Re: [Freeipa-devel] [PATCH 0073] Remove support for IPA deployments with no persistent search

2013-07-16 Thread Petr Spacek
On 15.7.2013 18:36, Martin Kosek wrote: On 07/15/2013 06:28 PM, Simo Sorce wrote: On Mon, 2013-07-15 at 16:41 +0200, Petr Spacek wrote: On 15.7.2013 16:15, Simo Sorce wrote: On Mon, 2013-07-15 at 15:57 +0200, Martin Kosek wrote: On 07/15/2013 03:44 PM, Petr Spacek wrote: On 15.7.2013 15:31,

[Freeipa-devel] [PATCH 0175-0177] Prepare transition from persistent search to RFC 4533

2013-07-16 Thread Petr Spacek
Hello, this patch set changes default configuration to 'psearch yes' and changes README and informational messages accordingly. -- Petr^2 Spacek From b6eb73072b501a646c90e591c3fb7421ab011bd3 Mon Sep 17 00:00:00 2001 From: Petr Spacek pspa...@redhat.com Date: Tue, 16 Jul 2013 09:43:23 +0200

[Freeipa-devel] [PATCH 0178-0179] Preparation for 3.5 release

2013-07-16 Thread Petr Spacek
Hello, I plan to release 3.5 as soon as all previous patches are ACKed. -- Petr^2 Spacek From 1c73120c82ddf52c70b16aabde4cf249ed2ec148 Mon Sep 17 00:00:00 2001 From: Petr Spacek pspa...@redhat.com Date: Tue, 16 Jul 2013 10:11:00 +0200 Subject: [PATCH] Update NEWS file for upcoming 3.5 release.

Re: [Freeipa-devel] [PATCH] slapi-nis support for trusted domains

2013-07-16 Thread Jakub Hrozek
On Mon, Jul 15, 2013 at 08:30:03PM +0300, Alexander Bokovoy wrote: Hi! Attached please find two patches against slapi-nis 0.47 to serve trusted domain users and groups to old clients. FreeIPA master needs to be enabled with this, see my patch 0108 (on freeipa-devel@). The patches add both

Re: [Freeipa-devel] [PATCH] 410-411 Drop selinux subpackage

2013-07-16 Thread Martin Kosek
On 06/17/2013 05:38 PM, Martin Kosek wrote: On 06/14/2013 01:25 PM, Petr Viktorin wrote: On 06/13/2013 03:29 PM, Martin Kosek wrote: All SELinux policy needed by FreeIPA server is now part of the global system SELinux policy which makes the subpackage redundant and slowing down the

Re: [Freeipa-devel] [PATCH] slapi-nis support for trusted domains

2013-07-16 Thread Alexander Bokovoy
Hi! On Tue, 16 Jul 2013, Jakub Hrozek wrote: +AC_ARG_WITH(sss_nss_idmap, + AS_HELP_STRING([--with-sss-nss-idmap], [use libsss_nss_idmap]), + use_sss_nss_idmap=$withval,use_sss_nss_idmap=AUTO) +if pkg-config sss_nss_idmap 2 /dev/null ; then + if test

Re: [Freeipa-devel] [PATCHES] 0039-0040 systemd ipactl fixes

2013-07-16 Thread Martin Kosek
On 07/15/2013 03:27 PM, Alexander Bokovoy wrote: On Mon, 15 Jul 2013, Martin Kosek wrote: On 07/11/2013 05:03 PM, Alexander Bokovoy wrote: On Thu, 11 Jul 2013, Ana Krivokapic wrote: On 07/11/2013 11:38 AM, Alexander Bokovoy wrote: On Thu, 11 Jul 2013, Alexander Bokovoy wrote: On Wed, 10 Jul

Re: [Freeipa-devel] [PATCH] 422-424 Web UI integration tests

2013-07-16 Thread Ana Krivokapic
On 07/16/2013 10:52 AM, Petr Vobornik wrote: On 07/09/2013 05:37 PM, Ana Krivokapic wrote: On 06/21/2013 10:56 AM, Petr Vobornik wrote: Sending an initial implementation of Web UI integration tests. The effort is documented at http://www.freeipa.org/page/Web_UI_Integration_Tests . The

Re: [Freeipa-devel] [PATCH 0075] Change group ownership of CRL publish directory

2013-07-16 Thread Martin Kosek
On 06/27/2013 10:20 AM, Martin Kosek wrote: On 06/21/2013 02:18 PM, Tomas Babej wrote: On 06/21/2013 02:15 PM, Martin Kosek wrote: On 06/21/2013 02:11 PM, Tomas Babej wrote: On 06/20/2013 06:00 PM, Simo Sorce wrote: On Thu, 2013-06-20 at 17:47 +0200, Martin Kosek wrote: On 06/20/2013 05:44

Re: [Freeipa-devel] [PATCH] 422-424 Web UI integration tests

2013-07-16 Thread Ana Krivokapic
On 07/16/2013 12:54 PM, Petr Vobornik wrote: On 07/16/2013 12:33 PM, Ana Krivokapic wrote: On 07/16/2013 10:52 AM, Petr Vobornik wrote: On 07/09/2013 05:37 PM, Ana Krivokapic wrote: On 06/21/2013 10:56 AM, Petr Vobornik wrote: Sending an initial implementation of Web UI integration tests. The

Re: [Freeipa-devel] [PATCH] 412 Remove entitlement support

2013-07-16 Thread Martin Kosek
On 07/11/2013 05:02 PM, Alexander Bokovoy wrote: On Thu, 27 Jun 2013, Martin Kosek wrote: On 06/27/2013 12:32 PM, Jan Cholasta wrote: On 26.6.2013 14:03, Tomas Babej wrote: On 06/19/2013 10:31 AM, Petr Vobornik wrote: On 06/19/2013 10:13 AM, Martin Kosek wrote: Entitlements code was not

Re: [Freeipa-devel] [PATCH] 422-424 Web UI integration tests

2013-07-16 Thread Petr Vobornik
On 07/16/2013 12:58 PM, Ana Krivokapic wrote: On 07/16/2013 12:54 PM, Petr Vobornik wrote: On 07/16/2013 12:33 PM, Ana Krivokapic wrote: On 07/16/2013 10:52 AM, Petr Vobornik wrote: On 07/09/2013 05:37 PM, Ana Krivokapic wrote: On 06/21/2013 10:56 AM, Petr Vobornik wrote: Sending an initial

Re: [Freeipa-devel] [PATCH 0072] Provide ipa-client-advise tool

2013-07-16 Thread Jan Cholasta
On 21.6.2013 11:45, Tomas Babej wrote: Newly added features: - options propagated to plugins - made plugin content creation more comfortable, now 3 classes of output are available (debug, comment, command) Now pretty much everything that comes into my mind is addressed, so please have

Re: [Freeipa-devel] [PATCH] slapi-nis support for trusted domains

2013-07-16 Thread Jakub Hrozek
On Tue, Jul 16, 2013 at 01:23:41PM +0300, Alexander Bokovoy wrote: Hi! On Tue, 16 Jul 2013, Jakub Hrozek wrote: +AC_ARG_WITH(sss_nss_idmap, + AS_HELP_STRING([--with-sss-nss-idmap], [use libsss_nss_idmap]), + use_sss_nss_idmap=$withval,use_sss_nss_idmap=AUTO) +if pkg-config

Re: [Freeipa-devel] [PATCHES] 0230-0244 Integration testing framework

2013-07-16 Thread Jan Cholasta
On 15.7.2013 16:43, Petr Viktorin wrote: On 07/11/2013 01:28 PM, Jan Cholasta wrote: On 10.7.2013 17:50, Petr Viktorin wrote: Yes, I believe that for the integration tests it's better to see what is going on. Both for manual runs, and also this way the information is more easily picked up by

Re: [Freeipa-devel] [PATCH] 0108 Add support for compatibility tree for trusted domain users

2013-07-16 Thread Jakub Hrozek
On Mon, Jul 15, 2013 at 08:14:52PM +0300, Alexander Bokovoy wrote: Hi! Attached patch allows to enable serving trusted domain users and groups through Schema Compatibilty plugin. The patch only does FreeIPA master configuration settings, the real work is done by the changes to slapi-nis

Re: [Freeipa-devel] [PATCH] 0108 Add support for compatibility tree for trusted domain users

2013-07-16 Thread Alexander Bokovoy
On Tue, 16 Jul 2013, Jakub Hrozek wrote: the patch looks mostly good to me. I only have some small nitpicks: +++ b/install/tools/man/ipa-adtrust-install.1 @@ -106,6 +106,24 @@ The password of the user with administrative privileges for this IPA server. Wil .TP The credentials of the admin

[Freeipa-devel] [PATCH 0078] Refactor the interactive prompt logic in idrange_add

2013-07-16 Thread Tomas Babej
Hi, Make the interactive prompts interpret the following logic: - AD range (dom-sid/dom-name set): require RID base if not set - local range(dom-sid/dom-name not set): a) server with adtrust support: require both RID base and secondary RID base b) server without adtrust

Re: [Freeipa-devel] [PATCH 0078] Refactor the interactive prompt logic in idrange_add

2013-07-16 Thread Tomas Babej
On Tuesday 16 of July 2013 17:11:46 Tomas Babej wrote: Hi, Make the interactive prompts interpret the following logic: - AD range (dom-sid/dom-name set): require RID base if not set - local range(dom-sid/dom-name not set): a) server with adtrust support: require

Re: [Freeipa-devel] DNSSEC support design considerations: key material handling

2013-07-16 Thread Petr Spacek
On 15.7.2013 21:07, Simo Sorce wrote: On Mon, 2013-07-15 at 16:58 +0200, Petr Spacek wrote: The remaining part is mostly about key management. Following text mentions 'DNSSEC keys' many times, so I tried to summarize how keys are used in DNSSEC. Feel free to skip it. == DNSSEC theory == Each

Re: [Freeipa-devel] [PATCH] slapi-nis support for trusted domains

2013-07-16 Thread Jakub Hrozek
On Tue, Jul 16, 2013 at 03:33:49PM +0300, Alexander Bokovoy wrote: On Tue, 16 Jul 2013, Jakub Hrozek wrote: On Tue, Jul 16, 2013 at 01:23:41PM +0300, Alexander Bokovoy wrote: Hi! On Tue, 16 Jul 2013, Jakub Hrozek wrote: +AC_ARG_WITH(sss_nss_idmap, +

Re: [Freeipa-devel] [PATCH] 0108 Add support for compatibility tree for trusted domain users

2013-07-16 Thread Jakub Hrozek
On Tue, Jul 16, 2013 at 04:22:01PM +0300, Alexander Bokovoy wrote: On Tue, 16 Jul 2013, Jakub Hrozek wrote: the patch looks mostly good to me. I only have some small nitpicks: +++ b/install/tools/man/ipa-adtrust-install.1 @@ -106,6 +106,24 @@ The password of the user with administrative

[Freeipa-devel] [PATCH] 0045 Expose ipaRangeType in Web UI

2013-07-16 Thread Ana Krivokapic
Hello, This patch addresses ticket https://fedorahosted.org/freeipa/ticket/3759. -- Regards, Ana Krivokapic Associate Software Engineer FreeIPA team Red Hat Inc. From 9966b24cde9c2368543a6f37d036cbba0da6f00e Mon Sep 17 00:00:00 2001 From: Ana Krivokapic akriv...@redhat.com Date: Tue, 16 Jul