[Freeipa-devel] [freeipa PR#425][opened] ipa-kra-install must create directory if it does not exist

2017-01-31 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/425 Author: flo-renaud Title: #425: ipa-kra-install must create directory if it does not exist Action: opened PR body: """ ipa-kra-install creates an admin cert file in /root/.dogtag/pki-tomcat/ca_admin.cert but does not check

[Freeipa-devel] [freeipa PR#395][synchronized] Configure PKI ajp redirection to use "localhost" instead of "::1"

2017-02-06 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/395 Author: flo-renaud Title: #395: Configure PKI ajp redirection to use "localhost" instead of "::1" Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetc

[Freeipa-devel] [freeipa PR#395][comment] Configure PKI ajp redirection to use "localhost" instead of "::1"

2017-02-06 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/395 Title: #395: Configure PKI ajp redirection to use "localhost" instead of "::1" flo-renaud commented: """ Hi, PR updated with dependency on pki 10.3.5-11 (note that this package is currently available in fed

[Freeipa-devel] [freeipa PR#395][synchronized] Configure PKI ajp redirection to use "localhost" instead of "::1"

2017-01-23 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/395 Author: flo-renaud Title: #395: Configure PKI ajp redirection to use "localhost" instead of "::1" Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetc

[Freeipa-devel] [freeipa PR#395][comment] Configure PKI ajp redirection to use "localhost" instead of "::1"

2017-01-23 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/395 Title: #395: Configure PKI ajp redirection to use "localhost" instead of "::1" flo-renaud commented: """ This PR has been modified to be consistent with PKI fix for [2570](https://fedorahosted.org/pki/ticke

[Freeipa-devel] [freeipa PR#412][opened] Define template version in certmap.conf

2017-01-24 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/412 Author: flo-renaud Title: #412: Define template version in certmap.conf Action: opened PR body: """ A previous commit (ffb9a09a0d63f7edae2b647b5c1d503d1d4d7a6e) removed the definition of VERSION 2 in certmap.conf.template. ipa

[Freeipa-devel] [freeipa PR#398][synchronized] Support for Certificate Identity Mapping

2017-02-21 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/398 Author: flo-renaud Title: #398: Support for Certificate Identity Mapping Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/398/head:pr398 git checkout pr398

[Freeipa-devel] [freeipa PR#398][synchronized] Support for Certificate Identity Mapping

2017-02-21 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/398 Author: flo-renaud Title: #398: Support for Certificate Identity Mapping Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/398/head:pr398 git checkout pr398

[Freeipa-devel] [freeipa PR#398][synchronized] Support for Certificate Identity Mapping

2017-02-21 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/398 Author: flo-renaud Title: #398: Support for Certificate Identity Mapping Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/398/head:pr398 git checkout pr398

[Freeipa-devel] [freeipa PR#398][synchronized] Support for Certificate Identity Mapping

2017-02-20 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/398 Author: flo-renaud Title: #398: Support for Certificate Identity Mapping Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/398/head:pr398 git checkout pr398

[Freeipa-devel] [freeipa PR#478][opened] [4.4] Do not configure PKI ajp redirection to use "::1"

2017-02-17 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/478 Author: flo-renaud Title: #478: [4.4] Do not configure PKI ajp redirection to use "::1" Action: opened PR body: """ When ipa-server-install configures PKI, it provides a configuration file with the paramete

[Freeipa-devel] [freeipa PR#412][synchronized] Define template version in certmap.conf

2017-02-25 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/412 Author: flo-renaud Title: #412: Define template version in certmap.conf Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/412/head:pr412 git checkout pr412

[Freeipa-devel] [freeipa PR#412][comment] Define template version in certmap.conf

2017-02-25 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/412 Title: #412: Define template version in certmap.conf flo-renaud commented: """ Hi @MartinBasti , patch rebased """ See the full comment at https://github.com/freeipa/freeipa/pull/412#issuecomment-28246959

[Freeipa-devel] [freeipa PR#508][opened] Fix ipa.service unit re. gssproxy

2017-02-24 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/508 Author: flo-renaud Title: #508: Fix ipa.service unit re. gssproxy Action: opened PR body: """ ipa.service unit defines Requires=gssproxy. Because of this, during ipa-server-upgrade, the restart of gssproxy triggers a restart of

[Freeipa-devel] [freeipa PR#398][comment] Support for Certificate Identity Mapping

2017-02-22 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/398 Title: #398: Support for Certificate Identity Mapping flo-renaud commented: """ Hi @sumit-bose , I am not able to reproduce this issue: `[root@vm-161 ~]# kinit -k [root@vm-161 ~]# klist Ticket cache: KEYRING:persistent:0:krb

[Freeipa-devel] [freeipa PR#496][+ack] Use newer Certificate.serial_number in krainstance.py

2017-02-23 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/496 Title: #496: Use newer Certificate.serial_number in krainstance.py Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#496][comment] Use newer Certificate.serial_number in krainstance.py

2017-02-23 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/496 Title: #496: Use newer Certificate.serial_number in krainstance.py flo-renaud commented: """ Hi @stlaz , the warning `/usr/lib/python2.7/site-packages/ipaserver/install/krainstance.py:316: DeprecationWarning: Certificate seria

[Freeipa-devel] [freeipa PR#412][comment] Define template version in certmap.conf

2017-02-23 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/412 Title: #412: Define template version in certmap.conf flo-renaud commented: """ Bump for review """ See the full comment at https://github.com/freeipa/freeipa/pull/412#issuecomment-281931336 -- Manage your subs

[Freeipa-devel] [freeipa PR#398][comment] Support for Certificate Identity Mapping

2017-02-14 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/398 Title: #398: Support for Certificate Identity Mapping flo-renaud commented: """ Hi @HonzaCholasta PR updated with `ipa user-add-certmapdata` using positional arg for CERTMAPDATA """ See the full comment at http

[Freeipa-devel] [freeipa PR#398][synchronized] Support for Certificate Identity Mapping

2017-02-14 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/398 Author: flo-renaud Title: #398: Support for Certificate Identity Mapping Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/398/head:pr398 git checkout pr398

[Freeipa-devel] [freeipa PR#398][comment] Support for Certificate Identity Mapping

2017-02-14 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/398 Title: #398: Support for Certificate Identity Mapping flo-renaud commented: """ Hi @HonzaCholasta, PR updated with most of your comments, except the suggestion to use default_from. Please see my answer inline for this one. &q

[Freeipa-devel] [freeipa PR#398][synchronized] Support for Certificate Identity Mapping

2017-02-14 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/398 Author: flo-renaud Title: #398: Support for Certificate Identity Mapping Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/398/head:pr398 git checkout pr398

[Freeipa-devel] [freeipa PR#398][synchronized] Support for Certificate Identity Mapping

2017-02-13 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/398 Author: flo-renaud Title: #398: Support for Certificate Identity Mapping Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/398/head:pr398 git checkout pr398

[Freeipa-devel] [freeipa PR#398][synchronized] Support for Certificate Identity Mapping

2017-02-13 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/398 Author: flo-renaud Title: #398: Support for Certificate Identity Mapping Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/398/head:pr398 git checkout pr398

[Freeipa-devel] [freeipa PR#398][synchronized] Support for Certificate Identity Mapping

2017-02-13 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/398 Author: flo-renaud Title: #398: Support for Certificate Identity Mapping Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/398/head:pr398 git checkout pr398

[Freeipa-devel] [freeipa PR#398][synchronized] Support for Certificate Identity Mapping

2017-02-15 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/398 Author: flo-renaud Title: #398: Support for Certificate Identity Mapping Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/398/head:pr398 git checkout pr398

[Freeipa-devel] [freeipa PR#398][comment] Support for Certificate Identity Mapping

2017-02-15 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/398 Title: #398: Support for Certificate Identity Mapping flo-renaud commented: """ PR updated with the check on domain in certmaprule-add/mod. """ See the full comment at https://github.com/freeipa/freeipa/p

[Freeipa-devel] [freeipa PR#398][synchronized] Support for Certificate Identity Mapping

2017-02-15 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/398 Author: flo-renaud Title: #398: Support for Certificate Identity Mapping Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/398/head:pr398 git checkout pr398

[Freeipa-devel] [freeipa PR#398][comment] Support for Certificate Identity Mapping

2017-02-15 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/398 Title: #398: Support for Certificate Identity Mapping flo-renaud commented: """ @HonzaCholasta PR updated according to your comments. Thanks for the detailed review! """ See the full comment at https://githu

[Freeipa-devel] [freeipa PR#398][opened] Support for Certificate Identity Mapping

2017-01-18 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/398 Author: flo-renaud Title: #398: Support for Certificate Identity Mapping Action: opened PR body: """ See design http://www.freeipa.org/page/V4/Certificate_Identity_Mapping https://fedorahosted.org/freeipa/ticket/6542 ""

[Freeipa-devel] [freeipa PR#398][synchronized] Support for Certificate Identity Mapping

2017-01-19 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/398 Author: flo-renaud Title: #398: Support for Certificate Identity Mapping Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/398/head:pr398 git checkout pr398

[Freeipa-devel] [freeipa PR#395][comment] Configure PKI ajp redirection to use "localhost" instead of "::1"

2017-01-16 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/395 Title: #395: Configure PKI ajp redirection to use "localhost" instead of "::1" flo-renaud commented: """ Please wait before merging this PR. @pvoborni Endi suggests 2 possible strategies for the upgrade fix

[Freeipa-devel] [freeipa PR#398][synchronized] Support for Certificate Identity Mapping

2017-01-18 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/398 Author: flo-renaud Title: #398: Support for Certificate Identity Mapping Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/398/head:pr398 git checkout pr398

[Freeipa-devel] [freeipa PR#405][opened] ipa-restore must stop tracking PKINIT cert in the preparation phase

2017-01-19 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/405 Author: flo-renaud Title: #405: ipa-restore must stop tracking PKINIT cert in the preparation phase Action: opened PR body: """ ipa-restore calls certmonger to stop tracking the PKI certs, HTTP and DS certs. It must als

[Freeipa-devel] [freeipa PR#400][comment] WebUI: Certificate Mapping

2017-02-28 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/400 Title: #400: WebUI: Certificate Mapping flo-renaud commented: """ Hi @pvomacka Thank you for the updated PR. I probably wongly advised you to replace 'usercertificate' with 'certificate' in one extra place where it was not need

[Freeipa-devel] [freeipa PR#516][opened] IdM Server: list all Employees with matching Smart Card

2017-02-28 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/516 Author: flo-renaud Title: #516: IdM Server: list all Employees with matching Smart Card Action: opened PR body: """ Implement a new IPA command allowing to retrieve the list of users matching the provided certificate. The comman

[Freeipa-devel] [freeipa PR#516][comment] IdM Server: list all Employees with matching Smart Card

2017-02-28 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/516 Title: #516: IdM Server: list all Employees with matching Smart Card flo-renaud commented: """ Note: this PR is work in progress. It requires PR#398 Support for Certificate Identity Mapping and sssd patches not pushed yet. &q

[Freeipa-devel] [freeipa PR#516][synchronized] IdM Server: list all Employees with matching Smart Card

2017-03-02 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/516 Author: flo-renaud Title: #516: IdM Server: list all Employees with matching Smart Card Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/516/head:pr516 git

[Freeipa-devel] [freeipa PR#516][comment] IdM Server: list all Employees with matching Smart Card

2017-03-02 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/516 Title: #516: IdM Server: list all Employees with matching Smart Card flo-renaud commented: """ @abbra , Thanks for your comment. Running in permissive mode I did not see any AVC logged in the journal. @HonzaCholasta thanks

[Freeipa-devel] [freeipa PR#508][comment] Fix ipa.service unit re. gssproxy

2017-02-27 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/508 Title: #508: Fix ipa.service unit re. gssproxy flo-renaud commented: """ @simo5 @abbra I agree but this should be tracked in a separate issue. """ See the full comment at https://github.com/freeipa/freeipa/p

[Freeipa-devel] [freeipa PR#516][comment] IdM Server: list all Employees with matching Smart Card

2017-02-28 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/516 Title: #516: IdM Server: list all Employees with matching Smart Card flo-renaud commented: """ Hi @simo5 The command must also be able to return matching entries coming from trusted domains, and SSSD is able to handle this part f

[Freeipa-devel] [freeipa PR#50] Add cert checks in ipa-server-certinstall (synchronize)

2016-09-06 Thread flo-renaud
flo-renaud's pull request #50: "Add cert checks in ipa-server-certinstall" was synchronize See the full pull-request at https://github.com/freeipa/freeipa/pull/50 ... or pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/50/head:pr50

[Freeipa-devel] [freeipa PR#50] Add cert checks in ipa-server-certinstall (synchronize)

2016-09-06 Thread flo-renaud
flo-renaud's pull request #50: "Add cert checks in ipa-server-certinstall" was synchronize See the full pull-request at https://github.com/freeipa/freeipa/pull/50 ... or pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/50/head:pr50

[Freeipa-devel] [freeipa PR#50] Add cert checks in ipa-server-certinstall (opened)

2016-09-02 Thread flo-renaud
flo-renaud's pull request #50: "Add cert checks in ipa-server-certinstall" was opened PR body: """ When ipa-server-certinstall is called to install a new server certificate, the prerequisite is that the certificate issuer must be already known by IPA. This fix adds new checks to make sure that

[Freeipa-devel] [freeipa PR#69] Fix ipa-replica-install with RHEL 6.8 master (opened)

2016-09-08 Thread flo-renaud
flo-renaud's pull request #69: "Fix ipa-replica-install with RHEL 6.8 master" was opened PR body: """ ipa-replica-prepare creates a gpg file containing realm_info/cacert.p12 with the certificates. When run on a RHEL 6.8 instance, cacert.p12 contains twice the same cert (for caSigningCert

[Freeipa-devel] [freeipa PR#71] Fix regression introduced in ipa-certupdate (opened)

2016-09-09 Thread flo-renaud
flo-renaud's pull request #71: "Fix regression introduced in ipa-certupdate" was opened PR body: """ The fix for 6288 was overwritten by commit 08b768313020c45bfa82d67cd214afabf605f4b3. https://fedorahosted.org/freeipa/ticket/6288 """ See the full pull-request at

[Freeipa-devel] [freeipa PR#50] Add cert checks in ipa-server-certinstall (comment)

2016-09-14 Thread flo-renaud
flo-renaud commented on a pull request """ Bump for review """ See the full comment at https://github.com/freeipa/freeipa/pull/50#issuecomment-246921696 -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freei

[Freeipa-devel] [freeipa PR#50] Add cert checks in ipa-server-certinstall (synchronize)

2016-09-15 Thread flo-renaud
flo-renaud's pull request #50: "Add cert checks in ipa-server-certinstall" was synchronize See the full pull-request at https://github.com/freeipa/freeipa/pull/50 ... or pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/50/head:pr50

[Freeipa-devel] [freeipa PR#138][comment] Fix ipa-cacert-manage man page

2016-10-06 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/138 Title: #138: Fix ipa-cacert-manage man page flo-renaud commented: """ Hi, thanks for your comment. Yes, the IDM guide is currently being updated to describe this requirement. See [lastSuccessfulBuild](http://jenkinscat.gsslab

[Freeipa-devel] [freeipa PR#138][comment] Fix ipa-cacert-manage man page

2016-10-06 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/138 Title: #138: Fix ipa-cacert-manage man page flo-renaud commented: """ Hi, thanks for your comment. Yes, the IDM guide is currently being updated to describe this requirement. See [lastSuccessfulBuild](http://jenkinscat.gsslab

[Freeipa-devel] [freeipa PR#138][opened] Fix ipa-cacert-manage man page

2016-10-05 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/138 Author: flo-renaud Title: #138: Fix ipa-cacert-manage man page Action: opened PR body: """ When the admin runs ipa-cacert-manage install, he should also run ipa-certupdate on master/replicas/clients in order to update the certifi

[Freeipa-devel] [freeipa PR#126][synchronized] Fix ipa migrate-ds when it finds a search reference

2016-10-04 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/126 Author: flo-renaud Title: #126: Fix ipa migrate-ds when it finds a search reference Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/126/head:pr126 git

[Freeipa-devel] [freeipa PR#76][comment] Keep NSS trust flags of existing certificates

2016-09-19 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/76 Title: #76: Keep NSS trust flags of existing certificates flo-renaud commented: """ (re-sending as setting the review state did not send any email) Hi Tomas, thanks for your patch. Works as expected. """

[Freeipa-devel] [freeipa PR#76][+ack] Keep NSS trust flags of existing certificates

2016-09-19 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/76 Title: #76: Keep NSS trust flags of existing certificates Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#94][+ack] [ipa-4-2] Keep NSS trust flags of existing certificates

2016-09-21 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/94 Title: #94: [ipa-4-2] Keep NSS trust flags of existing certificates Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#69][comment] Fix ipa-replica-install with RHEL 6.8 master

2016-09-16 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/69 Title: #69: Fix ipa-replica-install with RHEL 6.8 master flo-renaud commented: """ Please ignore this PR as the issue has been fixed in IPA 3.0 (in ipa-replica-prepare). """ See the full comment at https://gith

[Freeipa-devel] [freeipa PR#50] Add cert checks in ipa-server-certinstall (synchronize)

2016-09-07 Thread flo-renaud
flo-renaud's pull request #50: "Add cert checks in ipa-server-certinstall" was synchronize See the full pull-request at https://github.com/freeipa/freeipa/pull/50 ... or pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/50/head:pr50

[Freeipa-devel] [freeipa PR#121][comment] Pylint: enable unused-variable check

2016-09-27 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/121 Title: #121: Pylint: enable unused-variable check flo-renaud commented: """ Agree with you, ACK. """ See the full comment at https://github.com/freeipa/freeipa/pull/121#issuecomment-249822167 -- Manage your subs

[Freeipa-devel] [freeipa PR#126][opened] Fix ipa migrate-ds when it finds a search reference

2016-09-29 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/126 Author: flo-renaud Title: #126: Fix ipa migrate-ds when it finds a search reference Action: opened PR body: """ When ipa migrate-ds finds user entries and a search reference, it complains that the LDAP search did not return any

[Freeipa-devel] [freeipa PR#216][+ack] libexec scripts: ldap conn management

2016-11-09 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/216 Title: #216: libexec scripts: ldap conn management Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#216][comment] libexec scripts: ldap conn management

2016-11-09 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/216 Title: #216: libexec scripts: ldap conn management flo-renaud commented: """ Thanks for the update. Works for me. """ See the full comment at https://github.com/freeipa/freeipa/pull/216#issuecomment-25940630

[Freeipa-devel] [freeipa PR#222][opened] Fix ipa-replica-install when upgrade from ca-less to ca-full

2016-11-09 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/222 Author: flo-renaud Title: #222: Fix ipa-replica-install when upgrade from ca-less to ca-full Action: opened PR body: """ When ipa-replica-prepare is run on a master upgraded from CA-less to CA-full, it creates the replica f

[Freeipa-devel] [freeipa PR#219][opened] Refactor installer code requesting certificates

2016-11-09 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/219 Author: flo-renaud Title: #219: Refactor installer code requesting certificates Action: opened PR body: """ With this PR, the certificates requested during server installation are now consistently obtained through certmonger (

[Freeipa-devel] [freeipa PR#219][edited] Refactor installer code requesting certificates

2016-11-09 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/219 Author: flo-renaud Title: #219: Refactor installer code requesting certificates Action: edited Changed field: body Original value: """ With this PR, the certificates requested during server installation are now consistently o

[Freeipa-devel] [freeipa PR#219][comment] Refactor installer code requesting certificates

2016-11-10 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/219 Title: #219: Refactor installer code requesting certificates flo-renaud commented: """ I updated the patch for renewal lock with a new fix. The timeout needs to be increased, but the lock may also happen because the renewal

[Freeipa-devel] [freeipa PR#229][synchronized] Remove the renewal lock file upon uninstall

2016-11-10 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/229 Author: flo-renaud Title: #229: Remove the renewal lock file upon uninstall Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/229/head:pr229 git checkout

[Freeipa-devel] [freeipa PR#229][comment] Remove the renewal lock file upon uninstall

2016-11-10 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/229 Title: #229: Remove the renewal lock file upon uninstall flo-renaud commented: """ You are right, I updated the PR to put the code at the end of server uninstallation. """ See the full comment at https://githu

[Freeipa-devel] [freeipa PR#219][comment] Refactor installer code requesting certificates

2016-11-10 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/219 Title: #219: Refactor installer code requesting certificates flo-renaud commented: """ Thanks Fraser! The patch for renewal lock file deletion is available at https://github.com/freeipa/freeipa/pull/229 """

[Freeipa-devel] [freeipa PR#229][opened] Remove the renewal lock file upon uninstall

2016-11-10 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/229 Author: flo-renaud Title: #229: Remove the renewal lock file upon uninstall Action: opened PR body: """ Make sure that the file /var/run/ipa/renewal.lock is deleted upon uninstallation, in order to avoid subsequent installatio

[Freeipa-devel] [freeipa PR#219][comment] Refactor installer code requesting certificates

2016-11-10 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/219 Title: #219: Refactor installer code requesting certificates flo-renaud commented: """ Hi Fraser, can you check if the renewal lock was released after the last uninstallation? The file /var/run/ipa/renewal.lock should display

[Freeipa-devel] [freeipa PR#126][synchronized] Fix ipa migrate-ds when it finds a search reference

2016-10-14 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/126 Author: flo-renaud Title: #126: Fix ipa migrate-ds when it finds a search reference Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/126/head:pr126 git

[Freeipa-devel] [freeipa PR#239][comment] cainstance: use correct certificate for replica install check

2016-11-14 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/239 Title: #239: cainstance: use correct certificate for replica install check flo-renaud commented: """ Hi, works for me. """ See the full comment at https://github.com/freeipa/freeipa/pull/239#issuecomment-26039354

[Freeipa-devel] [freeipa PR#239][+ack] cainstance: use correct certificate for replica install check

2016-11-14 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/239 Title: #239: cainstance: use correct certificate for replica install check Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#269][comment] Prevent denial of replication updates during CA replica install

2016-11-25 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/269 Title: #269: Prevent denial of replication updates during CA replica install flo-renaud commented: """ Hi, thanks for the patch! Everything works as expected. """ See the full comment at https://github.com/freeipa

[Freeipa-devel] [freeipa PR#270][comment] Test: uniqueness of certificate renewal master

2016-11-28 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/270 Title: #270: Test: uniqueness of certificate renewal master flo-renaud commented: """ Hi, you may also want to perform the same test after changing the renewal master with _ipa config-mod --ca-renewal-master-server newrenewalmast

[Freeipa-devel] [freeipa PR#229][synchronized] Remove the renewal lock file upon uninstall

2016-11-14 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/229 Author: flo-renaud Title: #229: Remove the renewal lock file upon uninstall Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/229/head:pr229 git checkout

[Freeipa-devel] [freeipa PR#285][opened] Check the result of cert request in replica installer

2016-11-29 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/285 Author: flo-renaud Title: #285: Check the result of cert request in replica installer Action: opened PR body: """ When running ipa-replica-install in domain-level 1, the installer requests the LDAP and HTTP certificates u

[Freeipa-devel] [freeipa PR#318][+ack] server install: fix external CA install

2016-12-08 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/318 Title: #318: server install: fix external CA install Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#318][comment] server install: fix external CA install

2016-12-08 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/318 Title: #318: server install: fix external CA install flo-renaud commented: """ Works as expected. """ See the full comment at https://github.com/freeipa/freeipa/pull/318#issuecomment-265688266 -- Manage your subs

[Freeipa-devel] [freeipa PR#315][+ack] [ipa-4-4] gracefully handle setting replica bind dn group on old masters

2016-12-09 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/315 Title: #315: [ipa-4-4] gracefully handle setting replica bind dn group on old masters Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#322][comment] masters DS<1.3.3 do not support bind group

2016-12-09 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/322 Title: #322: masters DS<1.3.3 do not support bind group flo-renaud commented: """ Hi, there is already an open PR for this issue: https://github.com/freeipa/freeipa/pull/319 for master and https://github.com/freeipa/freeipa/pu

[Freeipa-devel] [freeipa PR#315][comment] [ipa-4-4] gracefully handle setting replica bind dn group on old masters

2016-12-09 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/315 Title: #315: [ipa-4-4] gracefully handle setting replica bind dn group on old masters flo-renaud commented: """ Hi, thanks for the patch. Everything works as expected. """ See the full comment at https://githu

[Freeipa-devel] [freeipa PR#319][+ack] [master] gracefully handle setting replica bind dn group on old masters

2016-12-12 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/319 Title: #319: [master] gracefully handle setting replica bind dn group on old masters Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#319][comment] [master] gracefully handle setting replica bind dn group on old masters

2016-12-12 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/319 Title: #319: [master] gracefully handle setting replica bind dn group on old masters flo-renaud commented: """ Hi, thanks for the patch. It works as expected. """ See the full comment at https://github.com/freeipa

[Freeipa-devel] [freeipa PR#395][comment] Configure PKI ajp redirection to use "localhost" instead of "::1"

2017-01-13 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/395 Title: #395: Configure PKI ajp redirection to use "localhost" instead of "::1" flo-renaud commented: """ Hi @tomaskrizek, I was not able to reproduce the master install issue. Here are my steps: On the master:

[Freeipa-devel] [freeipa PR#395][opened] Configure PKI ajp redirection to use "localhost" instead of "::1"

2017-01-12 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/395 Author: flo-renaud Title: #395: Configure PKI ajp redirection to use "localhost" instead of "::1" Action: opened PR body: """ When ipa-server-install configures PKI, it provides a configuration file with th

[Freeipa-devel] [freeipa PR#285][comment] Check the result of cert request in replica installer

2016-11-30 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/285 Title: #285: Check the result of cert request in replica installer flo-renaud commented: """ Thanks for the suggestion. I added certmonger's request status in the exception message. """ See the full comment

[Freeipa-devel] [freeipa PR#285][synchronized] Check the result of cert request in replica installer

2016-11-30 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/285 Author: flo-renaud Title: #285: Check the result of cert request in replica installer Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/285/head:pr285 git

[Freeipa-devel] [freeipa PR#292][synchronized] Increase the timeout waiting for certificate issuance in installer

2016-12-05 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/292 Author: flo-renaud Title: #292: Increase the timeout waiting for certificate issuance in installer Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/292

[Freeipa-devel] [freeipa PR#292][comment] Increase the timeout waiting for certificate issuance in installer

2016-12-05 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/292 Title: #292: Increase the timeout waiting for certificate issuance in installer flo-renaud commented: """ @martbab @mbasti-rh: I checked the code and some parts already use api.env.startup_timeout for certmonger requests (in ip

[Freeipa-devel] [freeipa PR#283][+ack] [ipa-4-4] Prevent denial of replication updates during CA replica install

2016-11-30 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/283 Title: #283: [ipa-4-4] Prevent denial of replication updates during CA replica install Label: +ack -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA:

[Freeipa-devel] [freeipa PR#283][comment] [ipa-4-4] Prevent denial of replication updates during CA replica install

2016-11-30 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/283 Title: #283: [ipa-4-4] Prevent denial of replication updates during CA replica install flo-renaud commented: """ Hi, the patch works as expected. Thanks! """ See the full comment at https://github.com/freeipa

[Freeipa-devel] [freeipa PR#292][synchronized] Increase the timeout waiting for certificate issuance in installer

2016-12-06 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/292 Author: flo-renaud Title: #292: Increase the timeout waiting for certificate issuance in installer Action: synchronized To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/292

[Freeipa-devel] [freeipa PR#355][comment] Set up DS TLS on replica in CA-less topology

2016-12-21 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/355 Title: #355: Set up DS TLS on replica in CA-less topology flo-renaud commented: """ @tomaskrizek FYI, the current documentation states that ipa-certupdate must be run after ipa-ca-install (see https://access.redhat.com/docu

[Freeipa-devel] [freeipa PR#632][opened] ipa-sam: create the gidNumber attribute in the trusted domain entry

2017-03-21 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/632 Author: flo-renaud Title: #632: ipa-sam: create the gidNumber attribute in the trusted domain entry Action: opened PR body: """ When a trusted domain entry is created, the uidNumber attribute is created but not the gidN

[Freeipa-devel] [freeipa PR#652][opened] dogtag-ipa-ca-renew-agent-submit: fix the is_replicated() function

2017-03-24 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/652 Author: flo-renaud Title: #652: dogtag-ipa-ca-renew-agent-submit: fix the is_replicated() function Action: opened PR body: """ dogtag-ipa-ca-renew-agent-submit behaves differently depending on the certificate it needs to rene

[Freeipa-devel] [freeipa PR#661][opened] git-commit-template: update ticket url to use pagure.io instead of fe…

2017-03-28 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/661 Author: flo-renaud Title: #661: git-commit-template: update ticket url to use pagure.io instead of fe… Action: opened PR body: """ …dorahosted.org After the migration to pagure.io, tickets are accessed through another URL.

[Freeipa-devel] [freeipa PR#659][comment] WebUI: Allow to add certs to certmapping with CERT LINES around

2017-03-27 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/659 Title: #659: WebUI: Allow to add certs to certmapping with CERT LINES around flo-renaud commented: """ Hi @pvomacka , thank you for the patch, it works as expected. """ See the full comment at https://githu

[Freeipa-devel] [freeipa PR#667][opened] idrange-mod: properly handle empty --dom-name option

2017-03-28 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/667 Author: flo-renaud Title: #667: idrange-mod: properly handle empty --dom-name option Action: opened PR body: """ When idrange-mod is called with --dom-name=, the CLI exits with ipa: ERROR: an internal error has occurred This

[Freeipa-devel] [freeipa PR#678][opened] ipa-ca-install man page: Add domain level 1 help

2017-03-30 Thread flo-renaud
URL: https://github.com/freeipa/freeipa/pull/678 Author: flo-renaud Title: #678: ipa-ca-install man page: Add domain level 1 help Action: opened PR body: """ In domain level 1 ipa-ca-install does not require a replica-file. Update the man page to distinguish the domain lev

  1   2   >