Re: [Freeipa-devel] [PATCH 0008] Typo in warning message where IPA realm and domain name differ

2014-03-05 Thread Petr Viktorin
On 03/04/2014 01:48 AM, Simo Sorce wrote: On Mon, 2014-03-03 at 17:20 -0700, Gabe Alford wrote: Hi all, Quick one line change to fix. https://fedorahosted.org/freeipa/ticket/4211 ACK Simo. Pushed to master: b50cdd55af8af7fdf30a822dce03af68969ddfe6 -- PetrĀ³

Re: [Freeipa-devel] [PATCH] 545 webui: Don't act on keyboard events which originated in, different dialog

2014-03-05 Thread Petr Viktorin
On 03/04/2014 05:56 PM, Adam Misnyovszki wrote: - Original Message - From: Adam Misnyovszki amisn...@redhat.com To: Petr Vobornik pvobo...@redhat.com Cc: freeipa-devel freeipa-devel@redhat.com Sent: Tuesday, March 4, 2014 5:27:21 PM Subject: Re: [Freeipa-devel] [PATCH] 545 webui:

Re: [Freeipa-devel] [PATCHES] 0337-0343 YAML test configuration

2014-03-05 Thread Petr Viktorin
On 03/04/2014 04:59 PM, Tomas Babej wrote: Thanks, PATCH 341: ACK (this is the last remaining ACK for this patchset) Also pushed to ipa-3-3: 23814f9b57794a5f2f8ae62a3342ee18535df2ea On 03/04/2014 11:58 AM, Petr Viktorin wrote: On 03/03/2014 01:41 PM, Tomas Babej wrote: Finally got to

Re: [Freeipa-devel] [PATCHES] 0337-0343 YAML test configuration

2014-03-05 Thread Petr Viktorin
On 03/04/2014 04:59 PM, Tomas Babej wrote: Thanks, PATCH 341: ACK (this is the last remaining ACK for this patchset) Thank you! Pushed to master: 561e57d12169cfa4e1d2c5d9fef42b149c37fca2 On 03/04/2014 11:58 AM, Petr Viktorin wrote: On 03/03/2014 01:41 PM, Tomas Babej wrote: Finally got

Re: [Freeipa-devel] [PATCH 0042] Rework how otptoken defaults are handled

2014-03-05 Thread Petr Viktorin
On 03/03/2014 01:14 PM, Jan Cholasta wrote: On 21.2.2014 17:45, Nathaniel McCallum wrote: On Fri, 2014-02-21 at 16:29 +0100, Jan Cholasta wrote: Hi, On 21.2.2014 16:09, Nathaniel McCallum wrote: On Fri, 2014-02-21 at 09:45 -0500, Nathaniel McCallum wrote: We had originally decided to

Re: [Freeipa-devel] [PATCH 0045] Fix token secret length RFC compliance

2014-03-05 Thread Petr Viktorin
On 03/03/2014 05:19 PM, Jan Cholasta wrote: On 3.3.2014 17:13, Nathaniel McCallum wrote: RFC 4226 states the following in section 4: R6 - The algorithm MUST use a strong shared secret. The length of the shared secret MUST be at least 128 bits. This document RECOMMENDs a shared

Re: [Freeipa-devel] [PATCH] 0145: trust fix filtering of users from subdomains

2014-03-05 Thread Martin Kosek
On 03/04/2014 05:12 PM, Simo Sorce wrote: On Tue, 2014-03-04 at 11:33 +0200, Alexander Bokovoy wrote: On Tue, 04 Mar 2014, Martin Kosek wrote: On 03/04/2014 10:13 AM, Alexander Bokovoy wrote: Attached patch should fix https://fedorahosted.org/freeipa/ticket/4207 where we didn't filter out

Re: [Freeipa-devel] DNSSEC design page: key wrapping

2014-03-05 Thread Petr Spacek
On 5.3.2014 08:48, Jan Cholasta wrote: On 5.3.2014 05:10, Simo Sorce wrote: On Tue, 2014-03-04 at 18:32 -0500, Dmitri Pal wrote: Remote means that there is a PKCS#11 library that can be loaded into a process and would remotely connect to a central server via LDAP/REST/whatever. My point is

Re: [Freeipa-devel] [PATCH 0154] man: sshd should be run at least once before client

2014-03-05 Thread Jan Pazdziora
On Mon, Feb 24, 2014 at 02:58:13PM +0100, Tomas Babej wrote: Hi, If SSH keys have not been generated prior to enrolling the client to the IPA server, they will not be uploaded to the server, since they're not present. Clarify this issue in the man pages.

Re: [Freeipa-devel] [PATCH 0154] man: sshd should be run at least once before client

2014-03-05 Thread Tomas Babej
Thanks Jan, both fixed. Tomas On 03/05/2014 10:53 AM, Jan Pazdziora wrote: On Mon, Feb 24, 2014 at 02:58:13PM +0100, Tomas Babej wrote: Hi, If SSH keys have not been generated prior to enrolling the client to the IPA server, they will not be uploaded to the server, since they're not

Re: [Freeipa-devel] [PATCH 0154] man: sshd should be run at least once before client

2014-03-05 Thread Jan Pazdziora
On Wed, Mar 05, 2014 at 12:33:01PM +0100, Tomas Babej wrote: Thanks Jan, both fixed. Ack. -- Jan Pazdziora Principal Software Engineer, Identity Management Engineering, Red Hat ___ Freeipa-devel mailing list Freeipa-devel@redhat.com

Re: [Freeipa-devel] [PATCH 0154] man: sshd should be run at least once before client

2014-03-05 Thread Martin Kosek
On 03/05/2014 12:37 PM, Jan Pazdziora wrote: On Wed, Mar 05, 2014 at 12:33:01PM +0100, Tomas Babej wrote: Thanks Jan, both fixed. Ack. Pushed to master: 6b94f959a4d41b62ca6c2b273633880bbfab8b49 Thanks, Martin ___ Freeipa-devel mailing list

Re: [Freeipa-devel] DNSSEC design page: key wrapping

2014-03-05 Thread Martin Kosek
On 03/04/2014 11:14 PM, Petr Spacek wrote: On 4.3.2014 22:53, Simo Sorce wrote: On Tue, 2014-03-04 at 22:38 +0100, Petr Spacek wrote: On 4.3.2014 22:15, Simo Sorce wrote: On Tue, 2014-03-04 at 21:25 +0100, Petr Spacek wrote: ... I guess my only reservation is about whether DRM storage is

Re: [Freeipa-devel] [PATCH 0137] ipalib: Add DateTime parameter

2014-03-05 Thread Jan Cholasta
On 25.2.2014 11:15, Tomas Babej wrote: On 01/14/2014 10:19 AM, Petr Viktorin wrote: On 01/14/2014 09:27 AM, Jan Cholasta wrote: On 13.1.2014 14:57, Petr Vobornik wrote: On 13.1.2014 13:41, Jan Cholasta wrote: Hi, On 10.1.2014 21:21, Nathaniel McCallum wrote: On Thu, 2014-01-09 at 16:30

Re: [Freeipa-devel] [PATCH 0138] ipalib: Expose krbPrincipalExpiration in CLI

2014-03-05 Thread Jan Cholasta
On 25.2.2014 08:34, Tomas Babej wrote: Rebased to current master. On 01/09/2014 04:31 PM, Tomas Babej wrote: Hi, Adds a krbPrincipalExpiration attribute to the user class in user.py ipalib plugin as a DateTime parameter. Part of: https://fedorahosted.org/freeipa/ticket/3306 The patch

Re: [Freeipa-devel] [PATCHES] 0473-0477 Managed permission updater, part 1

2014-03-05 Thread Petr Viktorin
On 03/03/2014 04:10 PM, Petr Viktorin wrote: On 02/28/2014 02:47 PM, Petr Viktorin wrote: On 02/28/2014 02:12 PM, Martin Kosek wrote: On 02/26/2014 10:44 AM, Petr Viktorin wrote: Hello, Here are a few fixes/improvements, and the first part of a managed permission updater. The patches should

Re: [Freeipa-devel] DNSSEC design page: key wrapping

2014-03-05 Thread Simo Sorce
On Wed, 2014-03-05 at 10:53 +0100, Petr Spacek wrote: On 5.3.2014 08:48, Jan Cholasta wrote: On 5.3.2014 05:10, Simo Sorce wrote: On Tue, 2014-03-04 at 18:32 -0500, Dmitri Pal wrote: Remote means that there is a PKCS#11 library that can be loaded into a process and would remotely connect

[Freeipa-devel] [PATCH] 0487 ipalib.plugable: Always set the parser in bootstrap()

2014-03-05 Thread Petr Viktorin
Hello, This patch fixes a failing test setup where logging was configured before the API was bootstrapped. The __setattr__ is moved before a conditional return. -- PetrĀ³ From d90395f3c7dc54efda49355976155bd56dc2259d Mon Sep 17 00:00:00 2001 From: Petr Viktorin pvikt...@redhat.com Date: Wed, 5

Re: [Freeipa-devel] DNSSEC design page: key wrapping

2014-03-05 Thread Simo Sorce
On Wed, 2014-03-05 at 13:05 +0100, Martin Kosek wrote: On 03/04/2014 11:14 PM, Petr Spacek wrote: On 4.3.2014 22:53, Simo Sorce wrote: On Tue, 2014-03-04 at 22:38 +0100, Petr Spacek wrote: On 4.3.2014 22:15, Simo Sorce wrote: On Tue, 2014-03-04 at 21:25 +0100, Petr Spacek wrote: ... I

Re: [Freeipa-devel] DNSSEC design page: key wrapping

2014-03-05 Thread Jan Cholasta
On 5.3.2014 14:21, Simo Sorce wrote: On Wed, 2014-03-05 at 10:53 +0100, Petr Spacek wrote: On 5.3.2014 08:48, Jan Cholasta wrote: On 5.3.2014 05:10, Simo Sorce wrote: On Tue, 2014-03-04 at 18:32 -0500, Dmitri Pal wrote: Remote means that there is a PKCS#11 library that can be loaded into a

Re: [Freeipa-devel] LDAP schema for PKCS#11

2014-03-05 Thread Stef Walter
On 03.03.2014 15:24, Jan Cholasta wrote: On 3.3.2014 15:07, Stef Walter wrote: On 03.03.2014 15:03, Jan Cholasta wrote: If you plug a PKCS#11 module into p11-kit, will p11-kit use NSS trust objects from the module? No. This is the spec for storing trust policy in PKCS#11 that we've been

Re: [Freeipa-devel] [PATCH] 0235 tests: Use ipa-getkeytab from /usr/sbin instead of the in-tree one

2014-03-05 Thread Petr Viktorin
On 09/24/2013 05:34 PM, Petr Viktorin wrote: On 06/04/2013 05:48 PM, Simo Sorce wrote: On Tue, 2013-06-04 at 17:24 +0200, Petr Viktorin wrote: On 06/04/2013 02:53 PM, Simo Sorce wrote: On Tue, 2013-06-04 at 13:48 +0200, Petr Viktorin wrote: Hardcoding the in-tree location for ipa-getkeytab

Re: [Freeipa-devel] DNSSEC design page: key wrapping

2014-03-05 Thread Petr Spacek
On 5.3.2014 14:21, Simo Sorce wrote: On Wed, 2014-03-05 at 10:53 +0100, Petr Spacek wrote: On 5.3.2014 08:48, Jan Cholasta wrote: On 5.3.2014 05:10, Simo Sorce wrote: On Tue, 2014-03-04 at 18:32 -0500, Dmitri Pal wrote: Remote means that there is a PKCS#11 library that can be loaded into a

Re: [Freeipa-devel] LDAP schema for PKCS#11

2014-03-05 Thread Derek Moore
In your descriptions, can you translate all acronyms according to: http://www.cryptsoft.com/pkcs11doc/v220/group__SEC__5__SYMBOLS__AND__ABBREVIATIONS.html ...and... http://www.cryptsoft.com/pkcs11doc/v220/group__SEC__10__2__COMMON__ATTRIBUTES.html E.g., instead of saying

Re: [Freeipa-devel] DNSSEC design page: key wrapping

2014-03-05 Thread Martin Kosek
On 03/05/2014 03:04 PM, Simo Sorce wrote: On Wed, 2014-03-05 at 13:05 +0100, Martin Kosek wrote: On 03/04/2014 11:14 PM, Petr Spacek wrote: On 4.3.2014 22:53, Simo Sorce wrote: On Tue, 2014-03-04 at 22:38 +0100, Petr Spacek wrote: On 4.3.2014 22:15, Simo Sorce wrote: On Tue, 2014-03-04 at

Re: [Freeipa-devel] [PATCH] 0487 ipalib.plugable: Always set the parser in bootstrap()

2014-03-05 Thread Jan Cholasta
On 5.3.2014 14:51, Petr Viktorin wrote: Hello, This patch fixes a failing test setup where logging was configured before the API was bootstrapped. The __setattr__ is moved before a conditional return. ACK, the test failures are gone. -- Jan Cholasta

Re: [Freeipa-devel] DNSSEC design page: key wrapping

2014-03-05 Thread Simo Sorce
On Wed, 2014-03-05 at 16:29 +0100, Martin Kosek wrote: On 03/05/2014 03:04 PM, Simo Sorce wrote: On Wed, 2014-03-05 at 13:05 +0100, Martin Kosek wrote: On 03/04/2014 11:14 PM, Petr Spacek wrote: On 4.3.2014 22:53, Simo Sorce wrote: On Tue, 2014-03-04 at 22:38 +0100, Petr Spacek wrote:

[Freeipa-devel] [PATCH] 0488 tests: Create the testing service certificate on demand

2014-03-05 Thread Petr Viktorin
Hello, This transforms the make-testcert command into a module that creates the certificate when it is first needed. As a result the tests are more self-contained, and can be run from a read-only location (such as from the freeipa-tests package). With 0235, 0487, and this patch, `ipa-run-tests`

Re: [Freeipa-devel] DNSSEC design page: key wrapping

2014-03-05 Thread Jan Cholasta
On 5.3.2014 16:02, Petr Spacek wrote: On 5.3.2014 14:21, Simo Sorce wrote: On Wed, 2014-03-05 at 10:53 +0100, Petr Spacek wrote: On 5.3.2014 08:48, Jan Cholasta wrote: On 5.3.2014 05:10, Simo Sorce wrote: On Tue, 2014-03-04 at 18:32 -0500, Dmitri Pal wrote: Remote means that there is a

Re: [Freeipa-devel] LDAP schema for PKCS#11

2014-03-05 Thread Jan Cholasta
On 5.3.2014 13:20, Stef Walter wrote: On 03.03.2014 15:24, Jan Cholasta wrote: On 3.3.2014 15:07, Stef Walter wrote: On 03.03.2014 15:03, Jan Cholasta wrote: If you plug a PKCS#11 module into p11-kit, will p11-kit use NSS trust objects from the module? No. This is the spec for storing trust