[Freeipa-devel] Correct firewall ports for multi-master replicas

2014-07-12 Thread James
Hi freeipa-devel, I just added automatic firewalling for puppet-ipa. (Disclaimer it's currently untested...) What I'm missing is an exact and exhaustive list of exactly which ports each replica needs open for each other replica. I'm hoping that this list is symmetrical. If this list changes

Re: [Freeipa-devel] [PATCH 0158] Extend ipa-range-check DS plugin to handle range types

2014-07-12 Thread Lukas Slebodnik
On (01/04/14 10:52), Tomas Babej wrote: On 04/01/2014 10:40 AM, Alexander Bokovoy wrote: On Tue, 01 Apr 2014, Tomas Babej wrote: From 736b3f747188696fd4a46ca63d91a6cca942fd56 Mon Sep 17 00:00:00 2001 From: Tomas Babej tba...@redhat.com Date: Wed, 5 Mar 2014 12:28:18 +0100 Subject: [PATCH]

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-07-12 Thread Lukas Slebodnik
On (23/06/14 14:35), Simo Sorce wrote: - Original Message - - Original Message - Can you check if ipaProtectedOperation is in the aci attribute in the base tree object ? It should be there as excluded, and that should cause admin to not be able to retrieve keytabs.

[Freeipa-devel] [PATCH] Fix warning: Using uninitialized value ld.

2014-07-12 Thread Lukas Slebodnik
ehlo, If create_getkeytab_control fails variable uninitialized pointer 'ld' will be used in done section. Simple patch is attached. From 6d882d2ede4d639dde2883bb147f3921fc46ae1c Mon Sep 17 00:00:00 2001 From: Lukas Slebodnik lsleb...@redhat.com Date: Sat, 12 Jul 2014 18:18:21 +0200 Subject: