Re: [Freeipa-devel] [PATCH 0364] Remove unused files rdlist.c and rdlist.h

2015-05-19 Thread Petr Spacek
On 18.5.2015 17:10, Lukas Slebodnik wrote: On (15/05/15 11:44), Petr Spacek wrote: Hello, Remove unused files rdlist.c and rdlist.h. I noticed this cruft while preparing the previous patchset. This patch is independent and applicable directly to master branch. I had an issue with

Re: [Freeipa-devel] [PATCH] Password vault

2015-05-19 Thread Jan Cholasta
Dne 18.5.2015 v 21:17 Endi Sukma Dewata napsal(a): Please take a look at the attached new patch which includes some of your changes you proposed. On 5/14/2015 7:17 PM, Endi Sukma Dewata wrote: On 5/14/2015 1:42 PM, Jan Cholasta wrote: Question: Services in IPA are identified by Kerberos

Re: [Freeipa-devel] [PATCHES 0001-0007] Profile management

2015-05-19 Thread Jan Cholasta
Dne 15.5.2015 v 14:27 Martin Basti napsal(a): On 15/05/15 10:24, Fraser Tweedale wrote: Please find attached latest patches including new patches: - 0006 enable LDAP-based profiles in Dogtag on upgrade - 0007 import included profiles during install or upgrade There is one TODO in the patches

[Freeipa-devel] [PATCH 0035] do not check for directory manager password during KRA uninstall

2015-05-19 Thread Martin Babinsky
https://fedorahosted.org/freeipa/ticket/5028 -- Martin^3 Babinsky From 96aae7a619c808e979699b56b5905e1e836a4f8b Mon Sep 17 00:00:00 2001 From: Martin Babinsky mbabi...@redhat.com Date: Tue, 19 May 2015 13:01:27 +0200 Subject: [PATCH] do not check for directory manager password during KRA

Re: [Freeipa-devel] [PATCHES 0001-0007] Profile management

2015-05-19 Thread Fraser Tweedale
On Tue, May 19, 2015 at 10:52:49AM +0200, Jan Cholasta wrote: Dne 15.5.2015 v 14:27 Martin Basti napsal(a): On 15/05/15 10:24, Fraser Tweedale wrote: Please find attached latest patches including new patches: - 0006 enable LDAP-based profiles in Dogtag on upgrade - 0007 import included

[Freeipa-devel] IPAUpgrade.create_instance causing ipa-server-install failure

2015-05-19 Thread Fraser Tweedale
I am experiencing ipa-server-install failure which seems to be caused by IPAUpgrade.__start_nowait() (upgradeinstance.py:174). It is claimed that the LDAP connection will wait for the (Unix) socket but it does not - instead it fails to connect. Did something chance recently that would cause the

Re: [Freeipa-devel] [PATCHES 0001-0007] Profile management

2015-05-19 Thread Fraser Tweedale
On Wed, May 20, 2015 at 07:40:44AM +0200, Jan Cholasta wrote: Dne 19.5.2015 v 13:50 Fraser Tweedale napsal(a): On Tue, May 19, 2015 at 10:52:49AM +0200, Jan Cholasta wrote: Dne 15.5.2015 v 14:27 Martin Basti napsal(a): On 15/05/15 10:24, Fraser Tweedale wrote: Please find attached latest

Re: [Freeipa-devel] [PATCHES 0001-0007] Profile management

2015-05-19 Thread Jan Cholasta
Dne 19.5.2015 v 13:50 Fraser Tweedale napsal(a): On Tue, May 19, 2015 at 10:52:49AM +0200, Jan Cholasta wrote: Dne 15.5.2015 v 14:27 Martin Basti napsal(a): On 15/05/15 10:24, Fraser Tweedale wrote: Please find attached latest patches including new patches: - 0006 enable LDAP-based profiles

Re: [Freeipa-devel] [UPSTREAM_FAILURES] Latest changes affect freeipa builds and client configuration

2015-05-19 Thread Fraser Tweedale
On Tue, May 19, 2015 at 05:42:15PM +0200, Martin Babinsky wrote: Hello Oleg, On 05/19/2015 05:21 PM, Oleg Fayans wrote: Dear colleagues I would like to notify you, that: 1. some of the recent changes in the upstream repo have broken the freeipa-client configuration. The symptoms are as

Re: [Freeipa-devel] [PATCH 0245] Fix uniqueness plugins vol. 2

2015-05-19 Thread Jan Cholasta
Dne 13.5.2015 v 12:56 Martin Babinsky napsal(a): On 05/12/2015 09:03 PM, Martin Basti wrote: On 12/05/15 18:23, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/4921 To test this, the mkosek/freeipa-master copr repo with 389-ds-base 1.3.4.0 is needed. All previous changes to

Re: [Freeipa-devel] [PATCH 0248] DNSSEC: Fix: Do not recreate kasp.db if already exists

2015-05-19 Thread Jan Cholasta
Dne 15.5.2015 v 12:10 Petr Spacek napsal(a): On 14.5.2015 17:09, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/4657 Patch attached. ACK for this change but it generally it would be nice if function __setup_dnssec had some meaningful name, e.g. __setup_opendnssec_db. Pushed

Re: [Freeipa-devel] [PATCH 0325] Add Domain Level feature

2015-05-19 Thread Ludwig Krispenz
On 05/19/2015 03:36 PM, Martin Kosek wrote: On 05/19/2015 03:22 PM, Tomas Babej wrote: ... 3) Domain level is just a single integer and it should be treated as such, there's no need for an LDAPObject plugin and other unnecessary complexities. The implemetation could be as simple as (from top

Re: [Freeipa-devel] [PATCH 0325] Add Domain Level feature

2015-05-19 Thread Martin Kosek
On 05/19/2015 03:49 PM, Ludwig Krispenz wrote: On 05/19/2015 03:36 PM, Martin Kosek wrote: On 05/19/2015 03:22 PM, Tomas Babej wrote: ... 3) Domain level is just a single integer and it should be treated as such, there's no need for an LDAPObject plugin and other unnecessary complexities.

Re: [Freeipa-devel] [PATCH 0325] Add Domain Level feature

2015-05-19 Thread Martin Kosek
On 05/19/2015 03:56 PM, Tomas Babej wrote: On 05/19/2015 03:51 PM, Martin Kosek wrote: On 05/19/2015 03:49 PM, Ludwig Krispenz wrote: On 05/19/2015 03:36 PM, Martin Kosek wrote: On 05/19/2015 03:22 PM, Tomas Babej wrote: ... 3) Domain level is just a single integer and it should be

Re: [Freeipa-devel] [PATCH 0325] Add Domain Level feature

2015-05-19 Thread Tomas Babej
On 05/14/2015 11:48 AM, Jan Cholasta wrote: Hi, Dne 14.5.2015 v 11:00 Tomas Babej napsal(a): Hi, this patch implements the domain level feature. https://fedorahosted.org/freeipa/ticket/5018 Tomas 1) +# Create entry proclaiming Domain Level support of this master +# This will update the

Re: [Freeipa-devel] [PATCH 0325] Add Domain Level feature

2015-05-19 Thread Jan Cholasta
Dne 19.5.2015 v 15:22 Tomas Babej napsal(a): On 05/14/2015 11:48 AM, Jan Cholasta wrote: Hi, Dne 14.5.2015 v 11:00 Tomas Babej napsal(a): Hi, this patch implements the domain level feature. https://fedorahosted.org/freeipa/ticket/5018 Tomas 1) +# Create entry proclaiming Domain Level

Re: [Freeipa-devel] [PATCH 0035] do not check for directory manager password during KRA uninstall

2015-05-19 Thread Martin Babinsky
On 05/19/2015 01:17 PM, Martin Babinsky wrote: https://fedorahosted.org/freeipa/ticket/5028 updated patch attached -- Martin^3 Babinsky From b7c20fa1e2e7d27b8eb968bb57955c7620f83e50 Mon Sep 17 00:00:00 2001 From: Martin Babinsky mbabi...@redhat.com Date: Tue, 19 May 2015 13:01:27 +0200

Re: [Freeipa-devel] [PATCH 0247] Modularization of the DNS subsytem installer

2015-05-19 Thread Jan Cholasta
Dne 15.5.2015 v 16:44 Martin Basti napsal(a): On 14/05/15 15:16, Martin Basti wrote: Required for new installers. Patch attached. Updated patch attached. Thanks, ACK. Pushed to master: ae9c3e2dce000ed185b28e2e6e85043ad8d001ed -- Jan Cholasta -- Manage your subscription for the

Re: [Freeipa-devel] [PATCHES 0033-0034] fix recent bugs introduced by letting httpd use file-based ccache

2015-05-19 Thread David Kupka
On 05/15/2015 04:41 PM, Martin Babinsky wrote: On 05/15/2015 04:25 PM, Jan Cholasta wrote: Dne 15.5.2015 v 16:16 Martin Babinsky napsal(a): These two patches fix two issues reported by David Kupka in most recent freeipa-master builds, which are caused by my previous patch 0031 provide a

Re: [Freeipa-devel] [PATCHES 0239-0243] Server Upgrade: minor fixes

2015-05-19 Thread Jan Cholasta
Dne 13.5.2015 v 15:22 David Kupka napsal(a): On 05/12/2015 02:44 PM, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/4904 Patches attached. Works for me, ACK. Pushed to master: 99c0b918a7cdf4ea6f24b4cbe687d9cafd21de24 -- Jan Cholasta -- Manage your subscription for the

Re: [Freeipa-devel] [PATCH 0325] Add Domain Level feature

2015-05-19 Thread Martin Kosek
On 05/19/2015 03:22 PM, Tomas Babej wrote: ... 3) Domain level is just a single integer and it should be treated as such, there's no need for an LDAPObject plugin and other unnecessary complexities. The implemetation could be as simple as (from top of my head, untested): That's right, I also

Re: [Freeipa-devel] [PATCH] 0048 Remove unused enable() method from DogtagInstance.

2015-05-19 Thread Jan Cholasta
Dne 14.5.2015 v 17:41 David Kupka napsal(a): On 05/13/2015 12:07 PM, Martin Basti wrote: On 12/05/15 16:54, David Kupka wrote: On 05/12/2015 02:16 PM, Martin Basti wrote: On 12/05/15 13:53, David Kupka wrote: DogtagInstance.enable() overrides Service.enable() and does nothing usefulll. Also

Re: [Freeipa-devel] [PATCHES 0033-0034] fix recent bugs introduced by letting httpd use file-based ccache

2015-05-19 Thread Jan Cholasta
Dne 19.5.2015 v 14:31 David Kupka napsal(a): On 05/15/2015 04:41 PM, Martin Babinsky wrote: On 05/15/2015 04:25 PM, Jan Cholasta wrote: Dne 15.5.2015 v 16:16 Martin Babinsky napsal(a): These two patches fix two issues reported by David Kupka in most recent freeipa-master builds, which are

Re: [Freeipa-devel] [PATCH 0325] Add Domain Level feature

2015-05-19 Thread Tomas Babej
On 05/19/2015 03:51 PM, Martin Kosek wrote: On 05/19/2015 03:49 PM, Ludwig Krispenz wrote: On 05/19/2015 03:36 PM, Martin Kosek wrote: On 05/19/2015 03:22 PM, Tomas Babej wrote: ... 3) Domain level is just a single integer and it should be treated as such, there's no need for an LDAPObject

Re: [Freeipa-devel] [PATCH 0325] Add Domain Level feature

2015-05-19 Thread Tomas Babej
On 05/19/2015 03:59 PM, Martin Kosek wrote: On 05/19/2015 03:56 PM, Tomas Babej wrote: On 05/19/2015 03:51 PM, Martin Kosek wrote: On 05/19/2015 03:49 PM, Ludwig Krispenz wrote: On 05/19/2015 03:36 PM, Martin Kosek wrote: On 05/19/2015 03:22 PM, Tomas Babej wrote: ... 3) Domain level is

[Freeipa-devel] [PATCH] 1112 Add service constraint delegation plugin

2015-05-19 Thread Rob Crittenden
Add a plugin to manage service delegations, like the one allowing the HTTP service to obtain an ldap service ticket on behalf of the user. This does not include impersonation targets, so one cannot yet limit by user what tickets can be obtained. There is also no referential integrity for the

Re: [Freeipa-devel] [PATCH 0249] DNSSEC: update kasp configuration template: increase key size lifetime

2015-05-19 Thread Jan Cholasta
Dne 15.5.2015 v 13:33 Martin Basti napsal(a): On 15/05/15 13:12, Petr Spacek wrote: On 14.5.2015 17:23, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/4657 Looking at 3072 bit key size, I think we can prolong KSK key rotation period to 2 years. It should be okay according to

Re: [Freeipa-devel] [PATCH] Password vault

2015-05-19 Thread Endi Sukma Dewata
Before I send another patch I have some questions below. On 5/19/2015 3:27 AM, Jan Cholasta wrote: I changed the 'host vaults' to become 'service vaults'. The interface will look like this: $ ipa vault-find --service HTTP/server.example.com $ ipa vault-add test --service

Re: [Freeipa-devel] [PATCH] 832-850 Stage Users Web UI and its prerequisites

2015-05-19 Thread thierry bordaz
On 05/15/2015 05:38 PM, David Kupka wrote: On 05/15/2015 12:34 PM, Petr Vobornik wrote: On 05/15/2015 10:59 AM, Petr Vobornik wrote: Stage User Web UI is actually just the last four patches(847-850). I expect that patch 848 - deleter dialog needs some adjustments (was discussed offline). The

Re: [Freeipa-devel] [PATCH 0035] do not check for directory manager password during KRA uninstall

2015-05-19 Thread Martin Basti
On 19/05/15 16:19, Martin Babinsky wrote: On 05/19/2015 01:17 PM, Martin Babinsky wrote: https://fedorahosted.org/freeipa/ticket/5028 updated patch attached Thanks. ACK -- Martin Basti -- Manage your subscription for the Freeipa-devel mailing list:

[Freeipa-devel] [PATCH 0250] Pylint: fix false positive warning

2015-05-19 Thread Martin Basti
Patch attached. -- Martin Basti From 45feb51a815276b2ea77dfe30ea007e058a40b7e Mon Sep 17 00:00:00 2001 From: Martin Basti mba...@redhat.com Date: Tue, 19 May 2015 18:37:43 +0200 Subject: [PATCH] Pylint: fix false positive warning for domain --- install/tools/ipa-server-install | 2 +- 1 file

[Freeipa-devel] [PATCH 0036] merge KRA installation machinery to a single module

2015-05-19 Thread Martin Babinsky
This patch is required for the installer ref@#$%ing work (https://fedorahosted.org/freeipa/ticket/4468). It required quite a bit of hacking to get it work as expected, but I hope that it's not so bad. Requires PATCH 0035 do not check for directory manager password during KRA uninstall to

Re: [Freeipa-devel] [UPSTREAM_FAILURES] Latest changes affect freeipa builds and client configuration

2015-05-19 Thread Martin Babinsky
Hello Oleg, On 05/19/2015 05:21 PM, Oleg Fayans wrote: Dear colleagues I would like to notify you, that: 1. some of the recent changes in the upstream repo have broken the freeipa-client configuration. The symptoms are as follows: at some point during ipa-server-install the process fails with

Re: [Freeipa-devel] [PATCH 0035] do not check for directory manager password during KRA uninstall

2015-05-19 Thread Martin Basti
On 19/05/15 16:41, Martin Basti wrote: On 19/05/15 16:19, Martin Babinsky wrote: On 05/19/2015 01:17 PM, Martin Babinsky wrote: https://fedorahosted.org/freeipa/ticket/5028 updated patch attached Thanks. ACK NACK, lint failed -- Martin Basti -- Manage your subscription for the

Re: [Freeipa-devel] [PATCH 0250] Pylint: fix false positive warning

2015-05-19 Thread Petr Vobornik
On 05/19/2015 06:56 PM, Martin Basti wrote: Patch attached. ACK Pushed to master: ab69a0b1a74e639d23ba8e684d402eaf7582c67c -- Petr Vobornik -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

Re: [Freeipa-devel] [PATCH] 832-850 Stage Users Web UI and its prerequisites

2015-05-19 Thread Petr Vobornik
On 05/19/2015 05:34 PM, thierry bordaz wrote: On 05/15/2015 05:38 PM, David Kupka wrote: On 05/15/2015 12:34 PM, Petr Vobornik wrote: On 05/15/2015 10:59 AM, Petr Vobornik wrote: Stage User Web UI is actually just the last four patches(847-850). I expect that patch 848 - deleter dialog needs

Re: [Freeipa-devel] [PATCH] 1112 Add service constraint delegation plugin

2015-05-19 Thread Rob Crittenden
Rob Crittenden wrote: Add a plugin to manage service delegations, like the one allowing the HTTP service to obtain an ldap service ticket on behalf of the user. This does not include impersonation targets, so one cannot yet limit by user what tickets can be obtained. There is also no

Re: [Freeipa-devel] [TEST PLAN] User lifecycle plugin

2015-05-19 Thread thierry bordaz
On 05/13/2015 05:54 PM, Martin Basti wrote: On 13/05/15 17:44, David Kupka wrote: On 05/13/2015 02:57 PM, Lenka Ryznarova wrote: Hi, I've prepared test plan design for User Lifecycle Plugin - [1]. Please review and let me know if you have any comments on that. Thanks, Lenka [1]

Re: [Freeipa-devel] [PATCH] 851-852 webui: datetime widget with datepicker

2015-05-19 Thread Martin Babinsky
On 05/18/2015 03:40 PM, Petr Vobornik wrote: Datetime widget was transform from a simple text input to 3 separate inputs: - date with bootstrap-datepicker - hour - minute e.g.: Validity end[ 2015-05-18 ] [23]:[01] UTC Vendor[ abc] Editation of

Re: [Freeipa-devel] [PATCH] 830 webui: fix empty table border in Firefox

2015-05-19 Thread Martin Babinsky
On 05/15/2015 11:01 AM, Petr Vobornik wrote: Firefox suffers from: https://bugzilla.mozilla.org/show_bug.cgi?id=409254 This is a workaround to fix it. ACK -- Martin^3 Babinsky -- Manage your subscription for the Freeipa-devel mailing list:

Re: [Freeipa-devel] [PATCH 0035] do not check for directory manager password during KRA uninstall

2015-05-19 Thread Martin Babinsky
On 05/19/2015 05:55 PM, Martin Basti wrote: On 19/05/15 16:41, Martin Basti wrote: On 19/05/15 16:19, Martin Babinsky wrote: On 05/19/2015 01:17 PM, Martin Babinsky wrote: https://fedorahosted.org/freeipa/ticket/5028 updated patch attached Thanks. ACK NACK, lint failed Attaching