Re: [Freeipa-devel] [RFE] List of IPA realm domains

2013-02-07 Thread Petr Vobornik
On 02/06/2013 06:27 PM, Ana Krivokapic wrote: Hello, Below is a design page for ticket: https://fedorahosted.org/freeipa/ticket/2945. There are a couple of questions in the text. Thoughts, comments welcome! http://www.freeipa.org/page/V3/Realm_Domains Hello, I don't think we should make

Re: [Freeipa-devel] [PATCH] 1085 cert-find command

2013-02-07 Thread Petr Vobornik
On 02/06/2013 12:44 AM, Rob Crittenden wrote: This adds a cert-find command for the dogtag backend. Searches can be done by serial number, by subject, revocation reason, issue date, notbefore, notafter and revocation dates. I added some basic tests for this. I made it a separate test file

Re: [Freeipa-devel] [RFE] List of IPA realm domains

2013-02-07 Thread Sumit Bose
On Thu, Feb 07, 2013 at 10:55:28AM +0100, Petr Vobornik wrote: On 02/06/2013 06:27 PM, Ana Krivokapic wrote: Hello, Below is a design page for ticket: https://fedorahosted.org/freeipa/ticket/2945. There are a couple of questions in the text. Thoughts, comments welcome!

Re: [Freeipa-devel] [RFE] List of IPA realm domains

2013-02-07 Thread Petr Vobornik
On 02/07/2013 12:48 PM, Sumit Bose wrote: On Thu, Feb 07, 2013 at 10:55:28AM +0100, Petr Vobornik wrote: On 02/06/2013 06:27 PM, Ana Krivokapic wrote: ipa host-add command can be hooked to realmdomains-add-domain, to automatically add domain of added host to the list of domains associated

Re: [Freeipa-devel] [RFE] List of IPA realm domains

2013-02-07 Thread Sumit Bose
On Wed, Feb 06, 2013 at 06:27:26PM +0100, Ana Krivokapic wrote: Hello, Below is a design page for ticket: https://fedorahosted.org/freeipa/ticket/2945. There are a couple of questions in the text. about 'Do we also need to check if the domain is accessible through DNS?' I think it would

Re: [Freeipa-devel] [RFE] List of IPA realm domains

2013-02-07 Thread Petr Spacek
On 7.2.2013 13:38, Sumit Bose wrote: On Wed, Feb 06, 2013 at 06:27:26PM +0100, Ana Krivokapic wrote: Hello, Below is a design page for ticket: https://fedorahosted.org/freeipa/ticket/2945. There are a couple of questions in the text. about 'Do we also need to check if the domain is

Re: [Freeipa-devel] [RFE] List of IPA realm domains

2013-02-07 Thread Sumit Bose
On Thu, Feb 07, 2013 at 01:57:18PM +0100, Petr Spacek wrote: On 7.2.2013 13:38, Sumit Bose wrote: On Wed, Feb 06, 2013 at 06:27:26PM +0100, Ana Krivokapic wrote: Hello, Below is a design page for ticket: https://fedorahosted.org/freeipa/ticket/2945. There are a couple of questions in the

Re: [Freeipa-devel] [PATCH] 1085 cert-find command

2013-02-07 Thread Rob Crittenden
Petr Vobornik wrote: On 02/06/2013 12:44 AM, Rob Crittenden wrote: This adds a cert-find command for the dogtag backend. Searches can be done by serial number, by subject, revocation reason, issue date, notbefore, notafter and revocation dates. I added some basic tests for this. I made it a

Re: [Freeipa-devel] [PATCH] 362 Add LDAP server fallback to client installer

2013-02-07 Thread Rob Crittenden
Martin Kosek wrote: On 02/06/2013 04:12 PM, Rob Crittenden wrote: Martin Kosek wrote: On 02/05/2013 05:57 PM, Rob Crittenden wrote: Martin Kosek wrote: On 02/04/2013 05:59 PM, Rob Crittenden wrote: Martin Kosek wrote: When ipa-client-install is run without --server option, it tries to

Re: [Freeipa-devel] [PATCH] 362 Add LDAP server fallback to client installer

2013-02-07 Thread Martin Kosek
On 02/07/2013 04:03 PM, Rob Crittenden wrote: Martin Kosek wrote: On 02/06/2013 04:12 PM, Rob Crittenden wrote: Martin Kosek wrote: On 02/05/2013 05:57 PM, Rob Crittenden wrote: Martin Kosek wrote: On 02/04/2013 05:59 PM, Rob Crittenden wrote: Martin Kosek wrote: When ipa-client-install

[Freeipa-devel] [PATCH] Add delegation info to MS-PAC

2013-02-07 Thread Simo Sorce
This information is not strictly required but is part of the MS-PAC specification and I had some time to kill on the plane on my last trip back. I tested it briefly with cross-realm trusts and it seem to work fine. Neither IPA nor AD2012 complained when looking at PACs, do far. Simo. -- Simo

Re: [Freeipa-devel] [PATCH] 362 Add LDAP server fallback to client installer

2013-02-07 Thread Rob Crittenden
Martin Kosek wrote: On 02/07/2013 04:03 PM, Rob Crittenden wrote: Martin Kosek wrote: On 02/06/2013 04:12 PM, Rob Crittenden wrote: Martin Kosek wrote: On 02/05/2013 05:57 PM, Rob Crittenden wrote: Martin Kosek wrote: On 02/04/2013 05:59 PM, Rob Crittenden wrote: Martin Kosek wrote: When

Re: [Freeipa-devel] [PATCH] 1085 cert-find command

2013-02-07 Thread Jan Cholasta
Hi, On 6.2.2013 00:44, Rob Crittenden wrote: This adds a cert-find command for the dogtag backend. Searches can be done by serial number, by subject, revocation reason, issue date, notbefore, notafter and revocation dates. I added some basic tests for this. I made it a separate test file