Re: [Freeipa-devel] [PATCH] 0053..0054 Configure lightweight CA key replication

2016-05-04 Thread Fraser Tweedale
On Thu, May 05, 2016 at 07:48:05AM +0200, Jan Cholasta wrote: > On 4.5.2016 06:04, Fraser Tweedale wrote: > >On Tue, May 03, 2016 at 05:05:58PM +1000, Fraser Tweedale wrote: > >>On Tue, Apr 26, 2016 at 10:02:45AM +0200, Jan Cholasta wrote: > >>>On 21.4.2016 05:30, Fraser Tweedale wrote: > On Th

Re: [Freeipa-devel] #5836 [RFE] Allow profile to specify default CA

2016-05-04 Thread Jan Cholasta
Hi, On 4.5.2016 02:21, Fraser Tweedale wrote: Continuing the discussion for #5836[1] as requested from triage session. [1] https://fedorahosted.org/freeipa/ticket/5836 IMO it is not important for FreeIPA 4.4. It is nice to have but I doubt it will make it. +1 Honza suggested it should be

Re: [Freeipa-devel] [PATCH] 0053..0054 Configure lightweight CA key replication

2016-05-04 Thread Jan Cholasta
On 4.5.2016 06:04, Fraser Tweedale wrote: On Tue, May 03, 2016 at 05:05:58PM +1000, Fraser Tweedale wrote: On Tue, Apr 26, 2016 at 10:02:45AM +0200, Jan Cholasta wrote: On 21.4.2016 05:30, Fraser Tweedale wrote: On Thu, Apr 14, 2016 at 04:39:37PM +1000, Fraser Tweedale wrote: Hi all, The att

[Freeipa-devel] [PATCHES 0089-0093] Authentication Indicators

2016-05-04 Thread Nathaniel McCallum
This series of patches implements authentication indicator insertion, evaluation and management in FreeIPA. Besides these patches, two other patches are needed to round out support. First, we need a UI patch: https://fedorahosted.org/freeipa/ticket/5872 Second, we need a SSSD patch to handle the

Re: [Freeipa-devel] Improving bug reporting

2016-05-04 Thread Rob Crittenden
Lukas Slebodnik wrote: On (04/05/16 12:56), Alexander Bokovoy wrote: I'm sorry but it was a TL;DR mail without any useful information to the topic. The topic is "Improving bug reporting". I do not care much how downstreams handle bug reports. I like David proposal with template. But I do not li

Re: [Freeipa-devel] Improving bug reporting

2016-05-04 Thread Lukas Slebodnik
On (04/05/16 12:56), Alexander Bokovoy wrote: >On Wed, 04 May 2016, Lukas Slebodnik wrote: >> On (04/05/16 11:05), Alexander Bokovoy wrote: >> > On Tue, 03 May 2016, Robbie Harwood wrote: >> > > Lukas Slebodnik writes: >> > > >> > > > On (03/05/16 12:29), Robbie Harwood wrote: >> > > > > David Ku

Re: [Freeipa-devel] [PATCH] pwpolicy: Do not expire passwords when maxlife is set to 0 (infinity).

2016-05-04 Thread Pavel Vomacka
On 05/04/2016 04:36 PM, Simo Sorce wrote: On Wed, 2016-05-04 at 15:39 +0200, Martin Kosek wrote: On 05/02/2016 02:28 PM, David Kupka wrote: https://fedorahosted.org/freeipa/ticket/2795 That patch looks suspiciously short given the struggles I saw in http://www.redhat.com/archives/freeipa-dev

Re: [Freeipa-devel] [PATCH] pwpolicy: Do not expire passwords when maxlife is set to 0 (infinity).

2016-05-04 Thread Simo Sorce
On Wed, 2016-05-04 at 15:39 +0200, Martin Kosek wrote: > On 05/02/2016 02:28 PM, David Kupka wrote: > > https://fedorahosted.org/freeipa/ticket/2795 > > That patch looks suspiciously short given the struggles I saw in > http://www.redhat.com/archives/freeipa-devel/2015-June/msg00198.html > :-) >

[Freeipa-devel] [PATCH 0472] fix stageuser-find test

2016-05-04 Thread Martin Basti
https://fedorahosted.org/freeipa/ticket/5281 I forgot to send patch that fixes also stageuser tests with current changes in has_keytab and has_password attributes. Patch attached From 125509907e74f77624086e2e86b531ac0feaf7ef Mon Sep 17 00:00:00 2001 From: Martin Basti Date: Wed, 4 May 2016 13

Re: [Freeipa-devel] [PATCH] pwpolicy: Do not expire passwords when maxlife is set to 0 (infinity).

2016-05-04 Thread Martin Kosek
On 05/02/2016 02:28 PM, David Kupka wrote: > https://fedorahosted.org/freeipa/ticket/2795 That patch looks suspiciously short given the struggles I saw in http://www.redhat.com/archives/freeipa-devel/2015-June/msg00198.html :-) Instead of setting to IPAPWD_END_OF_TIME, should we instead avoid fil

Re: [Freeipa-devel] [PATCH 0069] ipa-nis-manage enable: change service name from 'portmap' to 'rpcbind'

2016-05-04 Thread Gabe Alford
On Tue, May 3, 2016 at 11:17 PM, Abhijeet Kasurde wrote: > Hi Gabe, > > I am wondering, how are we handling "CalledProcessError" exception ? > I am not sure 100% what you are asking, but from what I understand, the "CalledProcessError" exception is when a process returns a non-zero exit status.

Re: [Freeipa-devel] [PATCH 0096] Batch command: avoid accessing potentially undefined context.principa

2016-05-04 Thread Jan Cholasta
Hi, On 22.4.2016 13:28, Petr Spacek wrote: Hello, Batch command: avoid accessing potentially undefined context.principal This might happen when the command is called directly in Python, e.g. in installers and so on. Pylint pylint-1.5.5-1.fc24.noarch caught this. https://fedorahosted.org/free

Re: [Freeipa-devel] [PATCH] 0001 (update 2) provide more information for "ipa cert-revoke -h"

2016-05-04 Thread Gabe Alford
On Wed, May 4, 2016 at 1:35 AM, Patrice Duc-Jacquet wrote: > Hi everyone > > this is a second update that take into account review feedback. > > In case the proposal fix is K what are the next step to commit this > change. I'm not sure to really understand the process. Thanks and regards > If th

[Freeipa-devel] Provisioning throughput

2016-05-04 Thread thierry bordaz
Hello, I have been doing some tests/measures using https://github.com/freeipa/freeipa-tools/blob/master/create-test-data.py. The tool creates a set of typical users/hosts/groups... to import with a ldapadd. I wrote down some finding in http://www.freeipa.org/page/V4/Performanc

Re: [Freeipa-devel] Another batch of Python 3 patches

2016-05-04 Thread Martin Basti
On 03.05.2016 18:14, Petr Viktorin wrote: On 05/03/2016 04:31 PM, Martin Basti wrote: On 03.05.2016 15:52, Petr Viktorin wrote: On 05/03/2016 03:02 PM, Petr Spacek wrote: On 2.5.2016 18:02, Martin Basti wrote: On 29.04.2016 19:46, Petr Viktorin wrote: Hello, These patches concentrate on t

Re: [Freeipa-devel] [TESTS][PATCH] Ping module tests in a non-declarative way

2016-05-04 Thread Peter Lacko
Hi! Thanks for the review, should be OK now. I won't change this email's subject, so adding it to the body only and will include it in subject of next patch. [PATCH 0001] Regards, Peter Lacko - Original Message - From: "Martin Basti" To: "Peter Lacko" , freeipa-devel@redhat.com Sent

Re: [Freeipa-devel] Improving bug reporting

2016-05-04 Thread Alexander Bokovoy
On Wed, 04 May 2016, Lukas Slebodnik wrote: On (04/05/16 11:05), Alexander Bokovoy wrote: On Tue, 03 May 2016, Robbie Harwood wrote: Lukas Slebodnik writes: > On (03/05/16 12:29), Robbie Harwood wrote: > > David Kupka writes: > > > > > --8<- trac-ticket-template-proposal

[Freeipa-devel] [PATCH 0110] DNS: Warn if forwarding policy conflicts with automatic empty zone

2016-05-04 Thread Petr Spacek
Hello, DNS: Warn if forwarding policy conflicts with automatic empty zones Forwarding policy "first" or "none" may conflicts with some automatic empty zones. Queries for zones specified by RFC 6303 will ignore forwarding and recursion and always result in NXDOMAIN answers. This is not detected a

Re: [Freeipa-devel] Improving bug reporting

2016-05-04 Thread Lukas Slebodnik
On (04/05/16 11:05), Alexander Bokovoy wrote: >On Tue, 03 May 2016, Robbie Harwood wrote: >> Lukas Slebodnik writes: >> >> > On (03/05/16 12:29), Robbie Harwood wrote: >> > > David Kupka writes: >> > > >> > > > --8<- trac-ticket-template-proposal --->8-- >> > > > Rel

Re: [Freeipa-devel] Improving bug reporting

2016-05-04 Thread Alexander Bokovoy
On Tue, 03 May 2016, Robbie Harwood wrote: Lukas Slebodnik writes: On (03/05/16 12:29), Robbie Harwood wrote: David Kupka writes: --8<- trac-ticket-template-proposal --->8-- Related SW versions: On server: {{{ $ rpm -q freeipa-server pki-base 389-ds-base bind sa

[Freeipa-devel] [PATCH] 0001 (update 2) provide more information for "ipa cert-revoke -h"

2016-05-04 Thread Patrice Duc-Jacquet
Hi everyone this is a second update that take into account review feedback. In case the proposal fix is K what are the next step to commit this change. I'm not sure to really understand the process. Thanks and regards Pat >From 0a2b0da4a1f2c517fae392ae3314796c0ebeee9a Mon Sep 17 00:00:00 200