Re: [Freeipa-devel] [PATCH] #1820 Fix legacy password generation

2011-10-06 Thread Simo Sorce
On Thu, 2011-10-06 at 17:29 +0200, Jakub Hrozek wrote: On Mon, Sep 19, 2011 at 05:39:06PM -0400, Simo Sorce wrote: Today I found another regression in the kpasswd password change path. I filed ticket #1820 Legacy password hashes were not generated due to an issue with the list of

Re: [Freeipa-devel] [PATCH] 887 add missing aci prefix to dns acis

2011-10-06 Thread Rob Crittenden
Martin Kosek wrote: On Wed, 2011-10-05 at 17:18 -0400, Rob Crittenden wrote: The aci prefix was missing in the description of the three dns acis which made them not show up when viewing their permission entries. rob This works fine, but it is just a part of a solution. DNS related privileges

Re: [Freeipa-devel] [PATCH] 887 add missing aci prefix to dns acis

2011-10-06 Thread Rob Crittenden
Martin Kosek wrote: On Thu, 2011-10-06 at 14:05 -0400, Rob Crittenden wrote: Martin Kosek wrote: On Wed, 2011-10-05 at 17:18 -0400, Rob Crittenden wrote: The aci prefix was missing in the description of the three dns acis which made them not show up when viewing their permission entries. rob

Re: [Freeipa-devel] Upgrading due to proxy changes

2011-10-06 Thread Rob Crittenden
Adam Young wrote: Upgrading from a system that had an earlier version of IPA to the current is broken right now, due to the fact that the new code expects to talk to the Certificate Authority (CA) via the proxy ports (80, 443), and the old code used non standard ports (above 8000). IPA needs

[Freeipa-devel] [PATCH] 0286-split-metadata-call

2011-10-06 Thread Adam Young
Even if ACKed, don't push this patch alone. It is part of some work that Petr V is going to be doing as part of fixing https://fedorahosted.org/freeipa/ticket/1933. From b5b93109a9035557770f0959e21f4310bac5b7ba Mon Sep 17 00:00:00 2001 From: Adam Young ayo...@redhat.com Date: Thu, 6 Oct 2011

Re: [Freeipa-devel] [PATCH] 887 add missing aci prefix to dns acis

2011-10-06 Thread Rob Crittenden
Rob Crittenden wrote: Martin Kosek wrote: On Thu, 2011-10-06 at 14:05 -0400, Rob Crittenden wrote: Martin Kosek wrote: On Wed, 2011-10-05 at 17:18 -0400, Rob Crittenden wrote: The aci prefix was missing in the description of the three dns acis which made them not show up when viewing their

[Freeipa-devel] [PATCHES] 0287 and 0288 for Proxy upgrade

2011-10-06 Thread Adam Young
Not yet ready for prime time. I've tested the changes to updateinstance by hand, so I know they work. I'm having problems with the python import setup. RPM build fails with: install/tools/ipa-upgradeconfig:36: [F0401] Unable to import 'installutils' And, if I uncomment the import for

Re: [Freeipa-devel] [PATCH] 134 Improve handling of GIDs when migrating groups

2011-10-06 Thread Rob Crittenden
Martin Kosek wrote: On Wed, 2011-10-05 at 13:44 -0400, Rob Crittenden wrote: Martin Kosek wrote: Since IPA v2 server already contain predefined groups that may collide with groups in migrated (IPA v1) server (for example admins, ipausers), users having colliding group as their primary group

Re: [Freeipa-devel] [PATCHES] 0287 and 0288 for Proxy upgrade

2011-10-06 Thread Rob Crittenden
Adam Young wrote: Not yet ready for prime time. I've tested the changes to updateinstance by hand, so I know they work. I'm having problems with the python import setup. RPM build fails with: install/tools/ipa-upgradeconfig:36: [F0401] Unable to import 'installutils' And, if I uncomment

Re: [Freeipa-devel] [PATCH] 0019 Sync time with NTP before joining the domain

2011-10-06 Thread Rob Crittenden
Alexander Bokovoy wrote: On Wed, 05 Oct 2011, Rob Crittenden wrote: I ended up not using raiseonerr=False as all I needed is a way to break out of the loop on success so that will come sequentially if there is no exception. Patch attached. This works but there is a noticeable pause on my

Re: [Freeipa-devel] [PATCH] 138 Prevent collisions of hostgroup and netgroup

2011-10-06 Thread Rob Crittenden
Martin Kosek wrote: On Wed, 2011-10-05 at 16:43 -0400, Rob Crittenden wrote: Martin Kosek wrote: For every hostgroup a managed netgroup is created (if this is allowed). Make sure that if a stand-alone netgroup exists, a hostgroup with the same name cannot be created to prevent collisions.

[Freeipa-devel] [PATCH] 888 always verify hostname

2011-10-06 Thread Rob Crittenden
When installing with DNS we skip a few hostname checks on the assumption that the DNS we are installing will cover things. We still need to verify /etc/hosts and we do this with gethostbyname_ex() which returns the primary name and all other names of the host. If the primary name doesn't match

Re: [Freeipa-devel] [PATCH] 020 Fixed links to images in config and migration pages

2011-10-06 Thread Endi Sukma Dewata
On 10/6/2011 8:42 AM, Petr Vobornik wrote: https://fedorahosted.org/freeipa/ticket/1932 Description of problem: Title is missing while configuring browser for the first time. Actual results: There is no title on this screen. I noticed it only on step 8 and later so I am not sure if title is