Re: [Freeipa-devel] [PATCH 0052] Create server-dns sub-package

2015-07-16 Thread Alexander Bokovoy
On Thu, 16 Jul 2015, Jan Cholasta wrote: Dne 15.7.2015 v 19:39 Simo Sorce napsal(a): - Original Message - From: Petr Spacek pspa...@redhat.com To: Jan Cholasta jchol...@redhat.com, freeipa-devel@redhat.com, Alexander Bokovoy aboko...@redhat.com Cc: Simo Sorce s...@redhat.com Sent:

Re: [Freeipa-devel] [PATCH 0052] Create server-dns sub-package

2015-07-16 Thread Jan Cholasta
Dne 15.7.2015 v 19:39 Simo Sorce napsal(a): - Original Message - From: Petr Spacek pspa...@redhat.com To: Jan Cholasta jchol...@redhat.com, freeipa-devel@redhat.com, Alexander Bokovoy aboko...@redhat.com Cc: Simo Sorce s...@redhat.com Sent: Tuesday, July 14, 2015 10:33:41 AM Subject:

Re: [Freeipa-devel] [PATCH] 904 do not import memcache on client

2015-07-16 Thread Tomas Babej
On 07/16/2015 10:25 AM, Petr Vobornik wrote: Fixes regression caused by cd3ca94ff2ef738cb3a9eae502193413058f976d. Which caused: * client installation failure (missing memcache) * invalid warning in CLI on server https://fedorahosted.org/freeipa/ticket/5133 Thanks for fixing this

Re: [Freeipa-devel] [PATCH] 0191 Add SELinux boolean for oddjobd-activated services

2015-07-16 Thread Tomas Babej
On 07/14/2015 01:31 PM, Alexander Bokovoy wrote: Hi! An SELinux policy we need for one-way trust is now in Fedora updates-testing repository. Attached patch adds support for 'httpd_run_ipa' SELinux boolean. Below is how one-way trust is using the communication with oddjobd (it is a

[Freeipa-devel] [PATCH 012] Fix selinux denial during kdcproxy user creation

2015-07-16 Thread Christian Heimes
Hi, the patch fixes the SELinux denial for kdcproxy's home directory. I have successfully tested a migration from FreeIPA 4.1. The user, group and home directory are successfully created with the correct permissions. https://fedorahosted.org/freeipa/ticket/5135 Christian From

Re: [Freeipa-devel] 4.3 Branch?

2015-07-16 Thread Petr Vobornik
On 07/14/2015 03:23 PM, Nathaniel McCallum wrote: 4.3 is going to be a very narrow feature release. Should we branch 4.3 early so that we can still land new features on master during 4.3? I did not like it at first but we should do it. -- Petr Vobornik -- Manage your subscription for the

Re: [Freeipa-devel] [PATCH 0057] Do not use anonymous bind in migration UI.

2015-07-16 Thread David Kupka
On 15/07/15 16:04, David Kupka wrote: On 15/07/15 15:34, Jan Cholasta wrote: Dne 15.7.2015 v 15:21 David Kupka napsal(a): https://fedorahosted.org/freeipa/ticket/4953 To test this patch: 1. Migrate users from LDAP or other FreeIPA server (https://www.freeipa.org/page/Howto/Migration) 2.

[Freeipa-devel] [PATCH] 904 do not import memcache on client

2015-07-16 Thread Petr Vobornik
Fixes regression caused by cd3ca94ff2ef738cb3a9eae502193413058f976d. Which caused: * client installation failure (missing memcache) * invalid warning in CLI on server https://fedorahosted.org/freeipa/ticket/5133 -- Petr Vobornik From 2a814456b7c143bc2f2f23d4706ec0543bf66ae3 Mon Sep 17 00:00:00

[Freeipa-devel] [PATCH 0340] dcerpc: Expand explanation for WERR_ACCESS_DENIED

2015-07-16 Thread Tomas Babej
Hi, It's possible for AD to contact a wrong IPA server in case the DNS SRV records on the AD sides are not properly configured. Mention this case in the error message as well. https://fedorahosted.org/freeipa/ticket/5013 From fee75ea269d70ca700a83037a1db9b07ea6e49bf Mon Sep 17 00:00:00 2001

Re: [Freeipa-devel] [PATCH 012] Fix selinux denial during kdcproxy user creation

2015-07-16 Thread Tomas Babej
On 07/16/2015 12:51 PM, Christian Heimes wrote: Hi, the patch fixes the SELinux denial for kdcproxy's home directory. I have successfully tested a migration from FreeIPA 4.1. The user, group and home directory are successfully created with the correct permissions.

Re: [Freeipa-devel] [PATCH 012] Fix selinux denial during kdcproxy user creation

2015-07-16 Thread Christian Heimes
On 2015-07-16 12:51, Christian Heimes wrote: Hi, the patch fixes the SELinux denial for kdcproxy's home directory. I have successfully tested a migration from FreeIPA 4.1. The user, group and home directory are successfully created with the correct permissions.

Re: [Freeipa-devel] 4.3 Branch?

2015-07-16 Thread Tomas Babej
On 07/16/2015 01:13 PM, Petr Vobornik wrote: On 07/14/2015 03:23 PM, Nathaniel McCallum wrote: 4.3 is going to be a very narrow feature release. Should we branch 4.3 early so that we can still land new features on master during 4.3? I did not like it at first but we should do it. We

Re: [Freeipa-devel] [PATCH 0052] Create server-dns sub-package

2015-07-16 Thread Petr Spacek
On 16.7.2015 08:33, Alexander Bokovoy wrote: On Thu, 16 Jul 2015, Jan Cholasta wrote: Dne 15.7.2015 v 19:39 Simo Sorce napsal(a): - Original Message - From: Petr Spacek pspa...@redhat.com To: Jan Cholasta jchol...@redhat.com, freeipa-devel@redhat.com, Alexander Bokovoy

Re: [Freeipa-devel] [PATCH] 902 webui: fix user reset password dialog

2015-07-16 Thread Martin Basti
On 14/07/15 18:47, Petr Vobornik wrote: Could not open user password dialog. regression introduced in ed78dcfa3acde7aeb1f381f49988c6911c5277ee https://fedorahosted.org/freeipa/ticket/5131 Works for me, ÅCK -- Martin Basti -- Manage your subscription for the Freeipa-devel mailing list:

[Freeipa-devel] [PATCH] 0192 oddjob: avoid chown keytab to sssd if sssd user does not exist

2015-07-16 Thread Alexander Bokovoy
Hi, a simple optimisation to allow FreeIPA 4.2 to work with SSSD 1.13 running as root instead of sssd user. Details in the commit message. This also fixes a simple exception in current Fedora 22 + mkosek/freeipa-4.2 repo because user 'sssd' does not exist. Fixes ticket

Re: [Freeipa-devel] [PATCH] 0192 oddjob: avoid chown keytab to sssd if sssd user does not exist

2015-07-16 Thread Tomas Babej
On 07/16/2015 01:19 PM, Alexander Bokovoy wrote: Hi, a simple optimisation to allow FreeIPA 4.2 to work with SSSD 1.13 running as root instead of sssd user. Details in the commit message. This also fixes a simple exception in current Fedora 22 + mkosek/freeipa-4.2 repo because user

Re: [Freeipa-devel] [PATCH] 902 webui: fix user reset password dialog

2015-07-16 Thread Petr Vobornik
On 07/16/2015 02:12 PM, Martin Basti wrote: On 14/07/15 18:47, Petr Vobornik wrote: Could not open user password dialog. regression introduced in ed78dcfa3acde7aeb1f381f49988c6911c5277ee https://fedorahosted.org/freeipa/ticket/5131 Works for me, ÅCK Pushed to: master:

Re: [Freeipa-devel] [PATCH 0047] ipa-ca-install: print more specific errors when CA is already installed

2015-07-16 Thread Petr Vobornik
On 07/16/2015 01:48 PM, Martin Basti wrote: On 15/07/15 14:47, Martin Babinsky wrote: Fixes https://fedorahosted.org/freeipa/ticket/4492 ACK Pushed to: master: 26dee66d1bf05aac5af5f82862ce54585ccde7e4 ipa-4-2: f5fa38399277ab16fa32832f53580651ad4a4026 -- Petr Vobornik -- Manage your

Re: [Freeipa-devel] [PATCH] 903, 287 fix hbac rule/selinuxuser map search for non-admin users

2015-07-16 Thread Petr Vobornik
On 07/16/2015 03:18 PM, Martin Basti wrote: On 14/07/15 18:50, Petr Vobornik wrote: hbacrule has it default attributes (which are used in search) attribute 'memberhostgroup'. This attr is not in ACI nor in schema. If the search contains an attribute which can't be read then the search won't

Re: [Freeipa-devel] [PATCH] 903, 287 fix hbac rule/selinuxuser map search for non-admin users

2015-07-16 Thread Martin Basti
On 14/07/15 18:50, Petr Vobornik wrote: hbacrule has it default attributes (which are used in search) attribute 'memberhostgroup'. This attr is not in ACI nor in schema. If the search contains an attribute which can't be read then the search won't return anything. Therefore all searches with

Re: [Freeipa-devel] [PATCH 0047] ipa-ca-install: print more specific errors when CA is already installed

2015-07-16 Thread Martin Basti
On 15/07/15 14:47, Martin Babinsky wrote: Fixes https://fedorahosted.org/freeipa/ticket/4492 ACK -- Martin Basti -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

Re: [Freeipa-devel] [PATCH 012] Fix selinux denial during kdcproxy user creation

2015-07-16 Thread Christian Heimes
On 2015-07-16 13:46, Tomas Babej wrote: On 07/16/2015 01:35 PM, Christian Heimes wrote: On 2015-07-16 12:51, Christian Heimes wrote: Hi, the patch fixes the SELinux denial for kdcproxy's home directory. I have successfully tested a migration from FreeIPA 4.1. The user, group and home

Re: [Freeipa-devel] [PATCH 0052] Create server-dns sub-package

2015-07-16 Thread Petr Spacek
On 16.7.2015 13:47, Petr Spacek wrote: On 16.7.2015 08:33, Alexander Bokovoy wrote: On Thu, 16 Jul 2015, Jan Cholasta wrote: Dne 15.7.2015 v 19:39 Simo Sorce napsal(a): - Original Message - From: Petr Spacek pspa...@redhat.com To: Jan Cholasta jchol...@redhat.com,

Re: [Freeipa-devel] [PATCH 0052] Create server-dns sub-package

2015-07-16 Thread Alexander Bokovoy
On Thu, 16 Jul 2015, Petr Spacek wrote: Third version of the patch is attached, please view. Behavior: - freeipa-server package continues to exist and does not include DNS dependencies - freeipa-server-dns package is new and requires all DNS dependencies - install freeipa-server will not pull

Re: [Freeipa-devel] [PATCH 0288] ipa-replica-manage: Allow value 'no' for replica-certify-all attr in abort-clean-ruv subcommand

2015-07-16 Thread Rob Crittenden
Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/4988 Patch attached. IMHO this should be mentioned in the man page. rob -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [PATCH 0288] ipa-replica-manage: Allow value 'no' for replica-certify-all attr in abort-clean-ruv subcommand

2015-07-16 Thread Martin Basti
https://fedorahosted.org/freeipa/ticket/4988 Patch attached. -- Martin Basti From b38c190f2d87a39f7b83aafc3e8c45c228ea1b2a Mon Sep 17 00:00:00 2001 From: Martin Basti mba...@redhat.com Date: Thu, 16 Jul 2015 16:26:55 +0200 Subject: [PATCH] Allow value 'no' for replica-certify-all attr in

Re: [Freeipa-devel] [PATCH 012] Fix selinux denial during kdcproxy user creation

2015-07-16 Thread Tomas Babej
On 07/16/2015 01:35 PM, Christian Heimes wrote: On 2015-07-16 12:51, Christian Heimes wrote: Hi, the patch fixes the SELinux denial for kdcproxy's home directory. I have successfully tested a migration from FreeIPA 4.1. The user, group and home directory are successfully created with the

Re: [Freeipa-devel] [PATCH 0288] ipa-replica-manage: Allow value 'no' for replica-certify-all attr in abort-clean-ruv subcommand

2015-07-16 Thread Martin Basti
On 16/07/15 17:07, Rob Crittenden wrote: Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/4988 Patch attached. IMHO this should be mentioned in the man page. rob Updated patch attached. -- Martin Basti From 0be2d89326529d472b0ba715f7fa2f0738ff2cd5 Mon Sep 17 00:00:00 2001

Re: [Freeipa-devel] [PATCH 0281] Validate adding a privilege to a permission

2015-07-16 Thread Jan Cholasta
Dne 15.7.2015 v 12:47 Martin Basti napsal(a): On 10/07/15 10:43, Martin Basti wrote: On 10/07/15 07:32, Jan Cholasta wrote: Hi, Dne 9.7.2015 v 16:55 Martin Basti napsal(a): https://fedorahosted.org/freeipa/ticket/5075 Patch attached. the check is very plugin-specific, so I don't think it

Re: [Freeipa-devel] [PATCH 0057] Do not use anonymous bind in migration UI.

2015-07-16 Thread Jan Cholasta
Dne 16.7.2015 v 12:16 David Kupka napsal(a): On 15/07/15 16:04, David Kupka wrote: On 15/07/15 15:34, Jan Cholasta wrote: Dne 15.7.2015 v 15:21 David Kupka napsal(a): https://fedorahosted.org/freeipa/ticket/4953 To test this patch: 1. Migrate users from LDAP or other FreeIPA server

Re: [Freeipa-devel] [PATCH 0052] Create server-dns sub-package

2015-07-16 Thread Jan Cholasta
Dne 16.7.2015 v 16:50 Alexander Bokovoy napsal(a): On Thu, 16 Jul 2015, Petr Spacek wrote: Third version of the patch is attached, please view. Behavior: - freeipa-server package continues to exist and does not include DNS dependencies - freeipa-server-dns package is new and requires all DNS

Re: [Freeipa-devel] [PATCH 0057] Do not use anonymous bind in migration UI.

2015-07-16 Thread Alexander Bokovoy
On Fri, 17 Jul 2015, Jan Cholasta wrote: Dne 16.7.2015 v 12:16 David Kupka napsal(a): On 15/07/15 16:04, David Kupka wrote: On 15/07/15 15:34, Jan Cholasta wrote: Dne 15.7.2015 v 15:21 David Kupka napsal(a): https://fedorahosted.org/freeipa/ticket/4953 To test this patch: 1. Migrate users