Re: [Freeipa-devel] DNS SOA serial managed by 389 DS plugin: design

2013-02-12 Thread Petr Spacek
On 11.2.2013 17:23, Simo Sorce wrote: On Mon, 2013-02-11 at 15:37 +0100, Petr Spacek wrote: Possible optimization Increment serial value at most once per second. Basic idea: Write current timestamp (no incrementation) and write serial value to the database with one second delay. Problem: How

[Freeipa-devel] [PATCH] 370 ipa-kdb: remove memory leaks

2013-02-12 Thread Martin Kosek
All known memory leaks caused by unfreed allocated memory or unfreed LDAP results (which should be also done after unsuccessful searches) are fixed. One ipadb_need_retry result check was fixed as this function returns trust in case of a need for retry and not a zero.

[Freeipa-devel] [PATCH 0111] Automatically reload invalid zone after each change in zone data

2013-02-12 Thread Petr Spacek
Hello, Automatically reload invalid zone after each change in zone data. https://fedorahosted.org/bind-dyndb-ldap/ticket/102 How to test: # create a invalid zone, e.g. zone without A records for names in NS records ipa dnszone-add zone.test --admin-email=blah.nonsense

[Freeipa-devel] [PATCH 0112] Make log messages related to Kerberos more verbose

2013-02-12 Thread Petr Spacek
Hello, Make log messages related to Kerberos more verbose. This change should help people supporting bind-dyndb-ldap to figure out what is happening under covers. -- Petr^2 Spacek From a7cae08cacad019852067dd7ecf86cefbe35c70e Mon Sep 17 00:00:00 2001 From: Petr Spacek pspa...@redhat.com

Re: [Freeipa-devel] [PATCH] 370 ipa-kdb: remove memory leaks

2013-02-12 Thread Sumit Bose
On Tue, Feb 12, 2013 at 12:24:48PM +0100, Martin Kosek wrote: All known memory leaks caused by unfreed allocated memory or unfreed LDAP results (which should be also done after unsuccessful searches) are fixed. One ipadb_need_retry result check was fixed as this function returns trust in

Re: [Freeipa-devel] More types of replicas in FreeIPA

2013-02-12 Thread Simo Sorce
On Mon, 2013-02-11 at 20:30 -0500, Dmitri Pal wrote: On 02/11/2013 03:21 PM, Simo Sorce wrote: On Mon, 2013-02-11 at 21:03 +0100, Ondrej Hamada wrote: Dne 3.2.2013 02:51, Dmitri Pal napsal(a): On 01/31/2013 06:09 PM, Ondrej Hamada wrote: Hello, I'm starting to work on my thesis about

Re: [Freeipa-devel] [PATCH] 370 ipa-kdb: remove memory leaks

2013-02-12 Thread Simo Sorce
On Tue, 2013-02-12 at 12:24 +0100, Martin Kosek wrote: Comments inline. --- a/daemons/ipa-kdb/ipa_kdb_common.c +++ b/daemons/ipa-kdb/ipa_kdb_common.c @@ -172,7 +172,7 @@ krb5_error_code ipadb_simple_search(struct ipadb_context *ipactx, /* first test if we need to retry to connect */

Re: [Freeipa-devel] [PATCH] 361 ipa-adtrust-install should ask for SID generation

2013-02-12 Thread Martin Kosek
On 02/12/2013 04:48 PM, Alexander Bokovoy wrote: On Fri, 01 Feb 2013, Martin Kosek wrote: On 01/31/2013 07:06 PM, Alexander Bokovoy wrote: On Thu, 31 Jan 2013, Martin Kosek wrote: On 01/31/2013 04:29 PM, Alexander Bokovoy wrote: On Thu, 31 Jan 2013, Martin Kosek wrote: When

Re: [Freeipa-devel] [PATCH] 255 Added Web UI support for service PAC type option: NONE

2013-02-12 Thread Petr Vobornik
On 02/12/2013 05:14 PM, Endi Sukma Dewata wrote: On 2/8/2013 7:27 AM, Petr Vobornik wrote: Checkbox for NONE option was added. https://fedorahosted.org/freeipa/ticket/3404 Patches for master and 3.1 branch attached. ACK. We were discussing to NACK this approach. The implementation

Re: [Freeipa-devel] [PATCH 0030] Add option to specify SID using domain name to idrange-add/mod

2013-02-12 Thread Alexander Bokovoy
On Fri, 08 Feb 2013, Tomas Babej wrote: On 02/08/2013 03:25 PM, Alexander Bokovoy wrote: On Mon, 04 Feb 2013, Tomas Babej wrote: Hi, When adding/modifying an ID range for a trusted domain, the newly added option --dom-name can be used. This looks up SID of the trusted domain in LDAP and

Re: [Freeipa-devel] [PATCH] 255 Added Web UI support for service PAC type option: NONE

2013-02-12 Thread Endi Sukma Dewata
On 2/12/2013 10:56 AM, Petr Vobornik wrote: We were discussing to NACK this approach. The implementation should be improved because of the mutually exclusive nature of NONE option with [MS-PAC, PAD] options. I think we should add spec definition (to Web UI only, or into server plugin as well)

Re: [Freeipa-devel] More types of replicas in FreeIPA

2013-02-12 Thread Dmitri Pal
On 02/12/2013 08:20 AM, Simo Sorce wrote: On Mon, 2013-02-11 at 20:30 -0500, Dmitri Pal wrote: On 02/11/2013 03:21 PM, Simo Sorce wrote: On Mon, 2013-02-11 at 21:03 +0100, Ondrej Hamada wrote: Dne 3.2.2013 02:51, Dmitri Pal napsal(a): On 01/31/2013 06:09 PM, Ondrej Hamada wrote: Hello, I'm