Re: [Freeipa-devel] [PATCH] - Add DRM to IPA

2014-08-25 Thread Petr Viktorin
On 08/22/2014 03:28 PM, Petr Vobornik wrote: [...] Should the requirement of Dogtag 10.2 be reflected in a spec file? Yes. Sorry for forgetting that point in he review. We can do two things here: 1) Require Dogtag 10.2 (and ask developers to add the vakwetu-dogtag repo for ipa master) or

Re: [Freeipa-devel] [PATCH] - Add DRM to IPA

2014-08-25 Thread Ade Lee
We plan to do an alpha build of Dogtag 10.2 on Fedora 21 at the end of this week. Ade On Mon, 2014-08-25 at 13:14 +0200, Petr Viktorin wrote: On 08/22/2014 03:28 PM, Petr Vobornik wrote: [...] Should the requirement of Dogtag 10.2 be reflected in a spec file? Yes. Sorry for forgetting

Re: [Freeipa-devel] [PATCH] - Add DRM to IPA

2014-08-22 Thread Petr Viktorin
On 08/21/2014 10:53 PM, Ade Lee wrote: On Thu, 2014-08-21 at 21:52 +0200, Martin Kosek wrote: On 08/21/2014 05:27 PM, Petr Viktorin wrote: On 08/21/2014 03:48 PM, Ade Lee wrote: As agreed on #irc, disabling uninstallation for now. Please apply this new patch on top of the big one. I'm fine

Re: [Freeipa-devel] [PATCH] - Add DRM to IPA

2014-08-22 Thread Petr Vobornik
On 22.8.2014 10:03, Petr Viktorin wrote: On 08/21/2014 10:53 PM, Ade Lee wrote: On Thu, 2014-08-21 at 21:52 +0200, Martin Kosek wrote: On 08/21/2014 05:27 PM, Petr Viktorin wrote: On 08/21/2014 03:48 PM, Ade Lee wrote: As agreed on #irc, disabling uninstallation for now. Please apply this

Re: [Freeipa-devel] [PATCH] - Add DRM to IPA

2014-08-21 Thread Petr Viktorin
On 08/20/2014 09:35 PM, Rob Crittenden wrote: [...] I'm kinda with Petr, I don't know that an uninstall option is needed. On a single master install I successfully did a kra install, uninstall, re-install, so maybe the issue that Petr saw was related to cloning. Yes, on a single master it

Re: [Freeipa-devel] [PATCH] - Add DRM to IPA

2014-08-21 Thread Ade Lee
As agreed on #irc, disabling uninstallation for now. Please apply this new patch on top of the big one. Ade On Thu, 2014-08-21 at 01:15 -0400, Ade Lee wrote: On Wed, 2014-08-20 at 15:35 -0400, Rob Crittenden wrote: Ade Lee wrote: On Thu, 2014-08-14 at 14:29 +0200, Petr Viktorin wrote:

Re: [Freeipa-devel] [PATCH] - Add DRM to IPA

2014-08-21 Thread Petr Viktorin
On 08/21/2014 03:48 PM, Ade Lee wrote: As agreed on #irc, disabling uninstallation for now. Please apply this new patch on top of the big one. I'm fine with pushing a patch with incomplete functionality, after all I did this all the time with permissions. The incomplete parts (apart from

Re: [Freeipa-devel] [PATCH] - Add DRM to IPA

2014-08-21 Thread Martin Kosek
On 08/21/2014 05:27 PM, Petr Viktorin wrote: On 08/21/2014 03:48 PM, Ade Lee wrote: As agreed on #irc, disabling uninstallation for now. Please apply this new patch on top of the big one. I'm fine with pushing a patch with incomplete functionality, after all I did this all the time with

Re: [Freeipa-devel] [PATCH] - Add DRM to IPA

2014-08-21 Thread Ade Lee
On Thu, 2014-08-21 at 21:52 +0200, Martin Kosek wrote: On 08/21/2014 05:27 PM, Petr Viktorin wrote: On 08/21/2014 03:48 PM, Ade Lee wrote: As agreed on #irc, disabling uninstallation for now. Please apply this new patch on top of the big one. I'm fine with pushing a patch with

Re: [Freeipa-devel] [PATCH] - Add DRM to IPA

2014-08-20 Thread Petr Viktorin
On 08/18/2014 07:36 PM, Ade Lee wrote: [...] After discussion with Endi, I also removed some functions in dogtag.py (the plugin) which basically just wrapped calls to the keyclient. There is no need to do this wrapping and it is much more flexible for IPA code to call the keyclient directly.

Re: [Freeipa-devel] [PATCH] - Add DRM to IPA

2014-08-20 Thread Rob Crittenden
Ade Lee wrote: On Thu, 2014-08-14 at 14:29 +0200, Petr Viktorin wrote: On 08/14/2014 10:53 AM, Martin Kosek wrote: On 08/13/2014 09:54 PM, Ade Lee wrote: In Dogtag, we have decided to revert the name of the DRM to the old name KRA. DRM was really only used in docs/marketing, whereas KRA is

Re: [Freeipa-devel] [PATCH] - Add DRM to IPA

2014-08-20 Thread Ade Lee
On Wed, 2014-08-20 at 15:35 -0400, Rob Crittenden wrote: Ade Lee wrote: On Thu, 2014-08-14 at 14:29 +0200, Petr Viktorin wrote: On 08/14/2014 10:53 AM, Martin Kosek wrote: On 08/13/2014 09:54 PM, Ade Lee wrote: In Dogtag, we have decided to revert the name of the DRM to the old name

Re: [Freeipa-devel] [PATCH] - Add DRM to IPA

2014-08-14 Thread Martin Kosek
On 08/13/2014 09:54 PM, Ade Lee wrote: In Dogtag, we have decided to revert the name of the DRM to the old name KRA. DRM was really only used in docs/marketing, whereas KRA is all over the code. Soon, the code and the marketing/docs will match. The following patch changes all references to

Re: [Freeipa-devel] [PATCH] - Add DRM to IPA

2014-08-14 Thread Petr Viktorin
On 08/14/2014 10:53 AM, Martin Kosek wrote: On 08/13/2014 09:54 PM, Ade Lee wrote: In Dogtag, we have decided to revert the name of the DRM to the old name KRA. DRM was really only used in docs/marketing, whereas KRA is all over the code. Soon, the code and the marketing/docs will match. The

Re: [Freeipa-devel] [PATCH] - Add DRM to IPA

2014-08-13 Thread Ade Lee
PM Subject: Re: [Freeipa-devel] [PATCH] - Add DRM to IPA New patch attached which all the issues noted below. Rebased to master. Please review, Thanks, Ade On Mon, 2014-08-11 at 16:54 +0200, Petr Viktorin wrote: On 08/09/2014 01:36 AM, Rob Crittenden wrote: Ade Lee wrote: Attached is a new

Re: [Freeipa-devel] [PATCH] - Add DRM to IPA

2014-08-11 Thread Petr Viktorin
On 08/09/2014 01:36 AM, Rob Crittenden wrote: Ade Lee wrote: Attached is a new patch. I believe I have addressed all the issues raided by pviktori, edewata and rcrit. Ar! Please let me know if I missed something! Incidentally, to get all this to work, you should use the latest Dogtag

Re: [Freeipa-devel] [PATCH] - Add DRM to IPA

2014-08-08 Thread Rob Crittenden
Ade Lee wrote: Attached is a new patch. I believe I have addressed all the issues raided by pviktori, edewata and rcrit. Please let me know if I missed something! Incidentally, to get all this to work, you should use the latest Dogtag 10.2 build, which also contains a fix for pkidestroy

Re: [Freeipa-devel] [PATCH] - Add DRM to IPA

2014-07-18 Thread Rob Crittenden
Ade Lee wrote: Hi all, I have rebased all the previous patches against master, and have squashed them all into a single patch. Its a large patch, but as many folks have already reviewed the constituent precursor patches, most if it should be familiar and easier to review. The main

Re: [Freeipa-devel] [PATCH] - Add DRM to IPA

2014-07-17 Thread Petr Viktorin
On 07/16/2014 02:55 PM, Petr Viktorin wrote: On 07/14/2014 11:45 AM, Ade Lee wrote: Hi all, I have rebased all the previous patches against master, and have squashed them all into a single patch. Its a large patch, but as many folks have already reviewed the constituent precursor patches, most

Re: [Freeipa-devel] [PATCH] - Add DRM to IPA

2014-07-16 Thread Petr Viktorin
On 07/14/2014 11:45 AM, Ade Lee wrote: Hi all, I have rebased all the previous patches against master, and have squashed them all into a single patch. Its a large patch, but as many folks have already reviewed the constituent precursor patches, most if it should be familiar and easier to

Re: [Freeipa-devel] [PATCH] - Add DRM to IPA

2014-07-16 Thread Endi Sukma Dewata
On 7/14/2014 4:45 AM, Ade Lee wrote: Hi all, I have rebased all the previous patches against master, and have squashed them all into a single patch. Its a large patch, but as many folks have already reviewed the constituent precursor patches, most if it should be familiar and easier to

Re: [Freeipa-devel] [PATCH] Add DRM to IPA

2014-04-21 Thread Rob Crittenden
Ade Lee wrote: Attached is a patch that adds the script ipa-drm-install. This script will be used to install a drm in any ipa server that contains a Dogtag CA. Right now, it works for a master. I will add logic in a subsequent patch to allow the installation on a replica using the same

Re: [Freeipa-devel] [PATCH] Add DRM to IPA

2014-04-15 Thread Rob Crittenden
Ade Lee wrote: Attached a new patch to address some of the concerns below, specifically I created a new base class DogtagInstance, in which much of the common CA/KRA code is placed. I'm sure we could go further in reducing duplication, and I'm open to further suggestions and refinements. I did

Re: [Freeipa-devel] [PATCH] Add DRM to IPA

2014-04-15 Thread Ade Lee
Attached is a patch that adds the script ipa-drm-install. This script will be used to install a drm in any ipa server that contains a Dogtag CA. Right now, it works for a master. I will add logic in a subsequent patch to allow the installation on a replica using the same script. This patch is

Re: [Freeipa-devel] [PATCH] Add DRM to IPA

2014-04-08 Thread Martin Kosek
On 04/07/2014 10:40 PM, Rob Crittenden wrote: Ade Lee wrote: This patch adds the capability of installing a Dogtag DRM to an IPA instance. With this patch, when ipa-server-install is run, a Dogtag CA and a Dogtag DRM are created. The DRM shares the same tomcat instance

Re: [Freeipa-devel] [PATCH] Add DRM to IPA

2014-04-08 Thread Rob Crittenden
Martin Kosek wrote: On 04/07/2014 10:40 PM, Rob Crittenden wrote: Ade Lee wrote: This patch adds the capability of installing a Dogtag DRM to an IPA instance. With this patch, when ipa-server-install is run, a Dogtag CA and a Dogtag DRM are created. The DRM shares the

Re: [Freeipa-devel] [PATCH] Add DRM to IPA

2014-04-08 Thread Ade Lee
On Tue, 2014-04-08 at 09:52 -0400, Rob Crittenden wrote: Martin Kosek wrote: On 04/07/2014 10:40 PM, Rob Crittenden wrote: Ade Lee wrote: This patch adds the capability of installing a Dogtag DRM to an IPA instance. With this patch, when ipa-server-install is run, a

Re: [Freeipa-devel] [PATCH] Add DRM to IPA

2014-04-07 Thread Dmitri Pal
On 04/04/2014 02:50 PM, Ade Lee wrote: This patch adds the capability of installing a Dogtag DRM to an IPA instance. With this patch, when ipa-server-install is run, a Dogtag CA and a Dogtag DRM are created. The DRM shares the same tomcat instance and DS instance as the

Re: [Freeipa-devel] [PATCH] Add DRM to IPA

2014-04-07 Thread Rob Crittenden
Dmitri Pal wrote: On 04/04/2014 02:50 PM, Ade Lee wrote: This patch adds the capability of installing a Dogtag DRM to an IPA instance. With this patch, when ipa-server-install is run, a Dogtag CA and a Dogtag DRM are created. The DRM shares the same tomcat instance and DS

Re: [Freeipa-devel] [PATCH] Add DRM to IPA

2014-04-07 Thread Rob Crittenden
Ade Lee wrote: This patch adds the capability of installing a Dogtag DRM to an IPA instance. With this patch, when ipa-server-install is run, a Dogtag CA and a Dogtag DRM are created. The DRM shares the same tomcat instance and DS instance as the Dogtag CA. Moreover,