011-01-27 at 11:15 +0100, Jan Zelený wrote: > >>> Lookup based on --filter wasn't implemented at all. It did't show until > >>> now, because of bug sitting on top of it which was resulting in > >>> internal error. Thi

Re: [Freeipa-devel] [PATCH] 0075 handle weird values in nolog

2011-01-27 Thread Simo Sorce
On Thu, 2011-01-27 at 11:43 +0100, Jan Zelený wrote: > > Ack, > but only a code inspection performed, since I'm not sure how to test > it > exactly. Pushed to master (I tested it extensively). Simo. -- Simo Sorce * Red Hat, Inc * New York ___ Freei

Re: [Freeipa-devel] [PATCH] 0074 Add requires

2011-01-27 Thread Simo Sorce
On Thu, 2011-01-27 at 11:27 +0100, Jan Zelený wrote: > The patch is obviously ok, so ack from this point of view. Pushed to master. Simo. -- Simo Sorce * Red Hat, Inc * New York ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redh

Re: [Freeipa-devel] [PATCH] Fixed permission lookup

2011-01-27 Thread Rob Crittenden
Jan Zelený wrote: Martin Kosek wrote: On Thu, 2011-01-27 at 11:15 +0100, Jan Zelený wrote: Lookup based on --filter wasn't implemented at all. It did't show until now, because of bug sitting on top of it which was resulting in internal error. This patch fixes the bug and adds the filtering fun

Re: [Freeipa-devel] [PATCH] 0074 Add requires

2011-01-27 Thread Rob Crittenden
Simo Sorce wrote: On Thu, 2011-01-27 at 11:27 +0100, Jan Zelený wrote: Simo Sorce wrote: First part of ticket #855 Add the requires we will need on F15, tested against jdennis ipa-devel repo, works as expected. Simo. The patch is obviously ok, so ack from this point of view. But I would ju

Re: [Freeipa-devel] [PATCH] 0075 handle weird values in nolog

2011-01-27 Thread Simo Sorce
On Thu, 2011-01-27 at 11:43 +0100, Jan Zelený wrote: > Simo Sorce wrote: > > When using ipa-replica-manage re-initialize with GSSAPI credentials it > > turns out that the DN password may be set to None and this can end up in > > the nolog list. > > > > Add a check to skip any non-string object in

Re: [Freeipa-devel] [PATCH] 0074 Add requires

2011-01-27 Thread Simo Sorce
On Thu, 2011-01-27 at 11:27 +0100, Jan Zelený wrote: > Simo Sorce wrote: > > First part of ticket #855 > > > > Add the requires we will need on F15, tested against jdennis ipa-devel > > repo, works as expected. > > > > Simo. > > The patch is obviously ok, so ack from this point of view. But I w

Re: [Freeipa-devel] [PATCH] 039 Delete the whole DNS record with no parameters

2011-01-27 Thread Jakub Hrozek
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/26/2011 09:50 PM, Simo Sorce wrote: > On Mon, 2011-01-24 at 15:51 +0100, Jakub Hrozek wrote: >> -BEGIN PGP SIGNED MESSAGE- >> Hash: SHA1 >> >> On 01/21/2011 05:54 PM, Rob Crittenden wrote: >>> Jakub Hrozek wrote: -BEGIN PGP SIGNE

Re: [Freeipa-devel] [PATCH] Fixed permission lookup

2011-01-27 Thread Jan Zelený
Martin Kosek wrote: > On Thu, 2011-01-27 at 11:15 +0100, Jan Zelený wrote: > > Lookup based on --filter wasn't implemented at all. It did't show until > > now, because of bug sitting on top of it which was resulting in internal > > error. This patch fixes the bug and adds the filtering functionali

Re: [Freeipa-devel] [PATCH] Fixed permission lookup

2011-01-27 Thread Martin Kosek
On Thu, 2011-01-27 at 11:15 +0100, Jan Zelený wrote: > Lookup based on --filter wasn't implemented at all. It did't show until > now, because of bug sitting on top of it which was resulting in internal > error. This patch fixes the bug and adds the filtering functionality. > > https://fedorahosted

[Freeipa-devel] [PATCH] 018 ipa permission-mod --rename does not work

2011-01-27 Thread Martin Kosek
This patch fixes nonfunctional rename operation in permission plugin. Also makes sure, that no change is made to the underlying ACI in pre_callback() when the target permission already exists. Several tests for the rename operation have been created to ensure that the it won't break again unnotice

Re: [Freeipa-devel] [PATCH] Changed dns permission types

2011-01-27 Thread Jan Zelený
Jan Zelený wrote: > Jan Zelený wrote: > > Rob Crittenden wrote: > > > Jan Zelený wrote: > > > > Rob Crittenden wrote: > > > >> Jan Zelený wrote: > > > >>> Recent change of DNS module to version caused that dns object type > > > >>> was replaced by dnszone and dnsrecord. This patch corrects dns

Re: [Freeipa-devel] [PATCH] 0075 handle weird values in nolog

2011-01-27 Thread Jan Zelený
Simo Sorce wrote: > When using ipa-replica-manage re-initialize with GSSAPI credentials it > turns out that the DN password may be set to None and this can end up in > the nolog list. > > Add a check to skip any non-string object in the log substitution list, > so that the code doesn't freak out

Re: [Freeipa-devel] [PATCH] 0074 Add requires

2011-01-27 Thread Jan Zelený
Simo Sorce wrote: > First part of ticket #855 > > Add the requires we will need on F15, tested against jdennis ipa-devel > repo, works as expected. > > Simo. The patch is obviously ok, so ack from this point of view. But I would just like to know if it is necessary. I just inspected F15 pki-ca

[Freeipa-devel] [PATCH] Fixed permission lookup

2011-01-27 Thread Jan Zelený
Lookup based on --filter wasn't implemented at all. It did't show until now, because of bug sitting on top of it which was resulting in internal error. This patch fixes the bug and adds the filtering functionality. https://fedorahosted.org/freeipa/ticket/818 -- Thank you Jan Zeleny Red Hat Soft