Re: [Freeipa-devel] [PATCH 0017] Add OTP support to ipalib CLI

2013-09-14 Thread Jan Cholasta
On 13.9.2013 10:07, Jan Cholasta wrote: On 5.9.2013 06:25, Nathaniel McCallum wrote: This patch has a few problems that I'd like some help with. There are a few notes here as well. 1. The handling of the 'key' option is insecure. It should probably be treated like a password (hidden from logs,

Re: [Freeipa-devel] [PATCH 0016] Add RADIUS proxy support to ipalib CLI

2013-09-14 Thread Jan Cholasta
On 13.9.2013 09:21, Jan Cholasta wrote: Hi, On 12.9.2013 22:48, Nathaniel McCallum wrote: On Thu, 2013-09-05 at 00:06 -0400, Nathaniel McCallum wrote: patch attached Update for ./makeapi attached. +if 'ipatokenradiusconfiglink' in entry_attrs: +cl =

Re: [Freeipa-devel] Off Topic, was: [PATCH 0017] Add OTP support to ipalib CLI

2013-09-14 Thread Simo Sorce
On Fri, 2013-09-13 at 15:06 -0700, Henry B. Hotz wrote: On Sep 13, 2013, at 11:38 AM, Dmitri Pal d...@redhat.com wrote: , ipatokenotpalgorithm Uses default TOTP we do not support more for now. In future it will be a global policy I assume. This is just me, like the sig says. I

Re: [Freeipa-devel] [RFC] Improve FreeIPA usability in cloud environments

2013-09-14 Thread Simo Sorce
On Fri, 2013-09-13 at 14:26 -0400, Dmitri Pal wrote: On 09/13/2013 09:08 AM, Simo Sorce wrote: On Fri, 2013-09-13 at 10:26 +0200, Petr Spacek wrote: Hello list, FreeIPA deployments in cloud environments do not work very well because 'clouds' break some assumptions we made during