Re: [Freeipa-devel] [PATCH] 1106 IPA REST smart proxy

2014-02-18 Thread Dmitri Pal
On 02/18/2014 04:01 AM, Petr Viktorin wrote: On 02/18/2014 07:52 AM, Martin Kosek wrote: On 02/18/2014 12:11 AM, Dmitri Pal wrote: On 02/17/2014 04:57 PM, Rob Crittenden wrote: Dmitri Pal wrote: On 02/17/2014 04:13 PM, Rob Crittenden wrote: Dmitri Pal wrote: On 02/17/2014 02:33 PM, Rob Crit

Re: [Freeipa-devel] [PATCH] Permission MOD command fix

2014-02-18 Thread Martin Kosek
On 02/18/2014 06:52 PM, Petr Viktorin wrote: On 02/18/2014 06:46 PM, Jan Cholasta wrote: Hi, On 18.2.2014 18:40, Nathaniel McCallum wrote: On Tue, 2014-02-18 at 12:31 -0500, Adam Misnyovszki wrote: Hi, this patch fixes permission-mod command returning duplicate memberships. https://fedorahos

Re: [Freeipa-devel] [PATCH 0025] Add support to ipa-kdb for keyless principals

2014-02-18 Thread Alexander Bokovoy
On Tue, 12 Nov 2013, Nathaniel McCallum wrote: https://fedorahosted.org/freeipa/ticket/3779 From 8806c71c1925b697103fb21df4f937a7a05be74c Mon Sep 17 00:00:00 2001 From: Nathaniel McCallum Date: Tue, 12 Nov 2013 10:52:51 -0500 Subject: [PATCH] Add support to ipa-kdb for keyless principals

Re: [Freeipa-devel] [PATCH 0025] Add support to ipa-kdb for keyless principals

2014-02-18 Thread Nathaniel McCallum
On Tue, 2013-11-12 at 10:59 -0500, Nathaniel McCallum wrote: > https://fedorahosted.org/freeipa/ticket/3779 This patch still needs a reviewer. It is very small. Nathaniel ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/ma

Re: [Freeipa-devel] [PATCH 0035] ipa-kdb: validate that an OTP user has tokens

2014-02-18 Thread Nathaniel McCallum
On Tue, 2014-02-18 at 14:48 -0500, Nathaniel McCallum wrote: > On Thu, 2014-02-06 at 11:02 -0500, Nathaniel McCallum wrote: > > This patch is independent of any of my other patches and can be merged > > out of order. > > This patch still needs a reviewer. It is very small. Oops! I replied to the

Re: [Freeipa-devel] [PATCH 0035] ipa-kdb: validate that an OTP user has tokens

2014-02-18 Thread Nathaniel McCallum
On Thu, 2014-02-06 at 11:02 -0500, Nathaniel McCallum wrote: > This patch is independent of any of my other patches and can be merged > out of order. This patch still needs a reviewer. It is very small. Nathaniel ___ Freeipa-devel mailing list Freeipa-

Re: [Freeipa-devel] [PATCH] Permission MOD command fix

2014-02-18 Thread Petr Viktorin
On 02/18/2014 06:46 PM, Jan Cholasta wrote: Hi, On 18.2.2014 18:40, Nathaniel McCallum wrote: On Tue, 2014-02-18 at 12:31 -0500, Adam Misnyovszki wrote: Hi, this patch fixes permission-mod command returning duplicate memberships. https://fedorahosted.org/freeipa/ticket/4175 NACK This patch

Re: [Freeipa-devel] [PATCH] Permission MOD command fix

2014-02-18 Thread Jan Cholasta
Hi, On 18.2.2014 18:40, Nathaniel McCallum wrote: On Tue, 2014-02-18 at 12:31 -0500, Adam Misnyovszki wrote: Hi, this patch fixes permission-mod command returning duplicate memberships. https://fedorahosted.org/freeipa/ticket/4175 NACK This patch does not apply to master. Nathaniel The t

Re: [Freeipa-devel] [PATCH] Permission MOD command fix

2014-02-18 Thread Nathaniel McCallum
On Tue, 2014-02-18 at 12:31 -0500, Adam Misnyovszki wrote: > Hi, > this patch fixes permission-mod command returning duplicate memberships. > > https://fedorahosted.org/freeipa/ticket/4175 NACK This patch does not apply to master. Nathaniel ___ Freei

[Freeipa-devel] [PATCH] Permission MOD command fix

2014-02-18 Thread Adam Misnyovszki
Hi, this patch fixes permission-mod command returning duplicate memberships. https://fedorahosted.org/freeipa/ticket/4175 Thanks AdamFrom a9b88eba0dd6e261cf294bbc330b798dc8831fb4 Mon Sep 17 00:00:00 2001 From: Misnyovszki Adam Date: Tue, 18 Feb 2014 18:27:01 +0100 Subject: [PATCH] Permission MOD

Re: [Freeipa-devel] [PATCH 0015] Add wait_for_dns option to default.conf

2014-02-18 Thread Martin Basti
On Tue, 2014-02-18 at 16:45 +0100, Petr Spacek wrote: > Hello, > > Add wait_for_dns option to default.conf. > > This option makes record changes in DNS tree synchronous. > IPA calls will wait until new data are visible over DNS protocol. > > It is intended only for testing - it should prevent te

Re: [Freeipa-devel] [PATCH 0220] Move temporary files to /var/named/dyndb-ldap directory

2014-02-18 Thread Nathaniel McCallum
On Tue, 2014-02-18 at 09:58 +0100, Petr Spacek wrote: > On 28.1.2014 16:45, Petr Spacek wrote: > > Hello, > > > > Move temporary files to /var/named/dyndb-ldap directory. > > > > This should make RPM packaging easier. > > > > This patch should go to master branch before 4.0 release. > > This versi

Re: [Freeipa-devel] [PATCH 0015] Add wait_for_dns option to default.conf

2014-02-18 Thread Nathaniel McCallum
On Tue, 2014-02-18 at 17:06 +0100, Petr Viktorin wrote: > On 02/18/2014 04:45 PM, Petr Spacek wrote: > > Hello, > > > > Add wait_for_dns option to default.conf. > > > > This option makes record changes in DNS tree synchronous. > > IPA calls will wait until new data are visible over DNS protocol. >

Re: [Freeipa-devel] DNSSEC design page

2014-02-18 Thread Martin Kosek
On 02/18/2014 04:38 PM, Jan Cholasta wrote: > On 18.2.2014 16:35, Petr Spacek wrote: >> On 18.2.2014 16:31, Jan Cholasta wrote: >> >> 2] low level replacement for eg the sqlite3 database in softhsm. >> That's what I sometimes get the impression what is wanted. SoftHsm has >> one com

Re: [Freeipa-devel] [PATCH 0015] Add wait_for_dns option to default.conf

2014-02-18 Thread Petr Viktorin
On 02/18/2014 04:45 PM, Petr Spacek wrote: Hello, Add wait_for_dns option to default.conf. This option makes record changes in DNS tree synchronous. IPA calls will wait until new data are visible over DNS protocol. It is intended only for testing - it should prevent tests from failing if there

[Freeipa-devel] [PATCH 0015] Add wait_for_dns option to default.conf

2014-02-18 Thread Petr Spacek
Hello, Add wait_for_dns option to default.conf. This option makes record changes in DNS tree synchronous. IPA calls will wait until new data are visible over DNS protocol. It is intended only for testing - it should prevent tests from failing if there is bigger delay between change in LDAP and

Re: [Freeipa-devel] [PATCH 0023 Do not display ports to open when password is incorrect during ipa-client-install

2014-02-18 Thread Martin Kosek
On 04/30/2013 04:33 PM, Petr Viktorin wrote: > On 04/30/2013 04:03 PM, Ana Krivokapic wrote: >> On 04/30/2013 10:42 AM, Petr Viktorin wrote: >>> On 04/23/2013 12:17 PM, Ana Krivokapic wrote: On 04/23/2013 12:06 AM, Rob Crittenden wrote: > Ana Krivokapic wrote: >> Do not display ports t

Re: [Freeipa-devel] DNSSEC design page

2014-02-18 Thread Jan Cholasta
On 18.2.2014 16:35, Petr Spacek wrote: On 18.2.2014 16:31, Jan Cholasta wrote: 2] low level replacement for eg the sqlite3 database in softhsm. That's what I sometimes get the impression what is wanted. SoftHsm has one component Softdatabase with an API, which more or less passes sets of attrib

Re: [Freeipa-devel] DNSSEC design page

2014-02-18 Thread Petr Spacek
On 18.2.2014 16:31, Jan Cholasta wrote: 2] low level replacement for eg the sqlite3 database in softhsm. That's what I sometimes get the impression what is wanted. SoftHsm has one component Softdatabase with an API, which more or less passes sets of attributes (attributes defined by PKCS#11) and

Re: [Freeipa-devel] DNSSEC design page

2014-02-18 Thread Jan Cholasta
On 18.2.2014 16:23, Rob Crittenden wrote: Jan Cholasta wrote: Hi, On 18.2.2014 14:02, Ludwig Krispenz wrote: Hi, yesterday jan asked me about the status of the schema and if it would be ready for certificate storage an dthat puzzled me a bit and showed that I still do not really understand wh

Re: [Freeipa-devel] DNSSEC design page

2014-02-18 Thread Rob Crittenden
Jan Cholasta wrote: Hi, On 18.2.2014 14:02, Ludwig Krispenz wrote: Hi, yesterday jan asked me about the status of the schema and if it would be ready for certificate storage an dthat puzzled me a bit and showed that I still do not really understand what you want to store in LDAP. Two me there

Re: [Freeipa-devel] [PATCH 0013-0014] Modify DNS tests to workaround bug in python-dns

2014-02-18 Thread Petr Viktorin
On 02/17/2014 03:42 PM, Petr Spacek wrote: Hello, I have found bug in python-dns and consequently another bug in LOC record parsing in IPA. See commit messages. My next patch for 'wait_for_dns' functionality (required for bind-dyndb-ldap 4.0) depends on these fixes. 0013 - ACK 0014 - ACK Pus

Re: [Freeipa-devel] DNSSEC design page

2014-02-18 Thread Jan Cholasta
Hi, On 18.2.2014 14:02, Ludwig Krispenz wrote: Hi, yesterday jan asked me about the status of the schema and if it would be ready for certificate storage an dthat puzzled me a bit and showed that I still do not really understand what you want to store in LDAP. Two me there are two very differen

Re: [Freeipa-devel] [PATCH 0221] Make getcwd() calls safer

2014-02-18 Thread Tomas Hozza
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 02/18/2014 10:34 AM, Petr Spacek wrote: > ewer GCC complains that I didn't check return value from getcwd() ... Hi. I reviewed all patches from "PATCH 0181" to the latest one "PATCH 0221" and tested the bind-dyndb-ldap on Fedora 20 (adding/removin

Re: [Freeipa-devel] [Patch] [DOC] documentation patches

2014-02-18 Thread Petr Viktorin
On 02/18/2014 08:41 AM, Alexander Bokovoy wrote: On Mon, 17 Feb 2014, Darth Vader wrote: Hi all, I have a couple of documentation patches that need to be reviewed. Probably the biggest one would be the upgrade procedure as what was in the docs was outdated. I can break these out in separate ema

Re: [Freeipa-devel] DNSSEC design page

2014-02-18 Thread Ludwig Krispenz
Hi, yesterday jan asked me about the status of the schema and if it would be ready for certificate storage an dthat puzzled me a bit and showed that I still do not really understand what you want to store in LDAP. Two me there are two very different approaches. 1] LDAP as store for high level

[Freeipa-devel] [PATCH 0221] Make getcwd() calls safer

2014-02-18 Thread Petr Spacek
Hello, Make getcwd() calls safer. Newer GCC complains that I didn't check return value from getcwd() ... -- Petr^2 Spacek From 39940f692e42313c7301c12c49d76003482d7e11 Mon Sep 17 00:00:00 2001 From: Petr Spacek Date: Tue, 18 Feb 2014 10:33:15 +0100 Subject: [PATCH] Make getcwd() calls safer.

Re: [Freeipa-devel] [PATCHES] OTP Patches

2014-02-18 Thread Alexander Bokovoy
On Tue, 18 Feb 2014, Petr Viktorin wrote: On 02/17/2014 06:17 PM, Alexander Bokovoy wrote: On Mon, 17 Feb 2014, Nathaniel McCallum wrote: On Wed, 2014-02-12 at 11:49 -0500, Nathaniel McCallum wrote: Through the review process, patches are getting shifted around, added, deleted, etc. So I'm now

Re: [Freeipa-devel] [PATCHES] OTP Patches

2014-02-18 Thread Petr Viktorin
On 02/17/2014 06:17 PM, Alexander Bokovoy wrote: On Mon, 17 Feb 2014, Nathaniel McCallum wrote: On Wed, 2014-02-12 at 11:49 -0500, Nathaniel McCallum wrote: Through the review process, patches are getting shifted around, added, deleted, etc. So I'm now just going to be posting all the patches a

Re: [Freeipa-devel] [PATCH] 1106 IPA REST smart proxy

2014-02-18 Thread Petr Viktorin
On 02/18/2014 07:52 AM, Martin Kosek wrote: On 02/18/2014 12:11 AM, Dmitri Pal wrote: On 02/17/2014 04:57 PM, Rob Crittenden wrote: Dmitri Pal wrote: On 02/17/2014 04:13 PM, Rob Crittenden wrote: Dmitri Pal wrote: On 02/17/2014 02:33 PM, Rob Crittenden wrote: Dmitri Pal wrote: On 02/17/201

Re: [Freeipa-devel] [PATCH 0220] Move temporary files to /var/named/dyndb-ldap directory

2014-02-18 Thread Petr Spacek
On 28.1.2014 16:45, Petr Spacek wrote: Hello, Move temporary files to /var/named/dyndb-ldap directory. This should make RPM packaging easier. This patch should go to master branch before 4.0 release. This version fixes packaging problems found by Tomas Hozza. -- Petr^2 Spacek From a52962e15

Re: [Freeipa-devel] [PATCHES] 0464-0466 Multivalued targetfilter

2014-02-18 Thread Martin Kosek
On 02/13/2014 01:12 PM, Petr Viktorin wrote: > Hello, > These patches fix https://fedorahosted.org/freeipa/ticket/4074 > Design: > http://www.freeipa.org/page/V3/Multivalued_target_filters_in_permissions > > > Since --type, affects only targetfilter values in the form "(objectclass=...)" > and l

Re: [Freeipa-devel] [PATCH]

2014-02-18 Thread Petr Viktorin
On 02/18/2014 08:40 AM, Alexander Bokovoy wrote: On Mon, 17 Feb 2014, Darth Vader wrote: Hi all, This patch fixes the spelling for hostname in ipa-join instructions. Since it is just a spelling change, I figured the one-liner rule would work and a push to the master would be okay; however, I wa