Re: [Freeipa-devel] Instructions to build ipa under RHEL

2016-03-29 Thread Rob Crittenden
Lukas Slebodnik wrote: On (29/03/16 10:16), Oleg Fayans wrote: Hi team, Is there any kind of $subj available? Like, which repos to enable, etc. I'm raising the topic because I was unable to install a number of build-time dependencies to build the official 4.3.1 packages under RHEL-7.2 (I need

Re: [Freeipa-devel] Instructions to build ipa under RHEL

2016-03-29 Thread Lukas Slebodnik
On (29/03/16 10:16), Oleg Fayans wrote: >Hi team, > >Is there any kind of $subj available? Like, which repos to enable, etc. >I'm raising the topic because I was unable to install a number of >build-time dependencies to build the official 4.3.1 packages under >RHEL-7.2 (I need freeipa-4.3.1 srpms

Re: [Freeipa-devel] [PATCH] 0009 webui: Show certificates in useful format

2016-03-29 Thread Pavel Vomacka
On 03/16/2016 06:56 PM, Petr Vobornik wrote: On 03/15/2016 01:23 PM, Pavel Vomacka wrote: Hello, patch for https://fedorahosted.org/freeipa/ticket/5311 is attached. -- Pavel^3 Vomacka Not tested, but can we avoid using s with "white-space: pre" and therefore use only

Re: [Freeipa-devel] URI in HBAC - design page

2016-03-29 Thread Jan Pazdziora
On Tue, Mar 29, 2016 at 11:21:05AM +0200, Lukáš Hellebrandt wrote: > > Right, we only have to deal with path as the protocol is already in HBAC > rules. I don't see protocol in HBAC rules -- there are HBAC (~ PAM) service name and canonical hostname of the machine. But there isn't protocol

Re: [Freeipa-devel] URI in HBAC - design page

2016-03-29 Thread Jan Pazdziora
On Tue, Mar 29, 2016 at 10:59:13AM +0200, Lukáš Hellebrandt wrote: > > No change compared to how it works now: if the public part doesn't > require any authorization at all, the application won't even ask for > authorization. In other words, it won't be possible to enable unauthenticated access

Re: [Freeipa-devel] URI in HBAC - design page

2016-03-29 Thread Lukáš Hellebrandt
On 03/24/2016 02:39 PM, Rob Crittenden wrote: > Adam Young wrote: >> On 03/24/2016 05:43 AM, Jan Pazdziora wrote: >>> On Wed, Mar 23, 2016 at 04:41:49PM +0100, Lukáš Hellebrandt wrote: I created a design page for the feature: http://www.freeipa.org/page/URI-based-HBAC-design >>> I

Re: [Freeipa-devel] URI in HBAC - design page

2016-03-29 Thread Jan Pazdziora
On Tue, Mar 29, 2016 at 10:50:08AM +0200, Lukáš Hellebrandt wrote: > > > > The benefit of this approach is that if you need to evaluate access > > to say > > > > /application/data/ > > > > and you already have rule for > > > > /application/ [ users/ ] > > > > cached

Re: [Freeipa-devel] URI in HBAC - design page

2016-03-29 Thread Lukáš Hellebrandt
On 03/24/2016 01:41 PM, Jan Pazdziora wrote: > On Wed, Mar 23, 2016 at 04:41:49PM +0100, Lukáš Hellebrandt wrote: >> I created a design page for the feature: >> >> http://www.freeipa.org/page/URI-based-HBAC-design > > Could you please elaborate on unauthenticated accesses? > > Many web

Re: [Freeipa-devel] URI in HBAC - design page

2016-03-29 Thread Lukáš Hellebrandt
On 03/24/2016 01:31 PM, Jan Pazdziora wrote: > On Wed, Mar 23, 2016 at 06:39:45PM +0100, Petr Vobornik wrote: >> On 03/23/2016 04:41 PM, Lukáš Hellebrandt wrote: >>> I created a design page for the feature: >>> >>> http://www.freeipa.org/page/URI-based-HBAC-design >> >> 1. The design page doesn't

Re: [Freeipa-devel] URI in HBAC - design page

2016-03-29 Thread Lukáš Hellebrandt
On 03/24/2016 10:31 AM, Jan Pazdziora wrote: > On Wed, Mar 23, 2016 at 04:41:49PM +0100, Lukáš Hellebrandt wrote: >> I created a design page for the feature: >> >> http://www.freeipa.org/page/URI-based-HBAC-design > > In the document, you say > > In all of them [ approaches ], I use only

Re: [Freeipa-devel] URI in HBAC - design page

2016-03-29 Thread Lukáš Hellebrandt
On 03/24/2016 10:24 AM, Jan Pazdziora wrote: > On Wed, Mar 23, 2016 at 04:41:49PM +0100, Lukáš Hellebrandt wrote: >> I created a design page for the feature: >> >> http://www.freeipa.org/page/URI-based-HBAC-design > > The way most web applications (that I see as the first use for this > feature)

Re: [Freeipa-devel] Instructions to build ipa under RHEL

2016-03-29 Thread Oleg Fayans
Petr, Martin, thanks guys! On 03/29/2016 10:37 AM, Petr Vobornik wrote: > On 03/29/2016 10:16 AM, Oleg Fayans wrote: >> Hi team, >> >> Is there any kind of $subj available? Like, which repos to enable, etc. >> I'm raising the topic because I was unable to install a number of >> build-time

Re: [Freeipa-devel] Instructions to build ipa under RHEL

2016-03-29 Thread Martin Babinsky
On 03/29/2016 10:33 AM, Oleg Fayans wrote: OK, I enabled the following repo: http://cosmos.lab.eng.pnq.redhat.com/idmqe-extras/rhel/7Server/x86_64/ and that gave me: pylint python-polib python-pytest-multihost python-pytest-sourceorder But the rest is still unavailable On 03/29/2016 10:16 AM,

Re: [Freeipa-devel] Instructions to build ipa under RHEL

2016-03-29 Thread Petr Vobornik
On 03/29/2016 10:16 AM, Oleg Fayans wrote: Hi team, Is there any kind of $subj available? Like, which repos to enable, etc. I'm raising the topic because I was unable to install a number of build-time dependencies to build the official 4.3.1 packages under RHEL-7.2 (I need freeipa-4.3.1 srpms

Re: [Freeipa-devel] Instructions to build ipa under RHEL

2016-03-29 Thread Oleg Fayans
OK, I enabled the following repo: http://cosmos.lab.eng.pnq.redhat.com/idmqe-extras/rhel/7Server/x86_64/ and that gave me: pylint python-polib python-pytest-multihost python-pytest-sourceorder But the rest is still unavailable On 03/29/2016 10:16 AM, Oleg Fayans wrote: > Hi team, > > Is there

[Freeipa-devel] Instructions to build ipa under RHEL

2016-03-29 Thread Oleg Fayans
Hi team, Is there any kind of $subj available? Like, which repos to enable, etc. I'm raising the topic because I was unable to install a number of build-time dependencies to build the official 4.3.1 packages under RHEL-7.2 (I need freeipa-4.3.1 srpms to build ipa-tests package): awk