[Freeipa-devel] Announcing FreeIPA 4.2.0

2015-07-10 Thread Petr Vobornik
The FreeIPA team is proud to announce FreeIPA v4.2.0 release! It can be downloaded from http://www.freeipa.org/page/Downloads. The builds for Fedora 22 and Fedora Rawhide will be available in the official COPR repository https://copr.fedoraproject.org/coprs/mkosek/freeipa-4.2/. This

Re: [Freeipa-devel] [PATCH 0281] Validate adding a privilege to a permission

2015-07-10 Thread Martin Basti
On 10/07/15 07:32, Jan Cholasta wrote: Hi, Dne 9.7.2015 v 16:55 Martin Basti napsal(a): https://fedorahosted.org/freeipa/ticket/5075 Patch attached. the check is very plugin-specific, so I don't think it should be in ipalib.util. You can keep it in privilege and import it from there in

Re: [Freeipa-devel] [PATCH 0282] Prevent to rename certprofile profile id

2015-07-10 Thread Jan Cholasta
Dne 10.7.2015 v 10:43 Martin Basti napsal(a): On 10/07/15 07:29, Jan Cholasta wrote: Hi, Dne 9.7.2015 v 17:21 Martin Basti napsal(a): https://fedorahosted.org/freeipa/ticket/5074 Patch attached. NACK, you should remove the --rename option from certprofile-mod. You can do it by removing

Re: [Freeipa-devel] [PATCH 0282] Prevent to rename certprofile profile id

2015-07-10 Thread Jan Cholasta
Dne 10.7.2015 v 10:59 Jan Cholasta napsal(a): Dne 10.7.2015 v 10:43 Martin Basti napsal(a): On 10/07/15 07:29, Jan Cholasta wrote: Hi, Dne 9.7.2015 v 17:21 Martin Basti napsal(a): https://fedorahosted.org/freeipa/ticket/5074 Patch attached. NACK, you should remove the --rename option from

Re: [Freeipa-devel] [PATCH 0282] Prevent to rename certprofile profile id

2015-07-10 Thread Simo Sorce
On Fri, 2015-07-10 at 11:01 +0200, Jan Cholasta wrote: Dne 10.7.2015 v 10:59 Jan Cholasta napsal(a): Dne 10.7.2015 v 10:43 Martin Basti napsal(a): On 10/07/15 07:29, Jan Cholasta wrote: Hi, Dne 9.7.2015 v 17:21 Martin Basti napsal(a): https://fedorahosted.org/freeipa/ticket/5074

Re: [Freeipa-devel] [PATCH 0282] Prevent to rename certprofile profile id

2015-07-10 Thread Jan Cholasta
Dne 10.7.2015 v 11:10 Simo Sorce napsal(a): On Fri, 2015-07-10 at 11:01 +0200, Jan Cholasta wrote: Dne 10.7.2015 v 10:59 Jan Cholasta napsal(a): Dne 10.7.2015 v 10:43 Martin Basti napsal(a): On 10/07/15 07:29, Jan Cholasta wrote: Hi, Dne 9.7.2015 v 17:21 Martin Basti napsal(a):

[Freeipa-devel] [patch 0004] spec file: Update the package name from libipa_hbac-python to python-libipa_hbac

2015-07-10 Thread Milan Kubik
Name update + the renamed package breaks 'dnf builddep'. I will report the bug. Yum can take care of the conflict resolution. Patch attached. Milan From 3d79c32ffad3ab280b7d84507d402039b70fa8e1 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Milan=20Kub=C3=ADk?= mku...@redhat.com Date: Fri, 10 Jul

Re: [Freeipa-devel] [PATCH 0334] Hide topology and domainlevel features

2015-07-10 Thread Simo Sorce
On Wed, 2015-07-08 at 00:09 +0200, Tomas Babej wrote: On 07/07/2015 07:16 PM, Martin Basti wrote: On 07/07/15 10:33, Tomas Babej wrote: Hi, * Hide topology and domainlevel commands in the CLI * Hide topology and domainlevel in the WebUI * Set maximum allowed domain level to 0 * Do

Re: [Freeipa-devel] [PATCH] 0001 Enhance the DNSNotARecordError message

2015-07-10 Thread Tomas Babej
On 07/09/2015 01:49 PM, Veronika Kabatova wrote: The attached patch solves the https://fedorahosted.org/freeipa/ticket/3959 ticket. Veronika Kabatova Hello, thanks for the patch. Actually, the doctest does not pass: $ ipa-run-tests

Re: [Freeipa-devel] [patch 0004] spec file: Update the package name from libipa_hbac-python to python-libipa_hbac

2015-07-10 Thread Jan Cholasta
Hi, Dne 10.7.2015 v 12:05 Milan Kubik napsal(a): Name update + the renamed package breaks 'dnf builddep'. I will report the bug. Yum can take care of the conflict resolution. Patch attached. You might as well update libsss_nss_idmap-python to python-libsss_nss_idmap while you are at it.

Re: [Freeipa-devel] Time-Based Account Policies

2015-07-10 Thread Petr Vobornik
On 07/10/2015 12:43 PM, Alexander Bokovoy wrote: On Fri, 10 Jul 2015, Stanislav Laznicka wrote: Hi, Long time no post from me, time to make it up to you. Welcome back! I have been working on the the implementation of the design of time policies for HBAC rules on FreeIPA and SSSD sides.

Re: [Freeipa-devel] [PATCH 0282] Prevent to rename certprofile profile id

2015-07-10 Thread Simo Sorce
On Fri, 2015-07-10 at 11:28 +0200, Jan Cholasta wrote: Dne 10.7.2015 v 11:10 Simo Sorce napsal(a): On Fri, 2015-07-10 at 11:01 +0200, Jan Cholasta wrote: Dne 10.7.2015 v 10:59 Jan Cholasta napsal(a): Dne 10.7.2015 v 10:43 Martin Basti napsal(a): On 10/07/15 07:29, Jan Cholasta wrote:

Re: [Freeipa-devel] Time-Based Account Policies

2015-07-10 Thread Stanislav Laznicka
On 07/10/2015 01:10 PM, Petr Vobornik wrote: On 07/10/2015 12:43 PM, Alexander Bokovoy wrote: On Fri, 10 Jul 2015, Stanislav Laznicka wrote: Hi, Long time no post from me, time to make it up to you. Welcome back! I have been working on the the implementation of the design of time policies

Re: [Freeipa-devel] [PATCH 0334] Hide topology and domainlevel features

2015-07-10 Thread Tomas Babej
On 07/10/2015 03:07 PM, Simo Sorce wrote: On Wed, 2015-07-08 at 00:09 +0200, Tomas Babej wrote: On 07/07/2015 07:16 PM, Martin Basti wrote: On 07/07/15 10:33, Tomas Babej wrote: Hi, * Hide topology and domainlevel commands in the CLI * Hide topology and domainlevel in the WebUI * Set

Re: [Freeipa-devel] Time-Based Account Policies

2015-07-10 Thread Alexander Bokovoy
On Fri, 10 Jul 2015, Stanislav Laznicka wrote: Hi, Long time no post from me, time to make it up to you. Welcome back! I have been working on the the implementation of the design of time policies for HBAC rules on FreeIPA and SSSD sides. Attached is the current state of the FreeIPA

Re: [Freeipa-devel] [patch 0004] spec file: Update the package name from libipa_hbac-python to python-libipa_hbac

2015-07-10 Thread Milan Kubik
On 07/10/2015 12:55 PM, Jan Cholasta wrote: Hi, Dne 10.7.2015 v 12:05 Milan Kubik napsal(a): Name update + the renamed package breaks 'dnf builddep'. I will report the bug. Yum can take care of the conflict resolution. Patch attached. You might as well update

[Freeipa-devel] [patch 0006] ipalib: pass api instance into textui in doctest snippets

2015-07-10 Thread Milan Kubik
Hi, the recent set of patches that modified api broke the tests that are included in ipalib/cli.py This patch fixes the problems by passing api instance to textui() calls. Milan From 5df216ad49c6787a6e170a483c545d0fdcc99828 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Milan=20Kub=C3=ADk?=

Re: [Freeipa-devel] [patch 0006] ipalib: pass api instance into textui in doctest snippets

2015-07-10 Thread Milan Kubik
On 07/10/2015 01:57 PM, Milan Kubik wrote: Hi, the recent set of patches that modified api broke the tests that are included in ipalib/cli.py This patch fixes the problems by passing api instance to textui() calls. Milan This may not be the complete solution. Similar problems arise in the

[Freeipa-devel] [PATCH 0283] copy-schema-to-ca: allow to overwrite schema files

2015-07-10 Thread Martin Basti
https://fedorahosted.org/freeipa/ticket/5034 Patch attached. -- Martin Basti From d77e41e76c333e504600109d4d9fdd41809bfe8b Mon Sep 17 00:00:00 2001 From: Martin Basti mba...@redhat.com Date: Fri, 10 Jul 2015 14:17:02 +0200 Subject: [PATCH] copy-schema-to-ca: allow to overwrite schema files If

[Freeipa-devel] [PATCH 0284] stageuser-activate: show user name in error message instead of DN

2015-07-10 Thread Martin Basti
https://fedorahosted.org/freeipa/ticket/5038 I reworded the error message to keep the same format as stageuser-add and user-add. Patch attached. -- Martin Basti From 108b44354e049b4a1de009e144e2b645656bfc0e Mon Sep 17 00:00:00 2001 From: Martin Basti mba...@redhat.com Date: Fri, 10 Jul 2015

Re: [Freeipa-devel] [patch 0006] ipalib: pass api instance into textui in doctest snippets

2015-07-10 Thread Tomas Babej
On 07/10/2015 02:15 PM, Milan Kubik wrote: On 07/10/2015 01:57 PM, Milan Kubik wrote: Hi, the recent set of patches that modified api broke the tests that are included in ipalib/cli.py This patch fixes the problems by passing api instance to textui() calls. Milan This may not be the

Re: [Freeipa-devel] Time-Based Account Policies

2015-07-10 Thread Stanislav Laznicka
On 07/10/2015 01:12 PM, Matúš Honěk wrote: On 07/10/2015 12:43 PM, Alexander Bokovoy wrote: On Fri, 10 Jul 2015, Stanislav Laznicka wrote: Hi, Long time no post from me, time to make it up to you. Welcome back! I have been working on the the implementation of the design of time policies

Re: [Freeipa-devel] Time-Based Account Policies

2015-07-10 Thread Matúš Honěk
On 07/10/2015 12:43 PM, Alexander Bokovoy wrote: On Fri, 10 Jul 2015, Stanislav Laznicka wrote: Hi, Long time no post from me, time to make it up to you. Welcome back! I have been working on the the implementation of the design of time policies for HBAC rules on FreeIPA and SSSD sides.

[Freeipa-devel] [PATCH 0337] ipalib: Fix missing format for InvalidDomainLevelError

2015-07-10 Thread Tomas Babej
Hi, this patch fixes missing format for the InvalidDomainLevelError exception. Pushed to, under oneliner rule: master: 8a4e79c9e6ebb92e5bcc3c53e3f0073c10333227 ipa-4-2: fe69b2cbe48c9874ac0ee1d34cce1cdb244abadc Tomas From 6d099e3a24c530f894d94b118e20baa1424e7f9c Mon Sep 17 00:00:00 2001 From:

Re: [Freeipa-devel] [PATCH 0338] Revert Hide topology and domainlevel features

2015-07-10 Thread Tomas Babej
On 07/10/2015 03:25 PM, Simo Sorce wrote: On Fri, 2015-07-10 at 15:18 +0200, Tomas Babej wrote: Hi, This reverts commit 62e8002bc43ddd890c3db35a123cb7daf35e3121. Hiding of the topology and domainlevel features was necessary for the 4.2 branch only. Tomas ACK Simo, Pushed to

Re: [Freeipa-devel] [PATCH 0338] Revert Hide topology and domainlevel features

2015-07-10 Thread Simo Sorce
On Fri, 2015-07-10 at 15:18 +0200, Tomas Babej wrote: Hi, This reverts commit 62e8002bc43ddd890c3db35a123cb7daf35e3121. Hiding of the topology and domainlevel features was necessary for the 4.2 branch only. Tomas ACK Simo, -- Simo Sorce * Red Hat, Inc * New York -- Manage your

Re: [Freeipa-devel] Time-Based Account Policies

2015-07-10 Thread Martin Basti
On 10/07/15 12:08, Stanislav Laznicka wrote: Hi, Long time no post from me, time to make it up to you. I have been working on the the implementation of the design of time policies for HBAC rules on FreeIPA and SSSD sides. Attached is the current state of the FreeIPA solution. My comments and

[Freeipa-devel] [PATCH 0338] Revert Hide topology and domainlevel features

2015-07-10 Thread Tomas Babej
Hi, This reverts commit 62e8002bc43ddd890c3db35a123cb7daf35e3121. Hiding of the topology and domainlevel features was necessary for the 4.2 branch only. Tomas From 89e55240b3e3820b42e85b63cd1849816690321a Mon Sep 17 00:00:00 2001 From: Tomas Babej tba...@redhat.com Date: Fri, 10 Jul 2015

Re: [Freeipa-devel] [RFC] Community Portal Captcha

2015-07-10 Thread Simo Sorce
On Fri, 2015-07-10 at 13:05 -0400, Drew Erny wrote: Hi, All, I think some of you discussed with me the details of the community portal captcha with me on IRC. Yesterday, I wrote up a design proposal for the captcha system that I'd like some of you to take a look at and check to see that

Re: [Freeipa-devel] [PATCH 529] Fix DNS record installation for replicas

2015-07-10 Thread Simo Sorce
On Fri, 2015-07-10 at 13:03 -0400, Simo Sorce wrote: This bug affects 4.2, we should backport the fix there too. See ticket: https://fedorahosted.org/freeipa/ticket/5116 For what is worth I tested this change in my replica install code and it fixes the issue, though the code is different and

Re: [Freeipa-devel] [PATCH] 0001 Enhance the DNSNotARecordError message

2015-07-10 Thread Veronika Kabatova
- Original Message - From: Tomas Babej tba...@redhat.com To: Veronika Kabatova vkaba...@redhat.com, freeipa-devel@redhat.com Sent: Friday, July 10, 2015 2:56:58 PM Subject: Re: [Freeipa-devel] [PATCH] 0001 Enhance the DNSNotARecordError message On 07/09/2015 01:49 PM, Veronika

[Freeipa-devel] [RFC] Community Portal Captcha

2015-07-10 Thread Drew Erny
Hi, All, I think some of you discussed with me the details of the community portal captcha with me on IRC. Yesterday, I wrote up a design proposal for the captcha system that I'd like some of you to take a look at and check to see that I'm understanding it correctly, and that this captcha

[Freeipa-devel] [PATCH 0006] Start dirsrv for kdcproxy upgrade

2015-07-10 Thread Christian Heimes
Hi, this patch ensures that DS is running before HTTPInstance attempts to connect to LDAP. https://fedorahosted.org/freeipa/ticket/5113 While I was testing the patch I ran into trouble with DS. The upgrade script couldn't connect to 389/TCP, although ns-slapd was running. After some digging I

[Freeipa-devel] [PATCH 529] Fix DNS record installation for replicas

2015-07-10 Thread Simo Sorce
This bug affects 4.2, we should backport the fix there too. See ticket: https://fedorahosted.org/freeipa/ticket/5116 Simo. -- Simo Sorce * Red Hat, Inc * New York From 84ca685e4dab2880812a915f04798d647068de0c Mon Sep 17 00:00:00 2001 From: Simo Sorce s...@redhat.com Date: Fri, 10 Jul 2015