Re: [Freeipa-devel] [PATCH 0131-0132] Add missing attributes to named.conf

2014-10-10 Thread David Kupka
On 10/03/2014 12:45 PM, Martin Basti wrote: Hello! Patch 131: https://fedorahosted.org/freeipa/ticket/3801#comment:31 Patch 132: I modified named.conf in 131, so I change the rest of paths to be ipaplatform specified. Patches attached ___

Re: [Freeipa-devel] [PATCH] 352 Fix certmonger configuration in installer code

2014-10-10 Thread Martin Kosek
On 10/09/2014 03:56 PM, David Kupka wrote: On 10/08/2014 01:23 PM, Jan Cholasta wrote: Dne 8.10.2014 v 12:27 Jan Cholasta napsal(a): Hi, the attached patch fixes https://fedorahosted.org/freeipa/ticket/4619. Honza Forgot to delete a line in dogtaginstance.py (thanks to David for noticing).

Re: [Freeipa-devel] [PATCH] 352 Fix certmonger configuration in installer code

2014-10-10 Thread David Kupka
On 10/10/2014 08:50 AM, Martin Kosek wrote: On 10/09/2014 03:56 PM, David Kupka wrote: On 10/08/2014 01:23 PM, Jan Cholasta wrote: Dne 8.10.2014 v 12:27 Jan Cholasta napsal(a): Hi, the attached patch fixes https://fedorahosted.org/freeipa/ticket/4619. Honza Forgot to delete a line in

Re: [Freeipa-devel] [PATCH] [WIP] DNSSEC support - preview

2014-10-10 Thread Martin Kosek
On 10/09/2014 03:57 PM, Petr Spacek wrote: Hello, it would be great if people could look at current state of DNSSEC patches for FreeIPA. It consist of several relatively independent parts: - python-pkcs#11 interface written by Martin Basti: https://github.com/spacekpe/freeipa-pkcs11 - DNSSEC

Re: [Freeipa-devel] [PATCH 0064] Create ipa-otp-decrement 389DS plugin

2014-10-10 Thread Martin Kosek
On 10/09/2014 06:48 PM, thierry bordaz wrote: On 10/09/2014 05:51 PM, Nathaniel McCallum wrote: On Thu, 2014-10-09 at 11:44 +0200, thierry bordaz wrote: On 10/09/2014 12:15 AM, Nathaniel McCallum wrote: On Wed, 2014-10-08 at 17:19 -0400, Simo Sorce wrote: On Wed, 08 Oct 2014 15:53:39 -0400

Re: [Freeipa-devel] [PATCH] [WIP] DNSSEC support - preview

2014-10-10 Thread Martin Basti
On 10/10/14 09:17, Martin Kosek wrote: On 10/09/2014 03:57 PM, Petr Spacek wrote: Hello, it would be great if people could look at current state of DNSSEC patches for FreeIPA. It consist of several relatively independent parts: - python-pkcs#11 interface written by Martin Basti:

[Freeipa-devel] [PATCH] 0159-0162 ID views in compat tree: ACIs, support for shell, gidNumber, and SSH keys

2014-10-10 Thread Alexander Bokovoy
Hi! I'm resending patches 0159 and 0160, and adding two more: 0161 -- support user SSH public keys in ID view user overrides 0162 -- support gidNumber in ID view user override SSH public keys to work require support from SSSD and that one is currently missing. At least, one add/remove the keys

Re: [Freeipa-devel] [PATCH] 352 Fix certmonger configuration in installer code

2014-10-10 Thread Jan Cholasta
Dne 10.10.2014 v 08:55 David Kupka napsal(a): On 10/10/2014 08:50 AM, Martin Kosek wrote: On 10/09/2014 03:56 PM, David Kupka wrote: On 10/08/2014 01:23 PM, Jan Cholasta wrote: Dne 8.10.2014 v 12:27 Jan Cholasta napsal(a): Hi, the attached patch fixes

Re: [Freeipa-devel] [PATCH] 0018 Check that port 8443 is available when installing PKI.

2014-10-10 Thread Martin Kosek
On 10/03/2014 12:18 PM, David Kupka wrote: On 10/02/2014 12:42 PM, Martin Kosek wrote: On 09/29/2014 04:48 PM, David Kupka wrote: https://fedorahosted.org/freeipa/ticket/4564 Looks and works OK. The port checking should be ideally refactored in 4.2 and *instance.py should use some common

[Freeipa-devel] [PATCH] 766 idviews: error out if appling Default Trust View on hosts

2014-10-10 Thread Petr Vobornik
CLI part of: https://fedorahosted.org/freeipa/ticket/4615 -- Petr Vobornik From 72f62454f8e02c5becec31675f018ec23b763e47 Mon Sep 17 00:00:00 2001 From: Petr Vobornik pvobo...@redhat.com Date: Fri, 10 Oct 2014 10:35:30 +0200 Subject: [PATCH] idviews: error out if appling Default Trust View on

[Freeipa-devel] [PATCH] 771 webui: do not offer ipa users to Default Trust View

2014-10-10 Thread Petr Vobornik
https://fedorahosted.org/freeipa/ticket/4616 -- Petr Vobornik From 2370973e869c154b92557a767e6e4f340fc6a283 Mon Sep 17 00:00:00 2001 From: Petr Vobornik pvobo...@redhat.com Date: Fri, 10 Oct 2014 10:50:56 +0200 Subject: [PATCH] webui: do not offer ipa users to Default Trust View

[Freeipa-devel] [PATCH] 767-770 webui: hide applied to hosts tab for Default Trust View

2014-10-10 Thread Petr Vobornik
Web UI part of: https://fedorahosted.org/freeipa/ticket/4615 Patch 767 is a little refactoring needed for $pre_op(as plain object) work as intended even with instantiated objects + fixes a bug where Evented objects were not considered a framework object. Patch 768 switches tabs so we can

Re: [Freeipa-devel] [PATCH] 0159-0162 ID views in compat tree: ACIs, support for shell, gidNumber, and SSH keys

2014-10-10 Thread Alexander Bokovoy
On Fri, 10 Oct 2014, Alexander Bokovoy wrote: Hi! I'm resending patches 0159 and 0160, and adding two more: 0161 -- support user SSH public keys in ID view user overrides 0162 -- support gidNumber in ID view user override SSH public keys to work require support from SSSD and that one is

Re: [Freeipa-devel] [PATCH] [WIP] DNSSEC support - preview

2014-10-10 Thread Simo Sorce
On Fri, 10 Oct 2014 09:17:34 +0200 Martin Kosek mko...@redhat.com wrote: On 10/09/2014 03:57 PM, Petr Spacek wrote: Hello, it would be great if people could look at current state of DNSSEC patches for FreeIPA. It consist of several relatively independent parts: - python-pkcs#11

Re: [Freeipa-devel] [PATCH] [WIP] DNSSEC support - preview

2014-10-10 Thread Martin Basti
On 10/10/14 14:51, Simo Sorce wrote: On Fri, 10 Oct 2014 09:17:34 +0200 Martin Kosek mko...@redhat.com wrote: On 10/09/2014 03:57 PM, Petr Spacek wrote: Hello, it would be great if people could look at current state of DNSSEC patches for FreeIPA. It consist of several relatively independent

Re: [Freeipa-devel] [PATCH] 0159-0162 ID views in compat tree: ACIs, support for shell, gidNumber, and SSH keys

2014-10-10 Thread Petr Vobornik
On 10.10.2014 10:39, Alexander Bokovoy wrote: Hi! I'm resending patches 0159 and 0160, and adding two more: 0161 -- support user SSH public keys in ID view user overrides 0162 -- support gidNumber in ID view user override SSH public keys to work require support from SSSD and that one is

Re: [Freeipa-devel] [PATCH] 0159-0162 ID views in compat tree: ACIs, support for shell, gidNumber, and SSH keys

2014-10-10 Thread Martin Kosek
On 10/10/2014 03:12 PM, Petr Vobornik wrote: On 10.10.2014 10:39, Alexander Bokovoy wrote: Hi! I'm resending patches 0159 and 0160, and adding two more: 0161 -- support user SSH public keys in ID view user overrides 0162 -- support gidNumber in ID view user override SSH public keys to work

Re: [Freeipa-devel] [PATCH] 0019 Stop dogtag when updating its configuration in, ipa-upgradeconfig

2014-10-10 Thread Jan Cholasta
Dne 8.10.2014 v 12:36 David Kupka napsal(a): On 10/08/2014 09:29 AM, Jan Cholasta wrote: Hi, Dne 8.10.2014 v 09:09 David Kupka napsal(a): https://fedorahosted.org/freeipa/ticket/4569 In renew_ca_cert and cainstance.py, dogtag should already be stopped in the places you modified, so why the

Re: [Freeipa-devel] [PATCH] 0159-0162 ID views in compat tree: ACIs, support for shell, gidNumber, and SSH keys

2014-10-10 Thread Alexander Bokovoy
On Fri, 10 Oct 2014, Petr Vobornik wrote: On 10.10.2014 10:39, Alexander Bokovoy wrote: Hi! I'm resending patches 0159 and 0160, and adding two more: 0161 -- support user SSH public keys in ID view user overrides 0162 -- support gidNumber in ID view user override SSH public keys to work

Re: [Freeipa-devel] [HELP] Regular users should not be able to add OTP tokens with custom name

2014-10-10 Thread thierry bordaz
On 10/09/2014 10:51 PM, Nathaniel McCallum wrote: On Thu, 2014-10-09 at 22:22 +0200, thierry bordaz wrote: On 10/09/2014 06:40 PM, Nathaniel McCallum wrote: On Thu, 2014-10-09 at 18:32 +0200, thierry bordaz wrote: On 10/09/2014 06:27 PM, Nathaniel McCallum wrote: On Thu, 2014-10-09 at 14:11

Re: [Freeipa-devel] [PATCH] 0020 Set IPA CA for freeipa certificates

2014-10-10 Thread Jan Cholasta
Hi, Dne 7.10.2014 v 16:56 David Kupka napsal(a): https://fedorahosted.org/freeipa/ticket/4618 This works, but I would prefer if the code did not silently ignore when the CA is not found. Honza -- Jan Cholasta ___ Freeipa-devel mailing list

Re: [Freeipa-devel] [PATCH] 0159-0162 ID views in compat tree: ACIs, support for shell, gidNumber, and SSH keys

2014-10-10 Thread Alexander Bokovoy
On Fri, 10 Oct 2014, Alexander Bokovoy wrote: On Fri, 10 Oct 2014, Petr Vobornik wrote: On 10.10.2014 10:39, Alexander Bokovoy wrote: Hi! I'm resending patches 0159 and 0160, and adding two more: 0161 -- support user SSH public keys in ID view user overrides 0162 -- support gidNumber in ID

Re: [Freeipa-devel] [PATCH] 0159-0162 ID views in compat tree: ACIs, support for shell, gidNumber, and SSH keys

2014-10-10 Thread Petr Vobornik
On 10.10.2014 15:36, Alexander Bokovoy wrote: On Fri, 10 Oct 2014, Petr Vobornik wrote: On 10.10.2014 10:39, Alexander Bokovoy wrote: Hi! I'm resending patches 0159 and 0160, and adding two more: 0161 -- support user SSH public keys in ID view user overrides 0162 -- support gidNumber in ID

Re: [Freeipa-devel] [HELP] Regular users should not be able to add OTP tokens with custom name

2014-10-10 Thread Ludwig Krispenz
On 10/10/2014 03:58 PM, thierry bordaz wrote: On 10/09/2014 10:51 PM, Nathaniel McCallum wrote: On Thu, 2014-10-09 at 22:22 +0200, thierry bordaz wrote: On 10/09/2014 06:40 PM, Nathaniel McCallum wrote: On Thu, 2014-10-09 at 18:32 +0200, thierry bordaz wrote: On 10/09/2014 06:27 PM,

Re: [Freeipa-devel] [PATCH] 0159-0162 ID views in compat tree: ACIs, support for shell, gidNumber, and SSH keys

2014-10-10 Thread Alexander Bokovoy
On Fri, 10 Oct 2014, Petr Vobornik wrote: On 10.10.2014 15:36, Alexander Bokovoy wrote: On Fri, 10 Oct 2014, Petr Vobornik wrote: On 10.10.2014 10:39, Alexander Bokovoy wrote: Hi! I'm resending patches 0159 and 0160, and adding two more: 0161 -- support user SSH public keys in ID view user

Re: [Freeipa-devel] [HELP] Regular users should not be able to add OTP tokens with custom name

2014-10-10 Thread thierry bordaz
On 10/10/2014 04:38 PM, Ludwig Krispenz wrote: On 10/10/2014 03:58 PM, thierry bordaz wrote: On 10/09/2014 10:51 PM, Nathaniel McCallum wrote: On Thu, 2014-10-09 at 22:22 +0200, thierry bordaz wrote: On 10/09/2014 06:40 PM, Nathaniel McCallum wrote: On Thu, 2014-10-09 at 18:32 +0200,

Re: [Freeipa-devel] [HELP] Regular users should not be able to add OTP tokens with custom name

2014-10-10 Thread Ludwig Krispenz
On 10/10/2014 05:16 PM, thierry bordaz wrote: On 10/10/2014 04:38 PM, Ludwig Krispenz wrote: On 10/10/2014 03:58 PM, thierry bordaz wrote: On 10/09/2014 10:51 PM, Nathaniel McCallum wrote: On Thu, 2014-10-09 at 22:22 +0200, thierry bordaz wrote: On 10/09/2014 06:40 PM, Nathaniel McCallum

Re: [Freeipa-devel] [HELP] Regular users should not be able to add OTP tokens with custom name

2014-10-10 Thread Nathaniel McCallum
On Fri, 2014-10-10 at 17:30 +0200, Ludwig Krispenz wrote: On 10/10/2014 05:16 PM, thierry bordaz wrote: On 10/10/2014 04:38 PM, Ludwig Krispenz wrote: On 10/10/2014 03:58 PM, thierry bordaz wrote: On 10/09/2014 10:51 PM, Nathaniel McCallum wrote: On Thu,

Re: [Freeipa-devel] [HELP] Regular users should not be able to add OTP tokens with custom name

2014-10-10 Thread Ludwig Krispenz
https://fedorahosted.org/389/ticket/47924 is it possible to reproduce without IPA ? Perhaps. You'd need the OTP schema and ACIs from FreeIPA, unless you can find another way to reproduce it. well, did think about it again, we probaly also would need all the plugins, so could be difficult

Re: [Freeipa-devel] [HELP] Regular users should not be able to add OTP tokens with custom name

2014-10-10 Thread Nathaniel McCallum
On Fri, 2014-10-10 at 17:38 +0200, Ludwig Krispenz wrote: https://fedorahosted.org/389/ticket/47924 is it possible to reproduce without IPA ? Perhaps. You'd need the OTP schema and ACIs from FreeIPA, unless you can find another way to reproduce it. well, did think about it again, we

Re: [Freeipa-devel] [HELP] Regular users should not be able to add OTP tokens with custom name

2014-10-10 Thread thierry bordaz
On 10/10/2014 05:30 PM, Ludwig Krispenz wrote: On 10/10/2014 05:16 PM, thierry bordaz wrote: On 10/10/2014 04:38 PM, Ludwig Krispenz wrote: On 10/10/2014 03:58 PM, thierry bordaz wrote: On 10/09/2014 10:51 PM, Nathaniel McCallum wrote: On Thu, 2014-10-09 at 22:22 +0200, thierry bordaz

Re: [Freeipa-devel] [PATCH] 0159-0162 ID views in compat tree: ACIs, support for shell, gidNumber, and SSH keys

2014-10-10 Thread Petr Vobornik
On 10.10.2014 16:38, Alexander Bokovoy wrote: On Fri, 10 Oct 2014, Petr Vobornik wrote: On 10.10.2014 15:36, Alexander Bokovoy wrote: On Fri, 10 Oct 2014, Petr Vobornik wrote: On 10.10.2014 10:39, Alexander Bokovoy wrote: Hi! I'm resending patches 0159 and 0160, and adding two more: 0161

Re: [Freeipa-devel] [HELP] Regular users should not be able to add OTP tokens with custom name

2014-10-10 Thread Nathaniel McCallum
As a result of this ongoing conversation, I have opened two 389 bugs: 1. Post Read - https://fedorahosted.org/389/ticket/47924 2. UUID ACIs - https://fedorahosted.org/389/ticket/47925 On Wed, 2014-10-08 at 17:46 -0400, Nathaniel McCallum wrote: The background of this email is this bug:

Re: [Freeipa-devel] [HELP] Regular users should not be able to add OTP tokens with custom name

2014-10-10 Thread Simo Sorce
On Fri, 10 Oct 2014 17:38:46 +0200 Ludwig Krispenz lkris...@redhat.com wrote: https://fedorahosted.org/389/ticket/47924 is it possible to reproduce without IPA ? Perhaps. You'd need the OTP schema and ACIs from FreeIPA, unless you can find another way to reproduce it. well, did

[Freeipa-devel] [PATCH] move replication topology to shared tree

2014-10-10 Thread Ludwig Krispenz
Hello, this is the current status of my work on #4302, and there are a few pieces still missing, eg the management command needs more input checking and error handling, but - I wanted to give people interested a chance to have a look again and get feedback - there came up the following

Re: [Freeipa-devel] [PATCH] 0159-0162 ID views in compat tree: ACIs, support for shell, gidNumber, and SSH keys

2014-10-10 Thread Alexander Bokovoy
On Fri, 10 Oct 2014, Petr Vobornik wrote: One more update for patch 0161, Petr noticed we need to call super post_callback() too. idoverrideuser_find callback causes internal error. I've attached new version of the patch which fixes it. Basically it's this change: diff --git

[Freeipa-devel] [PATCH] 772 webui: add new iduseroverride fields

2014-10-10 Thread Petr Vobornik
- add gecos, gidnumber, loginshell, sshkeys fields depends on ab's 160-165. Point for discussion: Before this patch, all fields were included in adder dialog and were listed on a search pages. Now: * Search page lacks: gecos, gidnumber, loginshell, sshkeys fields * Adder dialog lacks:

Re: [Freeipa-devel] [PATCH] move replication topology to shared tree

2014-10-10 Thread Simo Sorce
On Fri, 10 Oct 2014 17:52:15 +0200 Ludwig Krispenz lkris...@redhat.com wrote: Hello, this is the current status of my work on #4302, and there are a few pieces still missing, eg the management command needs more input checking and error handling, but - I wanted to give people interested

Re: [Freeipa-devel] [PATCH] move replication topology to shared tree

2014-10-10 Thread James
On 10 October 2014 12:21, Simo Sorce s...@redhat.com wrote: First thing, I do not think we want a new command here. If we need commands outside of the ipa framework they should be integrated in the ipa-replica-manage tool. But really one of the reasons to move data in the shared tree was

Re: [Freeipa-devel] [HELP] Regular users should not be able to add OTP tokens with custom name

2014-10-10 Thread Ludwig Krispenz
aci: (targetfilter = (objectClass=ipaToken))(targetattrs = objectclass || d escription || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNo tBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSer ial

Re: [Freeipa-devel] [PATCH] move replication topology to shared tree

2014-10-10 Thread Ludwig Krispenz
On 10/10/2014 06:30 PM, James wrote: On 10 October 2014 12:21, Simo Sorce s...@redhat.com wrote: First thing, I do not think we want a new command here. If we need commands outside of the ipa framework they should be integrated in the ipa-replica-manage tool. But really one of the reasons to

Re: [Freeipa-devel] [PATCH] move replication topology to shared tree

2014-10-10 Thread Simo Sorce
On Fri, 10 Oct 2014 18:38:36 +0200 Ludwig Krispenz lkris...@redhat.com wrote: On 10/10/2014 06:30 PM, James wrote: On 10 October 2014 12:21, Simo Sorce s...@redhat.com wrote: First thing, I do not think we want a new command here. If we need commands outside of the ipa framework they