URL: https://github.com/freeipa/freeipa/pull/227
Title: #227: cert-request: match names against principal aliases
martbab commented:
"""
Fixed upstream
master:
https://fedorahosted.org/freeipa/changeset/dfbdb5323863e6c3d681c1b33b1eb9d2efefd6c7
"""
See the full comment at
URL: https://github.com/freeipa/freeipa/pull/227
Title: #227: cert-request: match names against principal aliases
apophys commented:
"""
The tests look good to me.
"""
See the full comment at
https://github.com/freeipa/freeipa/pull/227#issuecomment-264854251
--
Manage your subscription for
URL: https://github.com/freeipa/freeipa/pull/227
Title: #227: cert-request: match names against principal aliases
martbab commented:
"""
There are small issues I found in the patch. Please address those.
@apophys can quickly you review the new test cases? they pass (except for one
pointed out
URL: https://github.com/freeipa/freeipa/pull/227
Title: #227: cert-request: match names against principal aliases
martbab commented:
"""
I agree that it is out of scope of this work and will open a separate ticket
for the `cert-request` refactoring.
"""
See the full comment at
URL: https://github.com/freeipa/freeipa/pull/227
Title: #227: cert-request: match names against principal aliases
martbab commented:
"""
I agree that it is out of scope of this work and will open a separate ticket
for the `cert-request` refactoring. You may open another ticket for the
URL: https://github.com/freeipa/freeipa/pull/227
Title: #227: cert-request: match names against principal aliases
frasertweedale commented:
"""
@martbab I agree with doing the refactor you propose, but I deem it out of
scope for this ticket.
Doing that refactor entails a cleanup of how we
URL: https://github.com/freeipa/freeipa/pull/227
Title: #227: cert-request: match names against principal aliases
frasertweedale commented:
"""
@martbab
Semantics:
0. *Subject principal* is looked up by `--principal` option, via
`{PRINCIPAL_TYPE}_show` command. If you think this should be
URL: https://github.com/freeipa/freeipa/pull/227
Title: #227: cert-request: match names against principal aliases
frasertweedale commented:
"""
@martbab thanks for review; I will revisit this some time in next week
(hopefully)
"""
See the full comment at
URL: https://github.com/freeipa/freeipa/pull/227
Title: #227: cert-request: match names against principal aliases
martbab commented:
"""
Also one of the tests in caacl_profile_enforcement suite fails:
https://paste.fedoraproject.org/481011/12920714/
"""
See the full comment at
URL: https://github.com/freeipa/freeipa/pull/227
Title: #227: cert-request: match names against principal aliases
martbab commented:
"""
Also, the current execution flow of the command is very confusing (retrieving
objects based on intended principal types etc.). As a part of the ticket I was
URL: https://github.com/freeipa/freeipa/pull/227
Title: #227: cert-request: match names against principal aliases
martbab commented:
"""
@frasertweedale What is the intended semantics of the checks against principal
aliases in SAN? If the requestor can use only the aliases belonging to the
11 matches
Mail list logo