[Freeipa-devel] new developer; development environment

2014-04-30 Thread Fraser Tweedale
Hi all, Fraser Tweedale, brand new Red Hatter, working in the Brisbane office on FreeIPA/Dogtag, and needing the wisdom of seasoned IPA developers on how best to set things up. In particular, is it common to be developing in VMs, and if so, do the various components (DS, Dogtag, IPA etc) under

Re: [Freeipa-devel] new developer; development environment

2014-04-30 Thread Alexander Bokovoy
On Wed, 30 Apr 2014, Fraser Tweedale wrote: Hi all, Fraser Tweedale, brand new Red Hatter, working in the Brisbane office on FreeIPA/Dogtag, and needing the wisdom of seasoned IPA developers on how best to set things up. Welcome Fraser! In particular, is it common to be developing in VMs,

Re: [Freeipa-devel] new developer; development environment

2014-04-30 Thread Martin Kosek
On 04/30/2014 08:21 AM, Fraser Tweedale wrote: Hi all, Fraser Tweedale, brand new Red Hatter, working in the Brisbane office on FreeIPA/Dogtag, and needing the wisdom of seasoned IPA developers on how best to set things up. In particular, is it common to be developing in VMs, and if so,

Re: [Freeipa-devel] new developer; development environment

2014-04-30 Thread Petr Spacek
On 30.4.2014 09:12, Martin Kosek wrote: On 04/30/2014 08:21 AM, Fraser Tweedale wrote: Hi all, Fraser Tweedale, brand new Red Hatter, working in the Brisbane office on FreeIPA/Dogtag, and needing the wisdom of seasoned IPA developers on how best to set things up. In particular, is it common

Re: [Freeipa-devel] [PATCH] 0543 - dns: Add idnsSecInlineSigning attribute, add --dnssec option to zone

2014-04-30 Thread thierry bordaz
On 04/29/2014 10:07 PM, Martin Kosek wrote: On 04/29/2014 08:17 PM, Simo Sorce wrote: On Tue, 2014-04-29 at 20:00 +0200, Petr Viktorin wrote: This adds the idnsSecInlineSigning attribute and related option. https://fedorahosted.org/freeipa/ticket/3801 Simo, is adding a MAY attribute to an

[Freeipa-devel] [PATCH] 589-590 webui-ci: save screenshot on test failure

2014-04-30 Thread Petr Vobornik
Very handy for debugging failures... New decorator: ui_driver.screenshot created. It should be applied on test methods. Screenshot is saved on each exception except SkipTest. Configuration: - add: `save_screenshots: True` to ~/.ipa/ui_test.conf to enable saving screenshots - optionally add

Re: [Freeipa-devel] [PATCH 0167] ipa-client-install: Configure sudo to use SSSD as data source

2014-04-30 Thread Tomas Babej
On 03/24/2014 03:27 PM, Jan Pazdziora wrote: On Mon, Mar 24, 2014 at 02:57:30PM +0100, Martin Kosek wrote: On 03/24/2014 02:47 PM, Jan Pazdziora wrote: On Mon, Mar 03, 2014 at 08:24:41PM +0100, Tomas Babej wrote: Hi, Makes ipa-client-install configure SSSD as the data provider for the sudo

[Freeipa-devel] [PATCH] 591 webui: add idnsSecInlineSigning option to DNS zone details facet

2014-04-30 Thread Petr Vobornik
Web UI part of pviktori-543 https://fedorahosted.org/freeipa/ticket/3801 -- Petr Vobornik From 2652953332ec5f5ee6f131a389168f5ee37099a5 Mon Sep 17 00:00:00 2001 From: Petr Vobornik pvobo...@redhat.com Date: Wed, 30 Apr 2014 12:24:25 +0200 Subject: [PATCH] webui: add idnsSecInlineSigning option

Re: [Freeipa-devel] [PATCH] 18 webui otptoken test data added

2014-04-30 Thread Petr Vobornik
On 29.4.2014 16:30, Misnyovszki Adam wrote: On Fri, 25 Apr 2014 17:16:48 +0200 Misnyovszki Adam amisn...@redhat.com wrote: Hi, this patch adds some static test data for the webui otptoken part. Adam Attached corrected DN's. Thanks Adam 1) Why otptoken_batch_del.json ends with error? Also

Re: [Freeipa-devel] [PATCH] 1106 IPA REST smart proxy

2014-04-30 Thread Petr Viktorin
On 04/30/2014 05:11 AM, Rob Crittenden wrote: Petr Viktorin wrote: On 04/29/2014 04:27 PM, Rob Crittenden wrote: Petr Viktorin wrote: On 04/23/2014 08:52 PM, Rob Crittenden wrote: Petr Viktorin wrote: On 04/09/2014 11:29 PM, Rob Crittenden wrote: Rob Crittenden wrote: Petr Viktorin wrote:

Re: [Freeipa-devel] [PATCH 0167] ipa-client-install: Configure sudo to use SSSD as data source

2014-04-30 Thread Jakub Hrozek
On Wed, Apr 30, 2014 at 11:05:52AM +0200, Tomas Babej wrote: On 03/24/2014 03:27 PM, Jan Pazdziora wrote: On Mon, Mar 24, 2014 at 02:57:30PM +0100, Martin Kosek wrote: On 03/24/2014 02:47 PM, Jan Pazdziora wrote: On Mon, Mar 03, 2014 at 08:24:41PM +0100, Tomas Babej wrote: Hi, Makes

[Freeipa-devel] [PATCHES 180-182] ipatests: Improvements!

2014-04-30 Thread Tomas Babej
Hi, * patch 180 fixes incorrect hostname usage when connecting to legacy clients * patch 181 sets up SSSD in debug_level 7 by default * patch 182 does the same, but on the legacy clients -- Tomas Babej Associate Software Engineer | Red Hat | Identity Management RHCE | Brno Site | IRC: tbabej |

Re: [Freeipa-devel] [PATCH 0034] Deny LDAP binds for user accounts with expired principal

2014-04-30 Thread Tomas Babej
On 01/07/2014 01:47 PM, Tomas Babej wrote: On 01/07/2014 07:23 AM, Alexander Bokovoy wrote: On Mon, 06 Jan 2014, Tomas Babej wrote: On 01/06/2014 12:16 PM, Tomas Babej wrote: On 04/15/2013 12:43 PM, Tomas Babej wrote: On 04/08/2013 03:55 PM, Martin Kosek wrote: On 04/01/2013 09:52 PM, Rob

Re: [Freeipa-devel] [PATCH 0138] ipalib: Expose krbPrincipalExpiration in CLI

2014-04-30 Thread Tomas Babej
On 04/25/2014 11:10 AM, Jan Cholasta wrote: On 22.4.2014 13:34, Tomas Babej wrote: Updated, rebased patch attached. This API.txt change belongs in the previous patch: +capability: datetime_values 2.84 Fixed, updated patch attached. I also added several tests for the user plugin that

Re: [Freeipa-devel] [PATCH 0137] ipalib: Add DateTime parameter

2014-04-30 Thread Tomas Babej
On 04/25/2014 11:08 AM, Jan Cholasta wrote: On 22.4.2014 13:32, Tomas Babej wrote: Thank you for the suggestions. Updated, rebased patch is attached. This API.txt change from the next patch belongs in this patch: +capability: datetime_values 2.84 I think you should use the

Re: [Freeipa-devel] new developer; development environment

2014-04-30 Thread Ade Lee
Welcome Fraser, To build dogtag, you should start here: http://pki.fedoraproject.org/wiki/Building_Dogtag_10 and I happen to know you'll be working on IPA/PKI stuff, you'll be interested in reviewing the links under: http://pki.fedoraproject.org/wiki/Dogtag#Resources_for_Client_Developers The

[Freeipa-devel] [PATCH] 0455 Replace replica admins read access ACI with a permission

2014-04-30 Thread Petr Viktorin
This should fix https://fedorahosted.org/freeipa/ticket/3829 -- PetrĀ³ From f5127411bdc21102022ed3d4849371501fc625f7 Mon Sep 17 00:00:00 2001 From: Petr Viktorin pvikt...@redhat.com Date: Mon, 28 Apr 2014 14:23:19 +0200 Subject: [PATCH] Replace replica admins read access ACI with a permission

[Freeipa-devel] [PATCH] 6 - Dogtag DRM -IPA plugin

2014-04-30 Thread Ade Lee
I have attached a patch that contains code for the new dogtag DRM plugin vault functionality. This patch should be applied on top of the ones used to install a DRM. Forthcoming is a patch to actually start using this plugin. Ade From cff819f1446492e3ab8cc151d2a8221475155ac9 Mon Sep 17 00:00:00

[Freeipa-devel] LDAP schema for DNSSEC keys

2014-04-30 Thread Petr Spacek
Hello list, following text summarizes schema DIT layout for DNSSEC key storage in LDAP. This is subset of full PKCS#11 schema [0]. It stores bare keys with few metadata attributes when necessary. The intention is to make transition to full PKCS#11-in-LDAP schema [0] as easy as possible.

[Freeipa-devel] [PATCHES] 0546-0547 Allow alternate aci keyword in ACIs

2014-04-30 Thread Petr Viktorin
Hello, The first patch adds == to ACI object to simplify comparisons. The second patch moves existing tests to the test suite. The third patch adds support for an alternate aci keyword that DS supports (but I couldn't get any documentaion on it). Dogtag adds ACIs with this keyword to

Re: [Freeipa-devel] [PATCHES] 0546-0547 Allow alternate aci keyword in ACIs

2014-04-30 Thread Rob Crittenden
Petr Viktorin wrote: Hello, The first patch adds == to ACI object to simplify comparisons. The second patch moves existing tests to the test suite. The third patch adds support for an alternate aci keyword that DS supports (but I couldn't get any documentaion on it). Dogtag adds ACIs with this

Re: [Freeipa-devel] [PATCHES] 0546-0547 Allow alternate aci keyword in ACIs

2014-04-30 Thread Petr Viktorin
On 04/30/2014 07:25 PM, Rob Crittenden wrote: Petr Viktorin wrote: Hello, The first patch adds == to ACI object to simplify comparisons. The second patch moves existing tests to the test suite. The third patch adds support for an alternate aci keyword that DS supports (but I couldn't get any

Re: [Freeipa-devel] [PATCH 0034] Deny LDAP binds for user accounts with expired principal

2014-04-30 Thread Simo Sorce
On Wed, 2014-04-30 at 17:07 +0200, Tomas Babej wrote: On 01/07/2014 01:47 PM, Tomas Babej wrote: On 01/07/2014 07:23 AM, Alexander Bokovoy wrote: On Mon, 06 Jan 2014, Tomas Babej wrote: On 01/06/2014 12:16 PM, Tomas Babej wrote: On 04/15/2013 12:43 PM, Tomas Babej wrote: On 04/08/2013

Re: [Freeipa-devel] [PATCH 0034] Deny LDAP binds for user accounts with expired principal

2014-04-30 Thread Alexander Bokovoy
On Wed, 30 Apr 2014, Simo Sorce wrote: Updated version attached. Tomas This version is rebased on top of OTP patches, addresses Simo's comments and brings unit tests to cover the functionality (however, they need to be applied on top of my patches 183-185). LGTM, but I haven't tested the

Re: [Freeipa-devel] [PATCH] 1106 IPA REST smart proxy

2014-04-30 Thread Petr Viktorin
On 04/30/2014 04:57 PM, Rob Crittenden wrote: Petr Viktorin wrote: On 04/30/2014 05:11 AM, Rob Crittenden wrote: Petr Viktorin wrote: On 04/29/2014 04:27 PM, Rob Crittenden wrote: Petr Viktorin wrote: On 04/23/2014 08:52 PM, Rob Crittenden wrote: Petr Viktorin wrote: On 04/09/2014 11:29

Re: [Freeipa-devel] [PATCHES] 0546-0547 Allow alternate aci keyword in ACIs

2014-04-30 Thread Petr Viktorin
On 04/30/2014 08:24 PM, Petr Viktorin wrote: On 04/30/2014 07:25 PM, Rob Crittenden wrote: Petr Viktorin wrote: Hello, The first patch adds == to ACI object to simplify comparisons. The second patch moves existing tests to the test suite. The third patch adds support for an alternate aci