URL: https://github.com/freeipa/freeipa/pull/425
Author: flo-renaud
Title: #425: ipa-kra-install must create directory if it does not exist
Action: opened
PR body:
"""
ipa-kra-install creates an admin cert file in
/root/.dogtag/pki-tomcat/ca_admin.cert but does not check
URL: https://github.com/freeipa/freeipa/pull/395
Author: flo-renaud
Title: #395: Configure PKI ajp redirection to use "localhost" instead of "::1"
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetc
URL: https://github.com/freeipa/freeipa/pull/395
Title: #395: Configure PKI ajp redirection to use "localhost" instead of "::1"
flo-renaud commented:
"""
Hi,
PR updated with dependency on pki 10.3.5-11 (note that this package is
currently available in fed
URL: https://github.com/freeipa/freeipa/pull/395
Author: flo-renaud
Title: #395: Configure PKI ajp redirection to use "localhost" instead of "::1"
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetc
URL: https://github.com/freeipa/freeipa/pull/395
Title: #395: Configure PKI ajp redirection to use "localhost" instead of "::1"
flo-renaud commented:
"""
This PR has been modified to be consistent with PKI fix for
[2570](https://fedorahosted.org/pki/ticke
URL: https://github.com/freeipa/freeipa/pull/412
Author: flo-renaud
Title: #412: Define template version in certmap.conf
Action: opened
PR body:
"""
A previous commit (ffb9a09a0d63f7edae2b647b5c1d503d1d4d7a6e) removed the
definition of VERSION 2 in certmap.conf.template.
ipa
URL: https://github.com/freeipa/freeipa/pull/398
Author: flo-renaud
Title: #398: Support for Certificate Identity Mapping
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/398/head:pr398
git checkout pr398
URL: https://github.com/freeipa/freeipa/pull/398
Author: flo-renaud
Title: #398: Support for Certificate Identity Mapping
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/398/head:pr398
git checkout pr398
URL: https://github.com/freeipa/freeipa/pull/398
Author: flo-renaud
Title: #398: Support for Certificate Identity Mapping
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/398/head:pr398
git checkout pr398
URL: https://github.com/freeipa/freeipa/pull/398
Author: flo-renaud
Title: #398: Support for Certificate Identity Mapping
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/398/head:pr398
git checkout pr398
URL: https://github.com/freeipa/freeipa/pull/478
Author: flo-renaud
Title: #478: [4.4] Do not configure PKI ajp redirection to use "::1"
Action: opened
PR body:
"""
When ipa-server-install configures PKI, it provides a configuration file
with the paramete
URL: https://github.com/freeipa/freeipa/pull/412
Author: flo-renaud
Title: #412: Define template version in certmap.conf
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/412/head:pr412
git checkout pr412
URL: https://github.com/freeipa/freeipa/pull/412
Title: #412: Define template version in certmap.conf
flo-renaud commented:
"""
Hi @MartinBasti ,
patch rebased
"""
See the full comment at
https://github.com/freeipa/freeipa/pull/412#issuecomment-28246959
URL: https://github.com/freeipa/freeipa/pull/508
Author: flo-renaud
Title: #508: Fix ipa.service unit re. gssproxy
Action: opened
PR body:
"""
ipa.service unit defines Requires=gssproxy. Because of this, during
ipa-server-upgrade, the restart of gssproxy triggers a restart of
URL: https://github.com/freeipa/freeipa/pull/398
Title: #398: Support for Certificate Identity Mapping
flo-renaud commented:
"""
Hi @sumit-bose ,
I am not able to reproduce this issue:
`[root@vm-161 ~]# kinit -k
[root@vm-161 ~]# klist
Ticket cache: KEYRING:persistent:0:krb
URL: https://github.com/freeipa/freeipa/pull/496
Title: #496: Use newer Certificate.serial_number in krainstance.py
Label: +ack
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/496
Title: #496: Use newer Certificate.serial_number in krainstance.py
flo-renaud commented:
"""
Hi @stlaz ,
the warning
`/usr/lib/python2.7/site-packages/ipaserver/install/krainstance.py:316:
DeprecationWarning: Certificate seria
URL: https://github.com/freeipa/freeipa/pull/412
Title: #412: Define template version in certmap.conf
flo-renaud commented:
"""
Bump for review
"""
See the full comment at
https://github.com/freeipa/freeipa/pull/412#issuecomment-281931336
--
Manage your subs
URL: https://github.com/freeipa/freeipa/pull/398
Title: #398: Support for Certificate Identity Mapping
flo-renaud commented:
"""
Hi @HonzaCholasta
PR updated with `ipa user-add-certmapdata` using positional arg for CERTMAPDATA
"""
See the full comment at
http
URL: https://github.com/freeipa/freeipa/pull/398
Author: flo-renaud
Title: #398: Support for Certificate Identity Mapping
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/398/head:pr398
git checkout pr398
URL: https://github.com/freeipa/freeipa/pull/398
Title: #398: Support for Certificate Identity Mapping
flo-renaud commented:
"""
Hi @HonzaCholasta,
PR updated with most of your comments, except the suggestion to use
default_from. Please see my answer inline for this one.
&q
URL: https://github.com/freeipa/freeipa/pull/398
Author: flo-renaud
Title: #398: Support for Certificate Identity Mapping
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/398/head:pr398
git checkout pr398
URL: https://github.com/freeipa/freeipa/pull/398
Author: flo-renaud
Title: #398: Support for Certificate Identity Mapping
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/398/head:pr398
git checkout pr398
URL: https://github.com/freeipa/freeipa/pull/398
Author: flo-renaud
Title: #398: Support for Certificate Identity Mapping
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/398/head:pr398
git checkout pr398
URL: https://github.com/freeipa/freeipa/pull/398
Author: flo-renaud
Title: #398: Support for Certificate Identity Mapping
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/398/head:pr398
git checkout pr398
URL: https://github.com/freeipa/freeipa/pull/398
Author: flo-renaud
Title: #398: Support for Certificate Identity Mapping
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/398/head:pr398
git checkout pr398
URL: https://github.com/freeipa/freeipa/pull/398
Title: #398: Support for Certificate Identity Mapping
flo-renaud commented:
"""
PR updated with the check on domain in certmaprule-add/mod.
"""
See the full comment at
https://github.com/freeipa/freeipa/p
URL: https://github.com/freeipa/freeipa/pull/398
Author: flo-renaud
Title: #398: Support for Certificate Identity Mapping
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/398/head:pr398
git checkout pr398
URL: https://github.com/freeipa/freeipa/pull/398
Title: #398: Support for Certificate Identity Mapping
flo-renaud commented:
"""
@HonzaCholasta
PR updated according to your comments. Thanks for the detailed review!
"""
See the full comment at
https://githu
URL: https://github.com/freeipa/freeipa/pull/398
Author: flo-renaud
Title: #398: Support for Certificate Identity Mapping
Action: opened
PR body:
"""
See design http://www.freeipa.org/page/V4/Certificate_Identity_Mapping
https://fedorahosted.org/freeipa/ticket/6542
""
URL: https://github.com/freeipa/freeipa/pull/398
Author: flo-renaud
Title: #398: Support for Certificate Identity Mapping
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/398/head:pr398
git checkout pr398
URL: https://github.com/freeipa/freeipa/pull/395
Title: #395: Configure PKI ajp redirection to use "localhost" instead of "::1"
flo-renaud commented:
"""
Please wait before merging this PR.
@pvoborni Endi suggests 2 possible strategies for the upgrade fix
URL: https://github.com/freeipa/freeipa/pull/398
Author: flo-renaud
Title: #398: Support for Certificate Identity Mapping
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/398/head:pr398
git checkout pr398
URL: https://github.com/freeipa/freeipa/pull/405
Author: flo-renaud
Title: #405: ipa-restore must stop tracking PKINIT cert in the preparation
phase
Action: opened
PR body:
"""
ipa-restore calls certmonger to stop tracking the PKI certs, HTTP and DS certs.
It must als
URL: https://github.com/freeipa/freeipa/pull/400
Title: #400: WebUI: Certificate Mapping
flo-renaud commented:
"""
Hi @pvomacka
Thank you for the updated PR.
I probably wongly advised you to replace 'usercertificate' with 'certificate'
in one extra place where it was not need
URL: https://github.com/freeipa/freeipa/pull/516
Author: flo-renaud
Title: #516: IdM Server: list all Employees with matching Smart Card
Action: opened
PR body:
"""
Implement a new IPA command allowing to retrieve the list of users matching the
provided certificate.
The comman
URL: https://github.com/freeipa/freeipa/pull/516
Title: #516: IdM Server: list all Employees with matching Smart Card
flo-renaud commented:
"""
Note: this PR is work in progress. It requires PR#398 Support for Certificate
Identity Mapping and sssd patches not pushed yet.
&q
URL: https://github.com/freeipa/freeipa/pull/516
Author: flo-renaud
Title: #516: IdM Server: list all Employees with matching Smart Card
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/516/head:pr516
git
URL: https://github.com/freeipa/freeipa/pull/516
Title: #516: IdM Server: list all Employees with matching Smart Card
flo-renaud commented:
"""
@abbra ,
Thanks for your comment. Running in permissive mode I did not see any AVC
logged in the journal.
@HonzaCholasta
thanks
URL: https://github.com/freeipa/freeipa/pull/508
Title: #508: Fix ipa.service unit re. gssproxy
flo-renaud commented:
"""
@simo5 @abbra I agree but this should be tracked in a separate issue.
"""
See the full comment at
https://github.com/freeipa/freeipa/p
URL: https://github.com/freeipa/freeipa/pull/516
Title: #516: IdM Server: list all Employees with matching Smart Card
flo-renaud commented:
"""
Hi @simo5
The command must also be able to return matching entries coming from trusted
domains, and SSSD is able to handle this part f
flo-renaud's pull request #50: "Add cert checks in ipa-server-certinstall" was
synchronize
See the full pull-request at https://github.com/freeipa/freeipa/pull/50
... or pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/50/head:pr50
flo-renaud's pull request #50: "Add cert checks in ipa-server-certinstall" was
synchronize
See the full pull-request at https://github.com/freeipa/freeipa/pull/50
... or pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/50/head:pr50
flo-renaud's pull request #50: "Add cert checks in ipa-server-certinstall" was
opened
PR body:
"""
When ipa-server-certinstall is called to install a new server certificate,
the prerequisite is that the certificate issuer must be already known by IPA.
This fix adds new checks to make sure that
flo-renaud's pull request #69: "Fix ipa-replica-install with RHEL 6.8 master"
was opened
PR body:
"""
ipa-replica-prepare creates a gpg file containing realm_info/cacert.p12 with
the certificates.
When run on a RHEL 6.8 instance, cacert.p12 contains twice the same cert
(for caSigningCert
flo-renaud's pull request #71: "Fix regression introduced in ipa-certupdate"
was opened
PR body:
"""
The fix for 6288 was overwritten by commit
08b768313020c45bfa82d67cd214afabf605f4b3.
https://fedorahosted.org/freeipa/ticket/6288
"""
See the full pull-request at
flo-renaud commented on a pull request
"""
Bump for review
"""
See the full comment at
https://github.com/freeipa/freeipa/pull/50#issuecomment-246921696
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freei
flo-renaud's pull request #50: "Add cert checks in ipa-server-certinstall" was
synchronize
See the full pull-request at https://github.com/freeipa/freeipa/pull/50
... or pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/50/head:pr50
URL: https://github.com/freeipa/freeipa/pull/138
Title: #138: Fix ipa-cacert-manage man page
flo-renaud commented:
"""
Hi,
thanks for your comment. Yes, the IDM guide is currently being updated to
describe this requirement. See
[lastSuccessfulBuild](http://jenkinscat.gsslab
URL: https://github.com/freeipa/freeipa/pull/138
Title: #138: Fix ipa-cacert-manage man page
flo-renaud commented:
"""
Hi,
thanks for your comment. Yes, the IDM guide is currently being updated to
describe this requirement. See
[lastSuccessfulBuild](http://jenkinscat.gsslab
URL: https://github.com/freeipa/freeipa/pull/138
Author: flo-renaud
Title: #138: Fix ipa-cacert-manage man page
Action: opened
PR body:
"""
When the admin runs ipa-cacert-manage install, he should also run
ipa-certupdate on master/replicas/clients in order to update the
certifi
URL: https://github.com/freeipa/freeipa/pull/126
Author: flo-renaud
Title: #126: Fix ipa migrate-ds when it finds a search reference
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/126/head:pr126
git
URL: https://github.com/freeipa/freeipa/pull/76
Title: #76: Keep NSS trust flags of existing certificates
flo-renaud commented:
"""
(re-sending as setting the review state did not send any email)
Hi Tomas,
thanks for your patch. Works as expected.
"""
URL: https://github.com/freeipa/freeipa/pull/76
Title: #76: Keep NSS trust flags of existing certificates
Label: +ack
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/94
Title: #94: [ipa-4-2] Keep NSS trust flags of existing certificates
Label: +ack
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/69
Title: #69: Fix ipa-replica-install with RHEL 6.8 master
flo-renaud commented:
"""
Please ignore this PR as the issue has been fixed in IPA 3.0 (in
ipa-replica-prepare).
"""
See the full comment at
https://gith
flo-renaud's pull request #50: "Add cert checks in ipa-server-certinstall" was
synchronize
See the full pull-request at https://github.com/freeipa/freeipa/pull/50
... or pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/50/head:pr50
URL: https://github.com/freeipa/freeipa/pull/121
Title: #121: Pylint: enable unused-variable check
flo-renaud commented:
"""
Agree with you, ACK.
"""
See the full comment at
https://github.com/freeipa/freeipa/pull/121#issuecomment-249822167
--
Manage your subs
URL: https://github.com/freeipa/freeipa/pull/126
Author: flo-renaud
Title: #126: Fix ipa migrate-ds when it finds a search reference
Action: opened
PR body:
"""
When ipa migrate-ds finds user entries and a search reference, it complains
that the LDAP search did not return any
URL: https://github.com/freeipa/freeipa/pull/216
Title: #216: libexec scripts: ldap conn management
Label: +ack
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/216
Title: #216: libexec scripts: ldap conn management
flo-renaud commented:
"""
Thanks for the update. Works for me.
"""
See the full comment at
https://github.com/freeipa/freeipa/pull/216#issuecomment-25940630
URL: https://github.com/freeipa/freeipa/pull/222
Author: flo-renaud
Title: #222: Fix ipa-replica-install when upgrade from ca-less to ca-full
Action: opened
PR body:
"""
When ipa-replica-prepare is run on a master upgraded from CA-less to
CA-full, it creates the replica f
URL: https://github.com/freeipa/freeipa/pull/219
Author: flo-renaud
Title: #219: Refactor installer code requesting certificates
Action: opened
PR body:
"""
With this PR, the certificates requested during server installation are now
consistently obtained through certmonger (
URL: https://github.com/freeipa/freeipa/pull/219
Author: flo-renaud
Title: #219: Refactor installer code requesting certificates
Action: edited
Changed field: body
Original value:
"""
With this PR, the certificates requested during server installation are now
consistently o
URL: https://github.com/freeipa/freeipa/pull/219
Title: #219: Refactor installer code requesting certificates
flo-renaud commented:
"""
I updated the patch for renewal lock with a new fix. The timeout needs to be
increased, but the lock may also happen because the renewal
URL: https://github.com/freeipa/freeipa/pull/229
Author: flo-renaud
Title: #229: Remove the renewal lock file upon uninstall
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/229/head:pr229
git checkout
URL: https://github.com/freeipa/freeipa/pull/229
Title: #229: Remove the renewal lock file upon uninstall
flo-renaud commented:
"""
You are right, I updated the PR to put the code at the end of server
uninstallation.
"""
See the full comment at
https://githu
URL: https://github.com/freeipa/freeipa/pull/219
Title: #219: Refactor installer code requesting certificates
flo-renaud commented:
"""
Thanks Fraser!
The patch for renewal lock file deletion is available at
https://github.com/freeipa/freeipa/pull/229
"""
URL: https://github.com/freeipa/freeipa/pull/229
Author: flo-renaud
Title: #229: Remove the renewal lock file upon uninstall
Action: opened
PR body:
"""
Make sure that the file /var/run/ipa/renewal.lock is deleted upon
uninstallation, in order to avoid subsequent installatio
URL: https://github.com/freeipa/freeipa/pull/219
Title: #219: Refactor installer code requesting certificates
flo-renaud commented:
"""
Hi Fraser,
can you check if the renewal lock was released after the last uninstallation?
The file /var/run/ipa/renewal.lock should display
URL: https://github.com/freeipa/freeipa/pull/126
Author: flo-renaud
Title: #126: Fix ipa migrate-ds when it finds a search reference
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/126/head:pr126
git
URL: https://github.com/freeipa/freeipa/pull/239
Title: #239: cainstance: use correct certificate for replica install check
flo-renaud commented:
"""
Hi,
works for me.
"""
See the full comment at
https://github.com/freeipa/freeipa/pull/239#issuecomment-26039354
URL: https://github.com/freeipa/freeipa/pull/239
Title: #239: cainstance: use correct certificate for replica install check
Label: +ack
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/269
Title: #269: Prevent denial of replication updates during CA replica install
flo-renaud commented:
"""
Hi,
thanks for the patch! Everything works as expected.
"""
See the full comment at
https://github.com/freeipa
URL: https://github.com/freeipa/freeipa/pull/270
Title: #270: Test: uniqueness of certificate renewal master
flo-renaud commented:
"""
Hi,
you may also want to perform the same test after changing the renewal master
with _ipa config-mod --ca-renewal-master-server newrenewalmast
URL: https://github.com/freeipa/freeipa/pull/229
Author: flo-renaud
Title: #229: Remove the renewal lock file upon uninstall
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/229/head:pr229
git checkout
URL: https://github.com/freeipa/freeipa/pull/285
Author: flo-renaud
Title: #285: Check the result of cert request in replica installer
Action: opened
PR body:
"""
When running ipa-replica-install in domain-level 1, the installer
requests the LDAP and HTTP certificates u
URL: https://github.com/freeipa/freeipa/pull/318
Title: #318: server install: fix external CA install
Label: +ack
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/318
Title: #318: server install: fix external CA install
flo-renaud commented:
"""
Works as expected.
"""
See the full comment at
https://github.com/freeipa/freeipa/pull/318#issuecomment-265688266
--
Manage your subs
URL: https://github.com/freeipa/freeipa/pull/315
Title: #315: [ipa-4-4] gracefully handle setting replica bind dn group on old
masters
Label: +ack
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/322
Title: #322: masters DS<1.3.3 do not support bind group
flo-renaud commented:
"""
Hi,
there is already an open PR for this issue:
https://github.com/freeipa/freeipa/pull/319 for master and
https://github.com/freeipa/freeipa/pu
URL: https://github.com/freeipa/freeipa/pull/315
Title: #315: [ipa-4-4] gracefully handle setting replica bind dn group on old
masters
flo-renaud commented:
"""
Hi,
thanks for the patch. Everything works as expected.
"""
See the full comment at
https://githu
URL: https://github.com/freeipa/freeipa/pull/319
Title: #319: [master] gracefully handle setting replica bind dn group on old
masters
Label: +ack
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/319
Title: #319: [master] gracefully handle setting replica bind dn group on old
masters
flo-renaud commented:
"""
Hi,
thanks for the patch. It works as expected.
"""
See the full comment at
https://github.com/freeipa
URL: https://github.com/freeipa/freeipa/pull/395
Title: #395: Configure PKI ajp redirection to use "localhost" instead of "::1"
flo-renaud commented:
"""
Hi @tomaskrizek,
I was not able to reproduce the master install issue. Here are my steps:
On the master:
URL: https://github.com/freeipa/freeipa/pull/395
Author: flo-renaud
Title: #395: Configure PKI ajp redirection to use "localhost" instead of "::1"
Action: opened
PR body:
"""
When ipa-server-install configures PKI, it provides a configuration file
with th
URL: https://github.com/freeipa/freeipa/pull/285
Title: #285: Check the result of cert request in replica installer
flo-renaud commented:
"""
Thanks for the suggestion. I added certmonger's request status in the exception
message.
"""
See the full comment
URL: https://github.com/freeipa/freeipa/pull/285
Author: flo-renaud
Title: #285: Check the result of cert request in replica installer
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/285/head:pr285
git
URL: https://github.com/freeipa/freeipa/pull/292
Author: flo-renaud
Title: #292: Increase the timeout waiting for certificate issuance in installer
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/292
URL: https://github.com/freeipa/freeipa/pull/292
Title: #292: Increase the timeout waiting for certificate issuance in installer
flo-renaud commented:
"""
@martbab @mbasti-rh: I checked the code and some parts already use
api.env.startup_timeout for certmonger requests (in ip
URL: https://github.com/freeipa/freeipa/pull/283
Title: #283: [ipa-4-4] Prevent denial of replication updates during CA replica
install
Label: +ack
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/283
Title: #283: [ipa-4-4] Prevent denial of replication updates during CA replica
install
flo-renaud commented:
"""
Hi,
the patch works as expected. Thanks!
"""
See the full comment at
https://github.com/freeipa
URL: https://github.com/freeipa/freeipa/pull/292
Author: flo-renaud
Title: #292: Increase the timeout waiting for certificate issuance in installer
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/292
URL: https://github.com/freeipa/freeipa/pull/355
Title: #355: Set up DS TLS on replica in CA-less topology
flo-renaud commented:
"""
@tomaskrizek FYI, the current documentation states that ipa-certupdate must be
run after ipa-ca-install (see
https://access.redhat.com/docu
URL: https://github.com/freeipa/freeipa/pull/632
Author: flo-renaud
Title: #632: ipa-sam: create the gidNumber attribute in the trusted domain
entry
Action: opened
PR body:
"""
When a trusted domain entry is created, the uidNumber attribute is created
but not the gidN
URL: https://github.com/freeipa/freeipa/pull/652
Author: flo-renaud
Title: #652: dogtag-ipa-ca-renew-agent-submit: fix the is_replicated() function
Action: opened
PR body:
"""
dogtag-ipa-ca-renew-agent-submit behaves differently depending on the
certificate it needs to rene
URL: https://github.com/freeipa/freeipa/pull/661
Author: flo-renaud
Title: #661: git-commit-template: update ticket url to use pagure.io instead
of fe…
Action: opened
PR body:
"""
…dorahosted.org
After the migration to pagure.io, tickets are accessed through another URL.
URL: https://github.com/freeipa/freeipa/pull/659
Title: #659: WebUI: Allow to add certs to certmapping with CERT LINES around
flo-renaud commented:
"""
Hi @pvomacka ,
thank you for the patch, it works as expected.
"""
See the full comment at
https://githu
URL: https://github.com/freeipa/freeipa/pull/667
Author: flo-renaud
Title: #667: idrange-mod: properly handle empty --dom-name option
Action: opened
PR body:
"""
When idrange-mod is called with --dom-name=, the CLI exits with
ipa: ERROR: an internal error has occurred
This
URL: https://github.com/freeipa/freeipa/pull/678
Author: flo-renaud
Title: #678: ipa-ca-install man page: Add domain level 1 help
Action: opened
PR body:
"""
In domain level 1 ipa-ca-install does not require a replica-file. Update the
man page to distinguish the domain lev
1 - 100 of 153 matches
Mail list logo