Re: [Freeipa-devel] [PATCH] 252 Add the CA constraint to the self-signed CA we generate

2009-08-27 Thread David O'Brien
? This sounds like a dumb question but I just haven't come across it before :-\ Thanks. -- David O'Brien IPA Content Author Red Hat Asia Pacific +61 7 3514 8189 http://freeipa.org/page/DocumentationPortal http://git.fedorahosted.org/git/ipadocs.git He who asks is a fool for five minutes, but he

Re: [Freeipa-devel] [PATCH] Use DNS forwarders in /etc/named.conf

2009-09-06 Thread David O'Brien
Martin Nagy wrote: On Fri, 2009-09-04 at 09:50 +1000, David O'Brien wrote: Martin Nagy wrote: Hi, This patch adds options --forwarder and --no-forwarders. At least one of them must be used if you are doing a setup with DNS server. They are also mutually exclusive. The --forwarder

Re: [Freeipa-devel] [PATCH] 274 detect whether to uninstall the CA or not

2009-10-21 Thread David O'Brien
as well to get rid of the CA? if so, maybe we could add this to the --uninstall description on the help page (i.e., this will automatically remove any CA that was installed using the --ca option) if not so, what? Is there any case for not removing the CA when uninstalling the IPA server? -- David

Re: [Freeipa-devel] [PATCHES] Add A and PTR records during ipa-replica-prepare

2010-01-21 Thread David O'Brien
don't have my ipa-server or test machine available atm to check man pages :-\ If necessary pls raise a bugzilla. thanks -- David O'Brien Senior Technical Writer, Engineering Content Services Red Hat Asia Pacific Pty Ltd 193 North Quay, Brisbane +61 7 3514 8189 http://freeipa.org/page

Re: [Freeipa-devel] [PATCH] 369 fix word usage in installer

2010-02-03 Thread David O'Brien
describing the procedure, this would appear as The set-up procedure in our documentation, same as you did for server-specific operations. The other variants are correct. /nit-pick -- David O'Brien Senior Technical Writer, Engineering Content Services Red Hat Asia Pacific Pty Ltd 193 North Quay

Re: [Freeipa-devel] [PATCH] Restore ipaserver/__init__.py

2010-03-03 Thread David O'Brien
The latest message is something about __init__.pyc contains no 'xmlrpc' We replaced the .py file and the latest status was the above error no longer occurred but I still get ipa: ERROR: an internal error has occurred (http://pastebin.test.redhat.com/20693) -- David O'Brien Red Hat Asia

Re: [Freeipa-devel] [PATCH] Make the DNS forwarders interactive input less confusing

2010-03-03 Thread David O'Brien
, it's in the singular, so users should only enter one IP and then press Enter, and get the same question again. How does this sound? -- David O'Brien Red Hat Asia Pacific Pty Ltd He who asks is a fool for five minutes, but he who does not ask remains a fool forever. ~ Chinese proverb

Re: [Freeipa-devel] gettext proof of concept : My hovercraft is full of eels

2010-09-07 Thread David O'Brien
can own getting people to cover Hebrew -- David O'Brien Red Hat APAC Pty Ltd We couldn't care less about comfort. We make you feel good. Federico Minoli CEO Ducati Motor S.p.A. ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https

Re: [Freeipa-devel] [PATCH] 559 update ipa-getkeytab man page

2010-10-06 Thread David O'Brien
Rob Crittenden wrote: David O'Brien wrote: Rob Crittenden wrote: Add some missing options to the ipa-getkeytab man page. rob Can you be consistent with Kerberos instead of adding kerberos to the mix as well (unless necessary, of course)? If my understanding is correct, I'd update

Re: [Freeipa-devel] [PATCH] 0003 Remove reference to ipa_webgui from ipa-server-install man page

2010-11-02 Thread David O'Brien
: ... and starting the ipa_kpasswd service provided by IPA. -- David O'Brien Red Hat Asia Pacific Pty Ltd +61 7 3514 8189 He who asks is a fool for five minutes, but he who does not ask remains a fool forever. ~ Chinese proverb ___ Freeipa-devel mailing

Re: [Freeipa-devel] [PATCH] 0003 Remove reference to ipa_webgui from ipa-server-install man page

2010-11-03 Thread David O'Brien
Jan Zelený wrote: David O'Brien dav...@redhat.com wrote: Jan Zelený wrote: There was a single reference, so I removed it and rephrased the sentence a little. https://fedorahosted.org/freeipa/ticket/330 Jan nack ...and starting IPA\-provided service ipa_kpasswd. is grammatically incorrect

Re: [Freeipa-devel] [PATCH] 611 increase default username len

2010-11-25 Thread David O'Brien
Rob Crittenden wrote: Increase default username length to 32 and max for users and groups to 255. rob There doesn't appear to be a default max groupname length like there is for usernames. Does that mean it defaults to 255? /dob ___

Re: [Freeipa-devel] [PATCH] 619 more aci target docs

2010-12-01 Thread David O'Brien
? lets members of the admin group You might need to review the examples a bit. cheers -- David O'Brien Red Hat Asia Pacific Pty Ltd +61 7 3514 8189 He who asks is a fool for five minutes, but he who does not ask remains a fool forever. ~ Chinese proverb

Re: [Freeipa-devel] [PATCH] 619 more aci target docs

2010-12-05 Thread David O'Brien
Rob Crittenden wrote: Rob Crittenden wrote: David O'Brien wrote: Rob Crittenden wrote: I added some more documentation and examples to the aci plugin on targets. ticket 310 rob NACK Running behind with reviews, sorry. Just a few minor fixes: s/targetted/targeted/ s/This is primarily

Re: [Freeipa-devel] [PATCH] 0024 - Better random ranges

2010-12-12 Thread David O'Brien
it :) Simo. [1] http://directory.fedoraproject.org/wiki/DNA_Plugin In that case: ack. Pushed to master. Simo. Did this make it into a man page or other doc anywhere, or is there a ticket to do so? Also, s/arent't/aren't/ ;-) -- David O'Brien Red Hat Asia Pacific Pty Ltd +61 7 3514

Re: [Freeipa-devel] Updated SUDO spec

2010-12-12 Thread David O'Brien
complex examples? Identity(ies)? That's just messy. In ECS our policy is If it can be plural, write in plural; if it can only be singular, write in singular. Is this not possible in the UI? -- David O'Brien Red Hat Asia Pacific Pty Ltd +61 7 3514 8189 He who asks is a fool for five minutes

Re: [Freeipa-devel] [PATCH] 632 add migration cmd docs

2010-12-12 Thread David O'Brien
the opportunity you might like to fix this: + The simplest migration, acceptinging all defaults: -- David O'Brien Red Hat Asia Pacific Pty Ltd +61 7 3514 8189 He who asks is a fool for five minutes, but he who does not ask remains a fool forever. ~ Chinese proverb

Re: [Freeipa-devel] UI seems to be completely broken

2010-12-12 Thread David O'Brien
up FF and got what appears to be the normal webUI. I'm using jdennis' repo. Links are clickable and all seems to be working. I don't know what the lite server is; first I've heard of it. Anyway, WFM. -- David O'Brien Red Hat Asia Pacific Pty Ltd +61 7 3514 8189 He who asks is a fool

Re: [Freeipa-devel] [PATCH] Fixed typos in man page of ipa-getkeytab.

2010-12-19 Thread David O'Brien
Gowrishankar Rajaiyan wrote: Hi All, Fixed typos in the man page of ipa-getkeytab and corrected my name in Contributors.txt. Regards /Shanks ACK -- David O'Brien Red Hat Asia Pacific Pty Ltd +61 7 3514 8189 He who asks is a fool for five minutes, but he who does not ask remains

Re: [Freeipa-devel] [PATCH] 0041 Fix ipa-replica-manage man page

2010-12-21 Thread David O'Brien
, retrieving the data from the srv2.example.com replica I realise pull is a commonplace verb in this context, so I'm not especially fussed about that, but I'd like to see the other changes. -- David O'Brien Red Hat Asia Pacific Pty Ltd +61 7 3514 8189 He who asks is a fool for five minutes

Re: [Freeipa-devel] Where is the code that generates the initial CA and server cert?

2011-01-13 Thread David O'Brien
, easily reproducible test case. Rich, the Install Guide on that page is due to be updated as soon as we get through some doc reviews. It's mostly a copy of the 1.2 version as it is. -- David O'Brien Red Hat Asia Pacific Pty Ltd +61 7 3514 8189 He who asks is a fool for five minutes, but he who

Re: [Freeipa-devel] [PATCH] 73 Update config doc to reflect that 0 is not allowed for search time limit.

2011-02-07 Thread David O'Brien
. I'd be inclined to change it to ( 0, or -1 for unlimited) but remember, I'm not a coder :) cheers -- David O'Brien Red Hat Asia Pacific Pty Ltd +61 7 3514 8189 He who asks is a fool for five minutes, but he who does not ask remains a fool forever. ~ Chinese proverb

Re: [Freeipa-devel] [PATCH] 77 Update krbtpolicy doc to inform that restarting krb5kdc might be needed.

2011-02-07 Thread David O'Brien
Dmitri Pal wrote: On 02/07/2011 06:46 PM, David O'Brien wrote: Jenny Galipeau wrote: Pavel Zuna wrote: It seems that restarting krb5kdc is only needed when changes to the global policy are made. Per-user policies take effect immediately for newly requested tickets. Can someone please confirm

Re: [Freeipa-devel] [PATCH] 77 Update krbtpolicy doc to inform that restarting krb5kdc might be needed.

2011-02-08 Thread David O'Brien
Rob Crittenden wrote: David O'Brien wrote: Dmitri Pal wrote: On 02/07/2011 06:46 PM, David O'Brien wrote: Jenny Galipeau wrote: Pavel Zuna wrote: It seems that restarting krb5kdc is only needed when changes to the global policy are made. Per-user policies take effect immediately for newly

Re: [Freeipa-devel] Help define the roles IPA has by default

2011-02-10 Thread David O'Brien
are people (faiap), while Helpdesk is a department. Anyway, you get the idea. We've already started with Name, Description, Goals; with a few use cases I can put together short sections with links to existing docs on how to use the relevant commands, or write them as needed. cheers -- David

Re: [Freeipa-devel] [PATCH] 44 Fixes in ipa-join man page

2011-02-15 Thread David O'Brien
a keytab with kerberos credentials. Join an IPA domain and retrieve a keytab using Kerberos credentials. -- David O'Brien Red Hat Asia Pacific Pty Ltd +61 7 3514 8189 He who asks is a fool for five minutes, but he who does not ask remains a fool forever. ~ Chinese proverb

Re: [Freeipa-devel] [PATCH] 44 Fixes in ipa-join man page

2011-02-17 Thread David O'Brien
Jan Zelený wrote: David O'Brien dav...@redhat.com wrote: Jan Zelený wrote: https://fedorahosted.org/freeipa/ticket/784 https://fedorahosted.org/freeipa/ticket/786 https://fedorahosted.org/freeipa/ticket/787 Jan nack A few typos and style issues: - _(File were to store the keytab

Re: [Freeipa-devel] [PATCH] Fixed in ipa-server-install help and man page

2011-02-17 Thread David O'Brien
recommendation you can pick and push the right one one. Jan Yes, pick maximum -- David O'Brien Red Hat Asia Pacific Pty Ltd +61 7 3514 8189 He who asks is a fool for five minutes, but he who does not ask remains a fool forever. ~ Chinese proverb

Re: [Freeipa-devel] Help define the roles IPA has by default

2011-02-21 Thread David O'Brien
Dmitri Pal wrote: On 02/11/2011 10:12 AM, Rob Crittenden wrote: Dmitri Pal wrote: On 02/10/2011 07:25 PM, David O'Brien wrote: Dmitri Pal wrote: On 02/10/2011 03:05 PM, Jakub Hrozek wrote: On 02/10/2011 05:12 PM, Rob Crittenden wrote: But what other roles do we need? The mind boggles

Re: [Freeipa-devel] [PATCH] 738 default.conf man page

2011-02-22 Thread David O'Brien
. s/server(s)/servers/ +user IPA configurationf ile configuration file +Optional configuration files used in a particular context are. The value of mode is used to attempt to load these files, if they exist: I'm not sure what this means -- David O'Brien Red Hat Asia Pacific Pty Ltd +61 7 3514

Re: [Freeipa-devel] [PATCH] 5 Add note about ipa-dns-install to ipa-server-install man page

2011-03-29 Thread David O'Brien
by running ipa-dns-install. cheers -- David O'Brien Senior Content Author Engineering Content Services (ECS) Red Hat Asia Pacific Pty Ltd +61 7 3514 8189 He who asks is a fool for five minutes, but he who does not ask remains a fool forever. ~ Chinese proverb

Re: [Freeipa-devel] [PATCH] 5 Add note about ipa-dns-install to ipa-server-install man page

2011-03-30 Thread David O'Brien
Jan Cholasta wrote: On 30.3.2011 01:01, David O'Brien wrote: Jan Cholasta wrote: Added the note so that users know that they can setup DNS at any time after ipa-server-install. https://fedorahosted.org/freeipa/ticket/1082