Re: [Freeipa-devel] [PATCH 0259] Server Upgrade: Wait until DS is ready after restart

2015-05-26 Thread Martin Basti
@foobar.service' s[:-8] 'dirsrv@foobar' s[:-8][7:] 'foobar' Empty string is expected. Emptry string means the instance has not been specified, and check will be skipped. Because 'dirsrv.service' doest not contain instance name, so empty string should be returned. -- Martin Basti -- Manage your

Re: [Freeipa-devel] [PATCHES 0001-0011 v3] Profile management

2015-05-21 Thread Martin Basti
On 21/05/15 14:31, Martin Basti wrote: On 21/05/15 14:16, Martin Basti wrote: On 20/05/15 16:41, Fraser Tweedale wrote: Hi Honza, Martin et al, Latest patches attached. On top of previous patches (most review matters addressed**) patches 0008..0011 add support for profiles and user

[Freeipa-devel] [PATCH 0255] Server Upgrade: Fix: executed schema upgrade

2015-05-21 Thread Martin Basti
Accidentaly , schema upgrade hasn't beed executed by ipa-server-upgrade. https://fedorahosted.org/freeipa/ticket/4904 Patch attached. -- Martin Basti From d6b1107aa9f952bf61dbdbaabdbab822d0dc69b5 Mon Sep 17 00:00:00 2001 From: Martin Basti mba...@redhat.com Date: Thu, 21 May 2015 14:40:22

[Freeipa-devel] [PATCH 0254] Server Upgrade: Wait until DS is ready after restart

2015-05-21 Thread Martin Basti
3183fc490d9615fada1dcc9069eb1303e9e61be8 Mon Sep 17 00:00:00 2001 From: Martin Basti mba...@redhat.com Date: Thu, 21 May 2015 13:25:10 +0200 Subject: [PATCH] Server Upgrade: wait until DS is ready During server upgrade we should wait until DS is ready after restart, otherwise connection error is raised. Instead of 389

Re: [Freeipa-devel] [PATCHES 0001-0011 v3] Profile management

2015-05-21 Thread Martin Basti
Profile,cn=permissions,cn=pbac,dc=abc,dc=idm,dc=lab,dc=eng,dc=brq,dc=redhat,dc=com\22;): Invalid syntax. [cleanup]: stopping directory server [cleanup]: restoring configuration I cannot find the ipacertprofilestoreissued in any IPA schema file. Did I miss something? -- Martin Basti -- Manage

Re: [Freeipa-devel] [PATCHES 0001-0011 v3] Profile management

2015-05-21 Thread Martin Basti
On 21/05/15 14:16, Martin Basti wrote: On 20/05/15 16:41, Fraser Tweedale wrote: Hi Honza, Martin et al, Latest patches attached. On top of previous patches (most review matters addressed**) patches 0008..0011 add support for profiles and user certificates to `ipa cert-request'. ** those

Re: [Freeipa-devel] Kerberos over HTTPS (KDC proxy)

2015-05-22 Thread Martin Basti
: Read IPA Masters' permission. Martin Basti and Petr Spacek have suggested that I introduce a new permission for the task. I haven't figured out how to configure and assign a new permission. Right now my experimental code uses this ACI: (targetfilter=(ipaConfigString=enabledService))(targetattr

[Freeipa-devel] [PATCH 0256] DNS: add UnknonwRecord attribute to schema

2015-05-22 Thread Martin Basti
Patch attached. Initial part of https://fedorahosted.org/freeipa/ticket/4939 -- Martin Basti From 50fd8f7d2d11f963a288c18dd4d1d98c941b7d51 Mon Sep 17 00:00:00 2001 From: Martin Basti mba...@redhat.com Date: Fri, 22 May 2015 12:39:08 +0200 Subject: [PATCH] DNS: add UnknownRecord to schema

Re: [Freeipa-devel] [PATCH 0048] fix ipa help command output errors

2015-05-22 Thread Martin Basti
for each ticket please? Martin^2 -- Martin Basti -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

[Freeipa-devel] [PATCH 0258] Server Upgrade: move code from ipa-upgrade config into separate module

2015-05-22 Thread Martin Basti
IPA services upgrade is executed only by ipa-server-upgrade, ipa-upgradeconfig will not work. Patch attached. https://fedorahosted.org/freeipa/ticket/4904 -- Martin Basti From 23272ea2f1eb8473563a7c84bbae3f276a9a495f Mon Sep 17 00:00:00 2001 From: Martin Basti mba...@redhat.com Date: Fri, 22

Re: [Freeipa-devel] [PATCH 0048] fix ipa help command output errors

2015-05-22 Thread Martin Basti
On 22/05/15 17:40, Gabe Alford wrote: On Fri, May 22, 2015 at 9:01 AM, Martin Basti mba...@redhat.com mailto:mba...@redhat.com wrote: On 22/05/15 16:08, Gabe Alford wrote: Hello, This should fix https://fedorahosted.org/freeipa/ticket/3584, and as requested in the ticket

Re: [Freeipa-devel] [PATCHES 0001-0011 v3] Profile management

2015-05-21 Thread Martin Basti
Martin^2 -- Martin Basti -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Re: [Freeipa-devel] [PATCH 0334] Hide topology and domainlevel features

2015-07-07 Thread Martin Basti
On 07/07/15 10:33, Tomas Babej wrote: Hi, * Hide topology and domainlevel commands in the CLI * Hide topology and domainlevel in the WebUI * Set maximum allowed domain level to 0 * Do not configure and enable the topology plugin https://fedorahosted.org/freeipa/ticket/5097 ACK -- Martin

Re: [Freeipa-devel] [PATCH 0055] ipa-replica-prepare: Do not create DNS zone it automatically.

2015-07-07 Thread Martin Basti
On 03/07/15 06:17, David Kupka wrote: Since ipa-replica-* tools will be soon removed I think this simple check should be enough. ACK -- Martin Basti -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA

Re: [Freeipa-devel] [PATCH] 0024..0025 Add missing certprofile features

2015-07-07 Thread Martin Basti
Updated patch 0025 (v4). Profile now gets re-enabled if profile update fails. Patch 0024 remains at v3. Thanks, Fraser ACK -- Martin Basti -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http

Re: [Freeipa-devel] [PATCH 0046] add option to skip client API version check and proceed at user's own risk

2015-07-07 Thread Martin Basti
On 03/07/15 16:41, Martin Babinsky wrote: On 07/02/2015 01:58 PM, Martin Babinsky wrote: First attempt at https://fedorahosted.org/freeipa/ticket/4768 Attaching reworked patch. ACK -- Martin Basti -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com

[Freeipa-devel] [PATCH 0276] Fix: ipa-dns-install will add CA records if CA is installed

2015-07-07 Thread Martin Basti
https://fedorahosted.org/freeipa/ticket/5101 Patch attached. -- Martin Basti From f5de8e7a9ecd8f8220bd542d9ff264ce7917a829 Mon Sep 17 00:00:00 2001 From: Martin Basti mba...@redhat.com Date: Tue, 7 Jul 2015 16:28:48 +0200 Subject: [PATCH] Fix regression: ipa-dns-install will add CA records

Re: [Freeipa-devel] [PATCH] 371 Added support for changing vault encryption.

2015-08-13 Thread Martin Basti
On 08/04/2015 01:20 AM, Endi Sukma Dewata wrote: The vault-mod command has been modified to support changing vault encryption attributes (i.e. type, password, public/private keys) in addition to normal attributes (i.e. description). Changing the encryption requires retrieving the stored secret

Re: [Freeipa-devel] [patch]-pytest-multihost-Return File Attributes to sftp.put

2015-08-13 Thread Martin Basti
On 08/13/2015 01:55 PM, Niranjan wrote: Greetings, This patch is regarding pytest-multihost plugin. Including a patch to return FileAttributes for sftp.put function used in the function. Current put_file function in transport.py in ParamikoTransport Class doesn't return any value. So when

Re: [Freeipa-devel] [PATCH 0002] TEST: Stageuser plugin

2015-08-13 Thread Martin Basti
On 08/11/2015 10:57 AM, Lenka Doudova wrote: On 08/11/2015 10:06 AM, thierry bordaz wrote: On 08/04/2015 01:37 PM, Lenka Doudova wrote: Dne 30.7.2015 v 16:10 Martin Basti napsal(a): On 30/07/15 16:09, Martin Basti wrote: On 29/07/15 16:10, Martin Basti wrote: On 29/07/15 15:29, Lenka

Re: [Freeipa-devel] [PATCH] 374 Fixed vault container ownership.

2015-08-13 Thread Martin Basti
On 08/10/2015 09:45 PM, Endi Sukma Dewata wrote: The vault-add command has been fixed such that if the user/service private vault container does not exist yet it will be created and owned by the user/service instead of the vault creator. https://fedorahosted.org/freeipa/ticket/5194 I

Re: [Freeipa-devel] [PATCH 471] ULC: Prevent preserved users from being assigned membership

2015-08-13 Thread Martin Basti
On 08/12/2015 02:20 PM, Jan Cholasta wrote: On 12.8.2015 12:22, Jan Cholasta wrote: Hi, the attached patch fixes https://fedorahosted.org/freeipa/ticket/5170. Honza Fixed broken user_show on preserved user. Updated patch attached. Pushed to: master:

Re: [Freeipa-devel] [PATCH] First part of integration tests for Topology Plugin

2015-08-13 Thread Martin Basti
On 08/11/2015 03:36 PM, Oleg Fayans wrote: Hi Martin, On 08/11/2015 02:02 PM, Martin Basti wrote: NACK, comments inline. On 11/08/15 13:25, Oleg Fayans wrote: Hi Martin, Thanks for the review! On 08/10/2015 07:08 PM, Martin Basti wrote: Thank you for patch, I have a few nitpicks: 1

Re: [Freeipa-devel] [PATCH] Added try/except for error handling ipautil

2015-08-17 Thread Martin Basti
On 08/17/2015 11:11 AM, Abhijeet Kasurde wrote: Hi All, Please find the update patch with review comments, On 08/14/2015 05:19 PM, Martin Basti wrote: On 08/14/2015 06:57 AM, Abhijeet Kasurde wrote: On 08/13/2015 07:08 PM, Martin Basti wrote: On 08/10/2015 01:47 PM, Abhijeet Kasurde

Re: [Freeipa-devel] [PATCH 0297] ULC: add user-stage command

2015-08-18 Thread Martin Basti
On 08/18/2015 09:50 AM, thierry bordaz wrote: On 08/17/2015 08:33 PM, Martin Basti wrote: Hello, the 'user-stage' command replaces 'stageuser-add --from-delete' command. https://fedorahosted.org/freeipa/ticket/5041 Thierry can you check If I don't break everything, it works for me

Re: [Freeipa-devel] [PATCH 0297] ULC: add user-stage command

2015-08-18 Thread Martin Basti
On 08/18/2015 09:59 AM, thierry bordaz wrote: On 08/18/2015 09:55 AM, Martin Basti wrote: On 08/18/2015 09:50 AM, thierry bordaz wrote: On 08/17/2015 08:33 PM, Martin Basti wrote: Hello, the 'user-stage' command replaces 'stageuser-add --from-delete' command. https://fedorahosted.org

Re: [Freeipa-devel] [PATCH 0002] TEST: Stageuser plugin

2015-08-18 Thread Martin Basti
, the test case will be valid, if it's changed I'll fix the test case to reflect the new command. Lenka On 08/14/2015 05:39 PM, Martin Basti wrote: On 08/14/2015 11:04 AM, Lenka Doudova wrote: NACK syntax error, missing ')' -from ipatests.util import assert_equal, assert_not_equal, raises +from

Re: [Freeipa-devel] [PATCH 0297] ULC: add user-stage command

2015-08-18 Thread Martin Basti
On 08/18/2015 11:32 AM, thierry bordaz wrote: On 08/18/2015 10:02 AM, Martin Basti wrote: On 08/18/2015 09:59 AM, thierry bordaz wrote: On 08/18/2015 09:55 AM, Martin Basti wrote: On 08/18/2015 09:50 AM, thierry bordaz wrote: On 08/17/2015 08:33 PM, Martin Basti wrote: Hello

Re: [Freeipa-devel] [PATCH 0058] ipa-restore: check whether DS is running before attempting connection

2015-08-18 Thread Martin Basti
On 08/18/2015 01:16 PM, Alexander Bokovoy wrote: On Tue, 18 Aug 2015, Martin Babinsky wrote: https://fedorahosted.org/freeipa/ticket/4838 -- Martin^3 Babinsky From d86aae6c3fef4dea1afbbdbacbc978afbbfa5fcf Mon Sep 17 00:00:00 2001 From: Martin Babinsky mbabi...@redhat.com Date: Tue, 18 Aug

Re: [Freeipa-devel] [PATCH 0298] Server Upgrade: start DS before CA is started

2015-08-18 Thread Martin Basti
On 08/18/2015 07:14 PM, Martin Basti wrote: On 08/18/2015 07:05 PM, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/5232 Patch attached. Self-NACK, I sent wrong patch The correct patch attached. From 4b2ce935b0f9f6c5fcdb6aa00b55ce2654b09e0f Mon Sep 17 00:00:00 2001 From

[Freeipa-devel] [PATCH 0298] Server Upgrade: start DS before CA is started

2015-08-18 Thread Martin Basti
https://fedorahosted.org/freeipa/ticket/5232 Patch attached. From 1f583442cb5c239de84e0f11046baa30d4b12636 Mon Sep 17 00:00:00 2001 From: Martin Basti mba...@redhat.com Date: Tue, 18 Aug 2015 18:01:09 +0200 Subject: [PATCH] Server Upgrade: Start DS before CA is started. https://fedorahosted.org

Re: [Freeipa-devel] [PATCH 0060] user-undel: Fix error messages.

2015-08-18 Thread Martin Basti
On 08/17/2015 03:39 PM, David Kupka wrote: On 14/08/15 17:18, Martin Basti wrote: On 08/13/2015 08:17 AM, David Kupka wrote: https://fedorahosted.org/freeipa/ticket/5207 Requires patch freeipa-jcholast-471.1. NACK This patch causes internal server error ipa user-del user --preserve

Re: [Freeipa-devel] [PATCH] 0039 Prohibit deletion of included profiles

2015-08-18 Thread Martin Basti
On 08/13/2015 12:09 PM, Fraser Tweedale wrote: On Thu, Aug 13, 2015 at 12:31:27PM +0300, Alexander Bokovoy wrote: On Thu, 13 Aug 2015, Fraser Tweedale wrote: On Thu, Aug 13, 2015 at 12:01:09PM +0300, Alexander Bokovoy wrote: On Thu, 13 Aug 2015, Fraser Tweedale wrote: On Thu, Aug 13, 2015

Re: [Freeipa-devel] [PATCH 0297] ULC: add user-stage command

2015-08-18 Thread Martin Basti
Thank you for the patch, I checked it, I just changed permission name to have all first letters in uppercase as others. Updated merged patch attached. On 08/18/2015 05:34 PM, thierry bordaz wrote: On 08/18/2015 04:13 PM, thierry bordaz wrote: On 08/18/2015 04:04 PM, Martin Basti wrote

Re: [Freeipa-devel] [PATCH 0059] improve the handling of krb5-related errors in dnssec daemons

2015-08-18 Thread Martin Basti
On 08/18/2015 06:41 PM, Martin Babinsky wrote: This patch fixes https://fedorahosted.org/freeipa/ticket/5229 and also improves the handling of Kerberos errors in other DNSSEC daemons. -- Martin^3 Babinsky Pushed to: ipa-4-2: a9f010fc286bee163601cbf0b512c6170501a1e9 master:

Re: [Freeipa-devel] [PATCH 0298] Server Upgrade: start DS before CA is started

2015-08-18 Thread Martin Basti
On 08/18/2015 07:05 PM, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/5232 Patch attached. Self-NACK, I sent wrong patch -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http

Re: [Freeipa-devel] [PATCH] Added try/except for error handling ipautil

2015-08-19 Thread Martin Basti
On 08/19/2015 01:49 PM, Abhijeet Kasurde wrote: Hi All, Please find the latest patch with review comments included. Thanks Martin for your help and review comments. Thanks, Abhijeet Kasurde On 08/19/2015 05:08 PM, Martin Basti wrote: On 08/17/2015 02:08 PM, Abhijeet Kasurde wrote: Hi

Re: [Freeipa-devel] [PATCH] First part of integration tests for Topology Plugin

2015-08-19 Thread Martin Basti
advised. Added the third test for http://www.freeipa.org/page/V4/Manage_replication_topology/Test_plan#Test_case:_Removal_of_a_topology_segment_is_allowed_only_if_there_is_at_least_one_more_segment_connecting_the_given_replica On 08/13/2015 05:06 PM, Martin Basti wrote: On 08/11/2015 03:36

Re: [Freeipa-devel] [PATCH] 0035 client: Update DNS with all available local IP addresses.

2015-08-18 Thread Martin Basti
On 08/18/2015 08:02 PM, David Kupka wrote: On 31/07/15 18:31, Martin Basti wrote: On 28/07/15 09:52, David Kupka wrote: On 27/07/15 16:45, David Kupka wrote: On 15/01/15 17:13, David Kupka wrote: On 01/15/2015 03:22 PM, David Kupka wrote: On 01/15/2015 12:43 PM, David Kupka wrote: On 01

Re: [Freeipa-devel] [PATCH 0059] improve the handling of krb5-related errors in dnssec daemons

2015-08-18 Thread Martin Basti
On 08/18/2015 09:13 PM, Martin Basti wrote: On 08/18/2015 06:41 PM, Martin Babinsky wrote: This patch fixes https://fedorahosted.org/freeipa/ticket/5229 and also improves the handling of Kerberos errors in other DNSSEC daemons. -- Martin^3 Babinsky Pushed to: ipa-4-2

Re: [Freeipa-devel] [PATCH 0063] client: Update DNS with all available local IP addresses.

2015-08-19 Thread Martin Basti
On 08/19/2015 12:46 PM, David Kupka wrote: On 19/08/15 11:06, Jan Cholasta wrote: On 19.8.2015 10:36, Martin Basti wrote: On 08/18/2015 10:53 PM, Martin Basti wrote: On 08/18/2015 08:02 PM, David Kupka wrote: On 31/07/15 18:31, Martin Basti wrote: On 28/07/15 09:52, David Kupka wrote

Re: [Freeipa-devel] [PATCH] First part of integration tests for Topology Plugin

2015-08-20 Thread Martin Basti
On 08/20/2015 10:26 AM, Martin Basti wrote: On 08/19/2015 04:17 PM, Martin Basti wrote: I got this: https://paste.fedoraproject.org/256746/43999380/ FYI replica install failure. (I will retest it, but I'm pretty sure that it was clean VM, test for some reason install client first

Re: [Freeipa-devel] [PATCH 0297] ULC: add user-stage command

2015-08-21 Thread Martin Basti
On 08/20/2015 07:17 PM, thierry bordaz wrote: On 08/20/2015 05:21 PM, Martin Basti wrote: On 08/20/2015 11:27 AM, Jan Cholasta wrote: On 19.8.2015 10:57, Jan Cholasta wrote: On 19.8.2015 10:47, thierry bordaz wrote: On 08/19/2015 10:34 AM, Jan Cholasta wrote: On 19.8.2015 09:39, thierry

Re: [Freeipa-devel] [PATCH] small fixes related to running dnssec tests in RHEL

2015-08-24 Thread Martin Basti
On 08/24/2015 01:28 PM, Oleg Fayans wrote: Hi, Could anyone review this. We are really blocked with testing on RHEL and Patch 0005 fixes it. Thank you. On 08/21/2015 10:52 AM, Oleg Fayans wrote: Hi list, Here are the the fixes for https://fedorahosted.org/freeipa/ticket/5240 plus

Re: [Freeipa-devel] [PATCH 0002] TEST: Stageuser plugin

2015-08-24 Thread Martin Basti
NACK You have unmerged changes in the patch On 08/24/2015 02:14 PM, Lenka Doudova wrote: from ipatests.test_xmlrpc import objectclasses + HEAD from ipatests.test_xmlrpc.xmlrpc_test import ( Declarative, fuzzy_digits, fuzzy_uuid, fuzzy_set_ci, add_sid, add_oc) +=== +from

Re: [Freeipa-devel] [PATCH 0006] Fixed installation failures

2015-08-24 Thread Martin Basti
On 08/24/2015 12:55 PM, Oleg Fayans wrote: Hi all. The current issue [1] effectively blocks testing of 4.2 branch. Here is (one of the possible) solution, that proved to work. [1] https://www.redhat.com/archives/freeipa-devel/2015-August/msg00085.html The patch needs rebase for ipa-4-2

Re: [Freeipa-devel] [PATCH] small fixes related to running dnssec tests in RHEL

2015-08-24 Thread Martin Basti
On 08/24/2015 02:36 PM, Martin Basti wrote: On 08/24/2015 01:28 PM, Oleg Fayans wrote: Hi, Could anyone review this. We are really blocked with testing on RHEL and Patch 0005 fixes it. Thank you. On 08/21/2015 10:52 AM, Oleg Fayans wrote: Hi list, Here are the the fixes for https

Re: [Freeipa-devel] [PATCH 0058] dns: do not add (forward)zone if it is already resolvable.

2015-08-24 Thread Martin Basti
On 08/20/2015 10:28 AM, David Kupka wrote: On 31/07/15 13:32, Martin Basti wrote: On 30/07/15 14:38, Martin Basti wrote: On 29/07/15 16:12, David Kupka wrote: https://fedorahosted.org/freeipa/ticket/5087 NACK You forgot to update API.txt file Thanks for catching that. Updated patch

Re: [Freeipa-devel] [PATCH 020] Change internal rsa_(public|private)_key variable names

2015-08-24 Thread Martin Basti
On 07/28/2015 04:28 PM, Simo Sorce wrote: On Tue, 2015-07-28 at 16:18 +0200, Christian Heimes wrote: In two places the vault plugin refers to rsa public or rsa private key although the code can handle just any kind of asymmetric algorithms, e.g. ECDSA. The patch just renames the occurences to

Re: [Freeipa-devel] ipa-replica-prepare requests reverse zone on RHEL

2015-08-20 Thread Martin Basti
On 08/20/2015 11:42 AM, Oleg Fayans wrote: Hi Martin On 08/20/2015 11:33 AM, Martin Basti wrote: On 08/20/2015 10:18 AM, Oleg Fayans wrote: Hi all, I am trying to run integration tests for dnssec in RHEL-7.2 The tests keep failing at the step of preparing the replica. I figured out

Re: [Freeipa-devel] ipa-replica-prepare requests reverse zone on RHEL

2015-08-20 Thread Martin Basti
On 08/20/2015 11:52 AM, Martin Basti wrote: On 08/20/2015 11:42 AM, Oleg Fayans wrote: Hi Martin On 08/20/2015 11:33 AM, Martin Basti wrote: On 08/20/2015 10:18 AM, Oleg Fayans wrote: Hi all, I am trying to run integration tests for dnssec in RHEL-7.2 The tests keep failing

Re: [Freeipa-devel] ipa-replica-prepare requests reverse zone on RHEL

2015-08-20 Thread Martin Basti
--no-reverse during the replica preparation on master. This looks like a bug to me. On 08/20/2015 12:37 PM, Oleg Fayans wrote: On 08/20/2015 12:01 PM, Martin Basti wrote: On 08/20/2015 11:52 AM, Martin Basti wrote: On 08/20/2015 11:42 AM, Oleg Fayans wrote: Hi Martin On 08/20/2015 11:33 AM

Re: [Freeipa-devel] [Freeipa-users] Dns SOA MNAME not resolving from LDAP data

2015-08-20 Thread Martin Basti
will be lost on an update? Kind Regards, David (Adding freeipa-users back) I checked code, it is default. You can change named.conf, upgrade will not replace it. Martin 2015-08-20 14:32 GMT+02:00 Martin Basti mba...@redhat.com mailto:mba...@redhat.com: On 08/20/2015 02:22 PM, Martin Basti

Re: [Freeipa-devel] [PATCH 0002] TEST: Stageuser plugin

2015-08-20 Thread Martin Basti
, the test case will be valid, if it's changed I'll fix the test case to reflect the new command. Lenka On 08/14/2015 05:39 PM, Martin Basti wrote: On 08/14/2015 11:04 AM, Lenka Doudova wrote: NACK syntax error, missing ')' -from ipatests.util import assert_equal, assert_not_equal, raises +from

Re: [Freeipa-devel] ipa-replica-prepare requests reverse zone on RHEL

2015-08-20 Thread Martin Basti
you try fedora on the same machine? On 08/20/2015 01:43 PM, Martin Basti wrote: It could be, please file a bug. On 08/20/2015 12:51 PM, Oleg Fayans wrote: Hi Martin, I guess, I know where is the problem. During replica-install the replica tries to resolve it's own ip to a hostname to check

Re: [Freeipa-devel] [PATCHES 0056-0057] improve backing-up of DNSSEC-related files

2015-08-17 Thread Martin Basti
On 08/13/2015 03:22 PM, Martin Babinsky wrote: PATCH 0056 just fixes a typo in ipaplatform/paths PATCH 0057 addresses https://fedorahosted.org/freeipa/ticket/5159 ACK Pushed to: ipa-4-2: 73ab4859e0749aeb8bf68454d575f94123695877 master: 0d1f35b054f0373d24eb2fe1830f2cf90b539381 -- Manage

Re: [Freeipa-devel] [PATCH 0357] trusts: Detect domain clash with IPA domain when adding a AD

2015-08-17 Thread Martin Basti
On 08/17/2015 02:58 PM, Martin Babinsky wrote: On 08/06/2015 10:55 AM, Tomas Babej wrote: Hi, When IPA is deployed in the same domain as AD, trust-add fails since the names of the local domain and trusted domain ranges is the same - it's always DOMAIN.NAME_id_range. When adding a trusted

Re: [Freeipa-devel] [PATCH 0356] trusts: Detect missing Samba instance

2015-08-17 Thread Martin Basti
On 08/17/2015 02:41 PM, Martin Babinsky wrote: On 08/06/2015 10:11 AM, Tomas Babej wrote: Hi, In the event of invocation of trust related commands, IPA server needs to contact local Samba instance. This is not possible on servers that merely act as AD trust agents, since they do not have

Re: [Freeipa-devel] [PATCH 0297] ULC: add user-stage command

2015-08-18 Thread Martin Basti
On 08/18/2015 03:49 PM, thierry bordaz wrote: On 08/18/2015 03:06 PM, Martin Basti wrote: On 08/18/2015 11:32 AM, thierry bordaz wrote: On 08/18/2015 10:02 AM, Martin Basti wrote: On 08/18/2015 09:59 AM, thierry bordaz wrote: On 08/18/2015 09:55 AM, Martin Basti wrote: On 08/18/2015

Re: [Freeipa-devel] [PATCH] 0195 harden trust-fetch-domains oddjobd script

2015-08-18 Thread Martin Basti
On 08/18/2015 06:00 PM, Tomas Babej wrote: On 08/18/2015 11:56 AM, Alexander Bokovoy wrote: On Tue, 18 Aug 2015, Alexander Bokovoy wrote: On Mon, 17 Aug 2015, Tomas Babej wrote: On 08/17/2015 09:03 AM, Alexander Bokovoy wrote: On Mon, 17 Aug 2015, Tomas Babej wrote: On 08/13/2015 04:29

Re: [Freeipa-devel] [PATCH] 375 Added mechanism to copy vault secrets.

2015-08-19 Thread Martin Basti
On 08/16/2015 05:29 PM, Endi Sukma Dewata wrote: The vault-add and vault-archive commands have been modified to optionally retrieve a secret from a source vault, then re-archive the secret into the new/existing target vault. https://fedorahosted.org/freeipa/ticket/5223 I cannot apply this

Re: [Freeipa-devel] [PATCH] 0299 client: Update DNS with all available local IP addresses.

2015-08-19 Thread Martin Basti
On 08/18/2015 10:53 PM, Martin Basti wrote: On 08/18/2015 08:02 PM, David Kupka wrote: On 31/07/15 18:31, Martin Basti wrote: On 28/07/15 09:52, David Kupka wrote: On 27/07/15 16:45, David Kupka wrote: On 15/01/15 17:13, David Kupka wrote: On 01/15/2015 03:22 PM, David Kupka wrote

[Freeipa-devel] [PATCH 0297] ULC: add user-stage command

2015-08-17 Thread Martin Basti
'user-stage'. From 74f0f8aa22f0c62284e5254d717baf9a067c6f17 Mon Sep 17 00:00:00 2001 From: Martin Basti mba...@redhat.com Date: Mon, 17 Aug 2015 20:11:21 +0200 Subject: [PATCH] Add user-stage command This patch replaces 'stageuser-add --from-delete' with new command user-stage. Original way

Re: [Freeipa-devel] Unable to install bits from ipa-4-2 branch

2015-08-17 Thread Martin Basti
On 08/12/2015 01:10 PM, Milan Kubík wrote: On 08/10/2015 04:41 PM, Jan Cholasta wrote: Dne 10.8.2015 v 16:03 Milan Kubík napsal(a): Forwarded Message Subject: Re: [Freeipa-devel] Unable to install bits from ipa-4-2 branch Date: Mon, 10 Aug 2015 15:55:35 +0200

Re: [Freeipa-devel] [patch 0011] Temporary workaround for [patch 0010] Python list comprehension leak breaking the test execution

2015-08-20 Thread Martin Basti
On 08/17/2015 09:53 AM, Milan Kubík wrote: On 08/11/2015 03:23 PM, Milan Kubík wrote: On 08/11/2015 09:53 AM, Jan Cholasta wrote: On 11.8.2015 09:46, Milan Kubík wrote: On 08/11/2015 09:08 AM, Jan Cholasta wrote: On 11.8.2015 09:00, Milan Kubík wrote: On 08/10/2015 06:22 PM, Milan Kubík

Re: [Freeipa-devel] [PATCH 0297] ULC: add user-stage command

2015-08-20 Thread Martin Basti
of the VERSION stuff that changed. Except that (changing VERSION), the fix looks good to me thanks thierry On 08/18/2015 07:21 PM, Martin Basti wrote: Thank you for the patch, I checked it, I just changed permission name to have all first letters in uppercase as others. Updated merged patch attached

Re: [Freeipa-devel] ipa-replica-prepare requests reverse zone on RHEL

2015-08-20 Thread Martin Basti
On 08/20/2015 10:18 AM, Oleg Fayans wrote: Hi all, I am trying to run integration tests for dnssec in RHEL-7.2 The tests keep failing at the step of preparing the replica. I figured out, the ipa-replica-prepare with the standard parameters requests reverse zone info (does not do it in

Re: [Freeipa-devel] [PATCH] 00015 User life cycle: permission to delete a preserved user

2015-06-29 Thread Martin Basti
On 22/06/15 17:08, thierry bordaz wrote: Add the permission to Stage users administrators to delete already preserved user ACK -- Martin Basti -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA

Re: [Freeipa-devel] [PATCH 0050] Fix client ca.crt to match the server's cert

2015-06-30 Thread Martin Basti
I'm getting certificate on server without extra '\n' at the end. So certificate files are not the same. -- Martin Basti -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page

Re: [Freeipa-devel] [PATCH 0051] Clear SSSD caches when uninstalling the client

2015-06-30 Thread Martin Basti
On 30/06/15 16:10, Martin Basti wrote: On 30/06/15 15:18, Martin Basti wrote: On 30/06/15 14:47, Simo Sorce wrote: On Tue, 2015-06-30 at 13:19 +0200, Tomas Babej wrote: On 06/30/2015 01:08 PM, Martin Basti wrote: On 30/06/15 13:00, Tomas Babej wrote: On 06/29/2015 03:50 PM, Martin Basti

Re: [Freeipa-devel] [PATCH 0051] Clear SSSD caches when uninstalling the client

2015-06-30 Thread Martin Basti
On 30/06/15 15:18, Martin Basti wrote: On 30/06/15 14:47, Simo Sorce wrote: On Tue, 2015-06-30 at 13:19 +0200, Tomas Babej wrote: On 06/30/2015 01:08 PM, Martin Basti wrote: On 30/06/15 13:00, Tomas Babej wrote: On 06/29/2015 03:50 PM, Martin Basti wrote: On 29/06/15 13:46, Jakub Hrozek

Re: [Freeipa-devel] [PATCH] Use Exception class instead of StandardError

2015-06-26 Thread Martin Basti
-- Martin Basti -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Re: [Freeipa-devel] [PATCH] 881 add python-setuptools to requires

2015-06-26 Thread Martin Basti
, in module from ipaplatform.base.tasks import BaseTaskNamespace File /usr/lib/python2.7/site-packages/ipaplatform/base/tasks.py, line 28, in module from pkg_resources import parse_version ImportError: No module named pkg_resources ACK -- Martin Basti -- Manage your subscription

Re: [Freeipa-devel] [PATCH 0051] Clear SSSD caches when uninstalling the client

2015-06-30 Thread Martin Basti
On 30/06/15 13:00, Tomas Babej wrote: On 06/29/2015 03:50 PM, Martin Basti wrote: On 29/06/15 13:46, Jakub Hrozek wrote: On Fri, Jun 05, 2015 at 11:31:54AM -0600, Gabe Alford wrote: Thanks. Updated patch attached. On Fri, Jun 5, 2015 at 9:53 AM, Jakub Hrozek jhro...@redhat.com wrote

[Freeipa-devel] [PATCH 0270] Sanitize CA replica install

2015-06-30 Thread Martin Basti
Check if cafile exists first, before using it. Patch attached. -- Martin Basti From 155b8d6ebe452ddd69cf94a2fb38d5420a9a3c11 Mon Sep 17 00:00:00 2001 From: Martin Basti mba...@redhat.com Date: Tue, 30 Jun 2015 12:16:56 +0200 Subject: [PATCH] Sanitize CA replica install Check if cafile exist

Re: [Freeipa-devel] [PATCH 0294] ULC: fix stageuser-add --from-delete command

2015-07-29 Thread Martin Basti
On 28/07/15 13:22, David Kupka wrote: On 23/07/15 13:46, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/5145 Patch attached. This patch fixes only first part of problem -- the traceback. Removing promt for name and surname requires too big hacks in internal API, and I'm not sure

Re: [Freeipa-devel] [PATCH 016] Require Dogtag PKI = 10.2.6

2015-07-29 Thread Martin Basti
On 29/07/15 15:56, Martin Basti wrote: On 23/07/15 12:26, Christian Heimes wrote: Dogtag 10.2.6 comes with two fixes for cloning from 9.x to 10.x instances: https://fedorahosted.org/pki/ticket/1495 https://fedorahosted.org/pki/ticket/1488 https://fedorahosted.org/freeipa/ticket/5140

Re: [Freeipa-devel] ipa-server-install completely broken in upstream

2015-07-30 Thread Martin Basti
-4.2.90.201507300929GIT4e18a62-0.fc22.x86_64 root@f22master:/home/ofayans]$ ipa-server-install root@f22master:/home/ofayans]$ Any Ideas how did it happen? Is something in /var/log/ipaserver-install.log? -- Martin Basti -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman

Re: [Freeipa-devel] [PATCH 0058] dns: do not add (forward)zone if it is already resolvable.

2015-07-30 Thread Martin Basti
On 29/07/15 16:12, David Kupka wrote: https://fedorahosted.org/freeipa/ticket/5087 NACK You forgot to update API.txt file -- Martin Basti -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http

Re: [Freeipa-devel] [PATCH 0291, 0292] Limit max age of replication changelog

2015-07-30 Thread Martin Basti
On 22/07/15 17:03, Martin Basti wrote: On 20/07/15 19:04, Mark Reynolds wrote: On 07/20/2015 12:50 PM, Martin Basti wrote: On 20/07/15 17:48, Petr Vobornik wrote: On 07/20/2015 05:24 PM, Rob Crittenden wrote: Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/5086 Patch attached

Re: [Freeipa-devel] [PATCH 0002] TEST: Stageuser plugin

2015-07-30 Thread Martin Basti
On 30/07/15 16:09, Martin Basti wrote: On 29/07/15 16:10, Martin Basti wrote: On 29/07/15 15:29, Lenka Doudova wrote: Hi, thanks a lot for the comments, will work on it tomorrow. Lenka Dne 29.7.2015 v 15:27 Martin Basti napsal(a): On 27/07/15 16:47, Lenka Doudova wrote: Hi, I'm attaching

Re: [Freeipa-devel] [PATCH] 0028 add --out option to user-show

2015-07-31 Thread Martin Basti
On 31/07/15 14:22, Martin Basti wrote: On 30/07/15 06:22, Fraser Tweedale wrote: On Thu, Jul 30, 2015 at 10:19:19AM +1000, Fraser Tweedale wrote: On Wed, Jul 29, 2015 at 03:48:47PM +0200, Jan Cholasta wrote: Dne 29.7.2015 v 15:46 Martin Basti napsal(a): On 29/07/15 15:41, Martin Basti wrote

Re: [Freeipa-devel] [PATCH 017] certprofile-import: do not require profileId in profile data

2015-07-31 Thread Martin Basti
On 30/07/15 12:44, Christian Heimes wrote: On 2015-07-24 12:41, Martin Basti wrote: On 24/07/15 05:15, Fraser Tweedale wrote: diff --git a/ipalib/plugins/certprofile.py b/ipalib/plugins/certprofile.py index 5550ed942521dbab2e783fba1570520268f9b378..fe8934690fe09499f0bacb6610d9815a2b4367a4

Re: [Freeipa-devel] [patch 0007] tests: Allow Tracker.dn be an instance of Fuzzy

2015-07-31 Thread Martin Basti
Trackers for plugins like CA ACL, which use ipaUniqueID as their primary key. Thanks, Milan Pushed to: master: 3f90aa0c18727f02e5e373ea0b625cfa6edb7a37 ipa-4-2: 3b90044f309548a7d0c508622b2858c010ba352f -- Martin Basti -- Manage your subscription for the Freeipa-devel mailing list: https

Re: [Freeipa-devel] [PATCH] 0035 client: Update DNS with all available local IP addresses.

2015-07-31 Thread Martin Basti
On 28/07/15 09:52, David Kupka wrote: On 27/07/15 16:45, David Kupka wrote: On 15/01/15 17:13, David Kupka wrote: On 01/15/2015 03:22 PM, David Kupka wrote: On 01/15/2015 12:43 PM, David Kupka wrote: On 01/12/2015 06:34 PM, Martin Basti wrote: On 09/01/15 14:43, David Kupka wrote: On 01/07

Re: [Freeipa-devel] [PATCH 0050] ACI plugin: correctly parse bind rules enclosed in parentheses

2015-07-28 Thread Martin Basti
On 28/07/15 13:33, Martin Babinsky wrote: On 07/27/2015 05:10 PM, Martin Basti wrote: On 23/07/15 16:06, Martin Babinsky wrote: This is a quick fix for https://fedorahosted.org/freeipa/ticket/5037 NACK I do not like your change in first regexp too much. Can you try this instead? PermPat

Re: [Freeipa-devel] [PATCH] 906 webui: fix regressions failed auth messages

2015-07-29 Thread Martin Basti
for me ACK -- Martin Basti -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Re: [Freeipa-devel] [PATCH] 0028 add --out option to user-show

2015-07-29 Thread Martin Basti
On 25/07/15 03:40, Fraser Tweedale wrote: On Fri, Jul 24, 2015 at 05:53:56PM +0200, Tomas Babej wrote: On 07/24/2015 05:34 PM, Martin Basti wrote: On 24/07/15 16:52, Tomas Babej wrote: On 07/24/2015 03:40 PM, Fraser Tweedale wrote: The attached patch adds --out option to user-show

Re: [Freeipa-devel] [PATCH 0002] TEST: Stageuser plugin

2015-07-29 Thread Martin Basti
'] = fuzzy_string Otherwise it looks good Martin^2 -- Martin Basti -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Re: [Freeipa-devel] Replace stageuser-add --from-delete with user-undel --to-staged

2015-08-05 Thread Martin Basti
, Jan Cholasta wrote: Dne 28.7.2015 v 11:36 Lenka Doudova napsal(a): Dne 28.7.2015 v 11:27 Jan Cholasta napsal(a): Dne 27.7.2015 v 17:59 Martin Basti napsal(a): On 23/07/15 14:43, Martin Basti wrote: Hello, I tried to fix #5145 and I partially succeeded. However, I cannot fix this part

Re: [Freeipa-devel] [PATCH 0286, 0290] Sysrestore: copy files instead of moving them to avoid SELinux issues

2015-07-29 Thread Martin Basti
On 29/07/15 09:02, David Kupka wrote: On 17/07/15 16:33, Martin Basti wrote: On 17/07/15 13:57, Petr Vobornik wrote: On 07/17/2015 01:46 PM, Petr Vobornik wrote: On 07/17/2015 01:44 PM, Alexander Bokovoy wrote: On Fri, 17 Jul 2015, Martin Basti wrote: From

Re: [Freeipa-devel] [PATCH 0050] ACI plugin: correctly parse bind rules enclosed in parentheses

2015-07-29 Thread Martin Basti
On 28/07/15 14:11, Martin Basti wrote: On 28/07/15 13:33, Martin Babinsky wrote: On 07/27/2015 05:10 PM, Martin Basti wrote: On 23/07/15 16:06, Martin Babinsky wrote: This is a quick fix for https://fedorahosted.org/freeipa/ticket/5037 NACK I do not like your change in first regexp too

Re: [Freeipa-devel] [PATCH 016] Require Dogtag PKI = 10.2.6

2015-07-29 Thread Martin Basti
/5129 ACK -- Martin Basti -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Re: [Freeipa-devel] [PATCH 0002] TEST: Stageuser plugin

2015-07-29 Thread Martin Basti
On 29/07/15 15:29, Lenka Doudova wrote: Hi, thanks a lot for the comments, will work on it tomorrow. Lenka Dne 29.7.2015 v 15:27 Martin Basti napsal(a): On 27/07/15 16:47, Lenka Doudova wrote: Hi, I'm attaching a patch with automated tests for stageuser plugin (https://fedorahosted.org

Re: [Freeipa-devel] [PATCH] 0028 add --out option to user-show

2015-07-29 Thread Martin Basti
On 29/07/15 15:41, Martin Basti wrote: On 25/07/15 03:40, Fraser Tweedale wrote: On Fri, Jul 24, 2015 at 05:53:56PM +0200, Tomas Babej wrote: On 07/24/2015 05:34 PM, Martin Basti wrote: On 24/07/15 16:52, Tomas Babej wrote: On 07/24/2015 03:40 PM, Fraser Tweedale wrote: The attached patch

Re: [Freeipa-devel] Replace stageuser-add --from-delete with user-undel --to-staged

2015-08-11 Thread Martin Basti
On 11/08/15 09:17, Jan Cholasta wrote: On 5.8.2015 12:34, thierry bordaz wrote: On 08/05/2015 12:13 PM, Jan Cholasta wrote: Dne 5.8.2015 v 11:55 thierry bordaz napsal(a): On 08/05/2015 11:27 AM, Martin Basti wrote: - Original Message - From: thierry bordaz tbor...@redhat.com To: Jan

Re: [Freeipa-devel] [PATCH] First part of integration tests for Topology Plugin

2015-08-11 Thread Martin Basti
NACK, comments inline. On 11/08/15 13:25, Oleg Fayans wrote: Hi Martin, Thanks for the review! On 08/10/2015 07:08 PM, Martin Basti wrote: Thank you for patch, I have a few nitpicks: 1) On 10/08/15 13:05, Oleg Fayans wrote: +def create_segment(master, leftnode, rightnode

Re: [Freeipa-devel] [PATCH] 0033 Fix default CA ACL added during upgrade

2015-08-11 Thread Martin Basti
: 8685c0d7b2463d0eef05ff351137afcc291621ec -- Martin Basti -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Re: [Freeipa-devel] [PATCH] 910 add permission: System: Manage User Certificates

2015-08-14 Thread Martin Basti
On 08/13/2015 03:46 PM, Fraser Tweedale wrote: On Thu, Aug 13, 2015 at 12:30:10PM +0300, Alexander Bokovoy wrote: On Thu, 13 Aug 2015, Fraser Tweedale wrote: On Thu, Aug 13, 2015 at 11:04:42AM +0200, Petr Vobornik wrote: On 08/13/2015 05:28 AM, Fraser Tweedale wrote: On Wed, Aug 12, 2015

Re: [Freeipa-devel] [PATCH] Added try/except for error handling ipautil

2015-08-14 Thread Martin Basti
On 08/14/2015 06:57 AM, Abhijeet Kasurde wrote: On 08/13/2015 07:08 PM, Martin Basti wrote: On 08/10/2015 01:47 PM, Abhijeet Kasurde wrote: Hi All, This patch fixes bug - https://fedorahosted.org/freeipa/ticket/3406 Thanks, Abhijeet Kasurde Hello, thank you for the patch 1

<    2   3   4   5   6   7   8   9   10   11   >