Re: [Freeipa-devel] [PATCHES 00012-0013 v7] Profiles and CA ACLs

2015-06-09 Thread Martin Basti
On 09/06/15 09:07, Fraser Tweedale wrote: On Thu, Jun 04, 2015 at 03:58:25PM +0200, Martin Basti wrote: On 04/06/15 15:48, Martin Kosek wrote: On 06/04/2015 03:40 PM, Martin Basti wrote: On 04/06/15 08:59, Fraser Tweedale wrote: On Wed, Jun 03, 2015 at 06:49:13PM +0200, Martin Basti wrote:

[Freeipa-devel] DNA range distribution to replicas by default

2015-06-09 Thread Petr Spacek
Hello, I would like to discuss https://bugzilla.redhat.com/show_bug.cgi?id=1211366 Error creating a user when jumping from an original server to replica. Currently the DNA ranges are distributed from master to other replicas on first attempt to get a number from particular range. This works

Re: [Freeipa-devel] [PATCH] 0005 User life cycle: del/mod/find/show stageuser commands

2015-06-09 Thread Jan Cholasta
Dne 20.5.2015 v 11:26 Jan Cholasta napsal(a): Dne 18.5.2015 v 10:33 thierry bordaz napsal(a): On 05/15/2015 04:44 PM, David Kupka wrote: Hello Thierry, thanks for the patch set. Overall functionality of ULC feature looks good to me and is definitely alpha ready. I found following issues but

[Freeipa-devel] [PATCH 0040] generalize certificate creation during testing

2015-06-09 Thread Martin Babinsky
A slight hack to ipatests/test_xmlrpc/testcert.py module in order to enable generation of multiple host/service/user certificates. It should make writing tests for new CA profile/sub-CA/user certificate functionality easier. -- Martin^3 Babinsky From 41578368546bca02654016c1df1295227ac89554

[Freeipa-devel] [PATCH 0051] Use 389-ds centralized scripts.

2015-06-09 Thread David Kupka
https://fedorahosted.org/freeipa/ticket/4051 -- David Kupka From da898ff6fbe760ff6786763297ecbf31bf10d300 Mon Sep 17 00:00:00 2001 From: David Kupka dku...@redhat.com Date: Wed, 1 Apr 2015 11:27:36 -0400 Subject: [PATCH] Use 389-ds centralized scripts. Directory server is deprecating use of

Re: [Freeipa-devel] topology issues

2015-06-09 Thread Ludwig Krispenz
On 06/09/2015 03:55 PM, Oleg Fayans wrote: Hi everybody, The current status of Topology plugin testing is as follows: 1. There is still no proper way of removing the replica. Standard procedure using `ipa-replica-manage del` throws Server is unwilling to perform: Entry is managed by topology

Re: [Freeipa-devel] topology issues

2015-06-09 Thread Oleg Fayans
On 06/09/2015 04:04 PM, Ludwig Krispenz wrote: On 06/09/2015 03:55 PM, Oleg Fayans wrote: Hi everybody, The current status of Topology plugin testing is as follows: 1. There is still no proper way of removing the replica. Standard procedure using `ipa-replica-manage del` throws Server is

[Freeipa-devel] #5056: Rename topologysegment-refresh to topologysegment-reinitialize

2015-06-09 Thread Martin Kosek
FYI, as mentioned on today conversation, I filed the ticket to rename topologysegment-refresh to topologysegment-reinitialize: https://fedorahosted.org/freeipa/ticket/5056 If there are any objections, please shout. If not, Petr - you know what to do... -- Martin Kosek mko...@redhat.com

Re: [Freeipa-devel] topology issues

2015-06-09 Thread Oleg Fayans
Simo, yep, I entered the name manually when writing this letter On 06/09/2015 04:28 PM, Simo Sorce wrote: On Tue, 2015-06-09 at 16:25 +0200, Oleg Fayans wrote: Then, after issuing `ipa-replica-manage-del f2replica1.bagam.net Is this a copy and paste error or the command you actually used ?

Re: [Freeipa-devel] topology issues

2015-06-09 Thread Oleg Fayans
On 06/09/2015 04:19 PM, Ludwig Krispenz wrote: On 06/09/2015 04:14 PM, Oleg Fayans wrote: On 06/09/2015 04:04 PM, Ludwig Krispenz wrote: On 06/09/2015 03:55 PM, Oleg Fayans wrote: Hi everybody, The current status of Topology plugin testing is as follows: 1. There is still no proper

Re: [Freeipa-devel] topology issues

2015-06-09 Thread Ludwig Krispenz
Hi Oleg, thanks for access to your machine, the replication agreements are still there - and that is expected since the server was not removed. In the access log I see: [09/Jun/2015:08:32:42 -0400] conn=150 op=52 SRCH base=cn=f22replica1.bagam.net,cn=masters,cn=ipa,cn=etc,dc=bagam,dc=net

Re: [Freeipa-devel] [PATCHES 00012-0013 v7] Profiles and CA ACLs

2015-06-09 Thread Martin Basti
On 09/06/15 08:58, Fraser Tweedale wrote: On Mon, Jun 08, 2015 at 08:49:06AM +0200, Martin Kosek wrote: On 06/08/2015 03:31 AM, Fraser Tweedale wrote: New patches attached. Comments inline. Thanks Fraser! ... 5) Missing referint plugin configuration for attribute

Re: [Freeipa-devel] topology issues

2015-06-09 Thread Ludwig Krispenz
On 06/09/2015 04:14 PM, Oleg Fayans wrote: On 06/09/2015 04:04 PM, Ludwig Krispenz wrote: On 06/09/2015 03:55 PM, Oleg Fayans wrote: Hi everybody, The current status of Topology plugin testing is as follows: 1. There is still no proper way of removing the replica. Standard procedure

Re: [Freeipa-devel] topology issues

2015-06-09 Thread Ludwig Krispenz
On 06/09/2015 04:25 PM, Oleg Fayans wrote: On 06/09/2015 04:19 PM, Ludwig Krispenz wrote: On 06/09/2015 04:14 PM, Oleg Fayans wrote: On 06/09/2015 04:04 PM, Ludwig Krispenz wrote: On 06/09/2015 03:55 PM, Oleg Fayans wrote: Hi everybody, The current status of Topology plugin testing

Re: [Freeipa-devel] Community Portal Milestone

2015-06-09 Thread Drew Erny
Hey, Freeipa, same thread new subtopic. So, I was bouncing some ideas around with another developer (ayoung) and I think I have a pretty good idea for self-service user registration. The idea is that I put self-service user registration into its own application that calls out to ipa user-add

[Freeipa-devel] [PATCH] Use Exception class instead of StandardError

2015-06-09 Thread Niranjan
Niranjan wrote: Greetings, Please find the modified patch for ipapython/adminutil.py. I have run few tests manually like running ipa-server-install as non-root user or provide --quiet and --verbose to see if it raises ScriptError properly. Also i checked by running ipa-server-install and

Re: [Freeipa-devel] DNA range distribution to replicas by default

2015-06-09 Thread Simo Sorce
On Tue, 2015-06-09 at 10:30 +0200, Petr Spacek wrote: Hello, I would like to discuss https://bugzilla.redhat.com/show_bug.cgi?id=1211366 Error creating a user when jumping from an original server to replica. Currently the DNA ranges are distributed from master to other replicas on first

[Freeipa-devel] topology issues

2015-06-09 Thread Oleg Fayans
Hi everybody, The current status of Topology plugin testing is as follows: 1. There is still no proper way of removing the replica. Standard procedure using `ipa-replica-manage del` throws Server is unwilling to perform: Entry is managed by topology plugin.Deletion not allowed.. The

Re: [Freeipa-devel] [PATCH] 0001 Provide Kerberos over HTTP (MS-KKDCP)

2015-06-09 Thread Christian Heimes
On 2015-05-27 15:16, Christian Heimes wrote: Hello, here is my first patch for FreeIPA. The patch integrates python-kdcproxy for MS-KKDCP support (aka Kerberos over HTTPS). https://www.freeipa.org/page/V4/KDC_Proxy Ticket: https://fedorahosted.org/freeipa/ticket/4801

Re: [Freeipa-devel] Community Portal Milestone

2015-06-09 Thread Petr Spacek
On 9.6.2015 12:30, Petr Spacek wrote: On 8.6.2015 21:37, Drew Erny wrote: Hi, all, I'm going to start working on the Community Portal milestone this week. The first thing I'm noticing is that for almost all of the community portal, there has to be some way for the IPA server to send email,

Re: [Freeipa-devel] Community Portal Milestone

2015-06-09 Thread Alexander Bokovoy
On Tue, 09 Jun 2015, Adam Young wrote: On 06/09/2015 06:34 PM, Simo Sorce wrote: On Tue, 2015-06-09 at 16:15 -0400, Drew Erny wrote: Hey, Freeipa, same thread new subtopic. So, I was bouncing some ideas around with another developer (ayoung) and I think I have a pretty good idea for

Re: [Freeipa-devel] Community Portal Milestone

2015-06-09 Thread Adam Young
On 06/09/2015 06:34 PM, Simo Sorce wrote: On Tue, 2015-06-09 at 16:15 -0400, Drew Erny wrote: Hey, Freeipa, same thread new subtopic. So, I was bouncing some ideas around with another developer (ayoung) and I think I have a pretty good idea for self-service user registration. The idea is that

Re: [Freeipa-devel] Community Portal Milestone

2015-06-09 Thread Adam Young
On 06/09/2015 04:44 PM, Alexander Bokovoy wrote: On Tue, 09 Jun 2015, Drew Erny wrote: Hey, Freeipa, same thread new subtopic. So, I was bouncing some ideas around with another developer (ayoung) and I think I have a pretty good idea for self-service user registration. The idea is that I

Re: [Freeipa-devel] [PATCHES 00012-0013 v7] Profiles and CA ACLs

2015-06-09 Thread Fraser Tweedale
On Tue, Jun 09, 2015 at 04:37:56PM +0200, Martin Basti wrote: On 09/06/15 08:58, Fraser Tweedale wrote: On Mon, Jun 08, 2015 at 08:49:06AM +0200, Martin Kosek wrote: On 06/08/2015 03:31 AM, Fraser Tweedale wrote: New patches attached. Comments inline. Thanks Fraser! ... 5) Missing

Re: [Freeipa-devel] Community Portal Milestone

2015-06-09 Thread Alexander Bokovoy
On Wed, 10 Jun 2015, Adam Young wrote: On 06/09/2015 04:44 PM, Alexander Bokovoy wrote: On Tue, 09 Jun 2015, Drew Erny wrote: Hey, Freeipa, same thread new subtopic. So, I was bouncing some ideas around with another developer (ayoung) and I think I have a pretty good idea for self-service