Re: [Freeipa-devel] [PATCH 0060] Fix ipa-getkeytab for pre-4.0 servers

2014-07-25 Thread Martin Kosek
On 07/24/2014 05:12 PM, Nathaniel McCallum wrote: On Thu, 2014-07-24 at 17:19 +0300, Alexander Bokovoy wrote: On Thu, 24 Jul 2014, Nathaniel McCallum wrote: Also, make the error messages for this fallback case less scary and clean up some indentation issues in the nearby code which made this

Re: [Freeipa-devel] [PATCH] 478 Allow hashed passwords in DS

2014-07-25 Thread Alexander Bokovoy
On Wed, 23 Jul 2014, Martin Kosek wrote: See related thread #4450: how to allow password migration? for more information. --- Without nsslapd-allow-hashed-passwords being turned on, user password migration fails. https://fedorahosted.org/freeipa/ticket/4450 ACK, also given that Bryce

Re: [Freeipa-devel] ipa-replica-manage and topology plugin

2014-07-25 Thread James
On Fri, 2014-07-25 at 10:13 +0200, Ludwig Krispenz wrote: Hi, I am working on ticket #4302 and am building a protoptype to verify if the current design [1] will work an what is missing. Now the question comes up, how will this be managed and what happens with eg ipa-replica-manage ? If

Re: [Freeipa-devel] [PATCH] 478 Allow hashed passwords in DS

2014-07-25 Thread Martin Kosek
On 07/25/2014 10:26 AM, Alexander Bokovoy wrote: On Wed, 23 Jul 2014, Martin Kosek wrote: See related thread #4450: how to allow password migration? for more information. --- Without nsslapd-allow-hashed-passwords being turned on, user password migration fails.

Re: [Freeipa-devel] [PATCH 0057] Add TOTP watermark support

2014-07-25 Thread Martin Kosek
On 07/25/2014 10:24 AM, Alexander Bokovoy wrote: On Fri, 11 Jul 2014, Nathaniel McCallum wrote: This prevents the reuse of TOTP tokens by recording the last token interval that was used. This will be replicated as normal. However, this patch does not increase the number of writes to the

[Freeipa-devel] Releasing FreeIPA 4.0.1

2014-07-25 Thread Martin Kosek
Hello, As I mentioned earlier, I would like to very soon release FreeIPA 4.0.1 containing the first bunch of stabilization fixes in 4.0 branch. One of the most critical ones were client installation and migration issues which blocked some of our users. Those are now fixed. This is the candidate

[Freeipa-devel] [PATCH] 716 baseldap: return 'none' attr level right as unicode string

2014-07-25 Thread Petr Vobornik
Returning non-unicode causes serialization into base64 which causes havoc in Web UI. https://fedorahosted.org/freeipa/ticket/4454 IMHO we should fix JSON-RPC serialization to encode non-unicode strings to normal JSON strings. -- Petr Vobornik From 1158e43ad6fd9107390f14a00b95c61ce489ff20

Re: [Freeipa-devel] Releasing FreeIPA 4.0.1

2014-07-25 Thread Ludwig Krispenz
On 07/25/2014 12:23 PM, Martin Kosek wrote: Hello, As I mentioned earlier, I would like to very soon release FreeIPA 4.0.1 containing the first bunch of stabilization fixes in 4.0 branch. One of the most critical ones were client installation and migration issues which blocked some of our

Re: [Freeipa-devel] Releasing FreeIPA 4.0.1

2014-07-25 Thread Alexander Bokovoy
On Fri, 25 Jul 2014, Ludwig Krispenz wrote: On 07/25/2014 12:23 PM, Martin Kosek wrote: Hello, As I mentioned earlier, I would like to very soon release FreeIPA 4.0.1 containing the first bunch of stabilization fixes in 4.0 branch. One of the most critical ones were client installation and

Re: [Freeipa-devel] ipa-replica-manage and topology plugin

2014-07-25 Thread Ludwig Krispenz
On 07/25/2014 10:29 AM, James wrote: On Fri, 2014-07-25 at 10:13 +0200, Ludwig Krispenz wrote: Hi, I am working on ticket #4302 and am building a protoptype to verify if the current design [1] will work an what is missing. Now the question comes up, how will this be managed and what happens

Re: [Freeipa-devel] [PATCH] 716 baseldap: return 'none' attr level right as unicode string

2014-07-25 Thread Petr Vobornik
On 25.7.2014 13:02, Alexander Bokovoy wrote: On Fri, 25 Jul 2014, Petr Vobornik wrote: Returning non-unicode causes serialization into base64 which causes havoc in Web UI. https://fedorahosted.org/freeipa/ticket/4454 ACK for this patch. Pushed to: master:

Re: [Freeipa-devel] Releasing FreeIPA 4.0.1

2014-07-25 Thread Martin Kosek
On 07/25/2014 01:19 PM, Alexander Bokovoy wrote: On Fri, 25 Jul 2014, Ludwig Krispenz wrote: On 07/25/2014 12:23 PM, Martin Kosek wrote: Hello, As I mentioned earlier, I would like to very soon release FreeIPA 4.0.1 containing the first bunch of stabilization fixes in 4.0 branch. One of the

Re: [Freeipa-devel] ipa-replica-manage and topology plugin

2014-07-25 Thread Rob Crittenden
Ludwig Krispenz wrote: Hi, I am working on ticket #4302 and am building a protoptype to verify if the current design [1] will work an what is missing. Now the question comes up, how will this be managed and what happens with eg ipa-replica-manage ? If the topology plugin is deployed and

[Freeipa-devel] Announcing FreeIPA 4.0.1

2014-07-25 Thread Martin Kosek
The FreeIPA team is proud to announce FreeIPA v4.0.1! It can be downloaded from http://www.freeipa.org/page/Downloads. The builds are available for Fedora 21 or in an unofficial Fedora 20 [https://copr.fedoraproject.org/coprs/pviktori/freeipa/ COPR repository]. These release notes can be read

Re: [Freeipa-devel] LDAP schema for DNSSEC keys

2014-07-25 Thread Petr Spacek
On 17.7.2014 10:30, Jan Cholasta wrote: On 16.7.2014 17:13, Petr Spacek wrote: On 24.6.2014 08:43, Jan Cholasta wrote: On 20.6.2014 20:23, Simo Sorce wrote: On Fri, 2014-06-20 at 20:04 +0200, Petr Spacek wrote: ipk11Private;privatekey: TRUE ipk11Private;publickey: FALSE can these two ever

Re: [Freeipa-devel] DNSSEC key metadata handling

2014-07-25 Thread Petr Spacek
On 18.6.2014 19:19, Petr Spacek wrote: On 13.6.2014 18:43, Petr Spacek wrote: On 12.6.2014 17:49, Petr Spacek wrote: On 12.6.2014 17:19, Simo Sorce wrote: On Thu, 2014-06-12 at 17:08 +0200, Petr Spacek wrote: Hello list, I have realized that we need to store certain DNSSEC metadata for

[Freeipa-devel] DNSSEC feature status (with pictures!)

2014-07-25 Thread Petr Spacek
Hello list, Now you have unique chance to stop me before I really implement something (:-), I'm leaving DNSSEC world for a while. I will resume work after two weeks of silence. Status == We (Martin Basti and me) have encountered various problems on our way to DNSSEC feature, you can

Re: [Freeipa-devel] [PATCH] webui: 696 support wildcard attribute level rights

2014-07-25 Thread Endi Sukma Dewata
On 7/21/2014 6:35 AM, Petr Vobornik wrote: https://fedorahosted.org/freeipa/ticket/4380 This is the original if-condition: (!rights !(that.flags.indexOf('w_if_no_aci') -1 write_oc)) || (rights rights.indexOf('w') 0) Here if 'rights' has a value but there's no 'w' in

Re: [Freeipa-devel] [PATCH] 709 webui: fix nested items creation in dropdown list

2014-07-25 Thread Endi Sukma Dewata
On 7/21/2014 6:51 AM, Petr Vobornik wrote: Items nested in other items were created in root list instead of nested list. Note: this feature is not used in current UI but it's likely to be used by a plugin ACK. -- Endi S. Dewata ___ Freeipa-devel

Re: [Freeipa-devel] [PATCH] 713-714 webui: replace action_buttons with action_widget

2014-07-25 Thread Endi Sukma Dewata
On 7/23/2014 8:26 AM, Petr Vobornik wrote: [PATCH] 713 webui: replace action_buttons with action_widget Simplify code base by reuse of 'disable' feature of button_widget. All occurrences of action-button which were disabled/enabled were replaced by button-widget.

Re: [Freeipa-devel] [PATCH] 712 webui: detach facet nodes

2014-07-25 Thread Endi Sukma Dewata
On 7/23/2014 8:25 AM, Petr Vobornik wrote: Detach/attach facet nodes when switching facets instead of hiding/showing. Keeps dom-tree more simple. This patch is not really needed. I implemented it while testing something in IE. But it might have positive effect for poorly written parts of Web

Re: [Freeipa-devel] [PATCH] 710 webui: review pending operation after expired session

2014-07-25 Thread Endi Sukma Dewata
On 7/23/2014 8:16 AM, Petr Vobornik wrote: Disable automatic re-execution of command after pending authentication. It's possible to enable it again globally by 'freeipa/config':`rpc_retry_auth`. https://fedorahosted.org/freeipa/ticket/4374 # Additional info: This ticket is in 4.0

Re: [Freeipa-devel] [PATCH] 711 webui: internet explorer fixes

2014-07-25 Thread Endi Sukma Dewata
On 7/24/2014 11:36 AM, Petr Vobornik wrote: On 23.7.2014 15:17, Petr Vobornik wrote: Fixed: 1. IE doesn't support value 'initial' in CSS rule. 2. setting innerHTML='' also destroys content of child nodes in LoginScreen in IE - reattached buttons have no text. Should go into 4.0 Milestone

Re: [Freeipa-devel] [PATCH] 715 webui: add bounce url to reset_password.html

2014-07-25 Thread Endi Sukma Dewata
On 7/23/2014 9:59 AM, Petr Vobornik wrote: reset_password.html now redirects browser to URL specified in 'redirect' uri component (if present). The component has to be URI encoded. ie (in browser console): $ encodeURIComponent('http://pvoborni.fedorapeople.org/doc/#!/guide/Debugging') --