Re: [Freeipa-devel] [PATCH] 872 allow csr file to be provided interactively

2011-09-14 Thread Martin Kosek
On Tue, 2011-09-13 at 14:35 -0400, Rob Crittenden wrote: > Add an escape clause to the CSR validator in the cert plugin. If the csr > is a file just return and let the load_files() call slurp in the > contents. It will still get validated. > > rob This works fine for CSR file. Shouldn't we fix

Re: [Freeipa-devel] [PATCH] 016 Fixed: Some widgets do not have space for validation error message

2011-09-14 Thread Petr Vobornik
Forgot to update tests - to address newly added validation row in table_widget. -- Petr Vobornik From 40382df3620607760e8a6033b93b178d149f9ed4 Mon Sep 17 00:00:00 2001 From: Petr Vobornik Date: Wed, 14 Sep 2011 13:01:25 +0200 Subject: [PATCH] Fixed: Some widgets do not have space for validatio

Re: [Freeipa-devel] [PATCH] 872 allow csr file to be provided interactively

2011-09-14 Thread Martin Kosek
On Wed, 2011-09-14 at 14:23 +0200, Martin Kosek wrote: > On Tue, 2011-09-13 at 14:35 -0400, Rob Crittenden wrote: > > Add an escape clause to the CSR validator in the cert plugin. If the csr > > is a file just return and let the load_files() call slurp in the > > contents. It will still get valid

Re: [Freeipa-devel] [PATCH] 873 update ipa-ldap-updater man page

2011-09-14 Thread Martin Kosek
On Tue, 2011-09-13 at 16:13 -0400, Rob Crittenden wrote: > ipa-ldap-updater is really just meant to be run during upgrades, not as > a user utility. Add a blurb about that. > > This also fixes a bit of formatting and adds a bit about the order of > operations. > > rob ACK. Pushed to master, ip

Re: [Freeipa-devel] [PATCH] 1 Add ipa-adtrust-install utility

2011-09-14 Thread Sumit Bose
On Tue, Sep 13, 2011 at 06:01:33PM +0200, Sumit Bose wrote: > On Mon, Sep 12, 2011 at 05:24:38PM -0400, Simo Sorce wrote: > > On Mon, 2011-09-12 at 17:53 +0200, Sumit Bose wrote: > > [..] > > > > > > > I can now run 'smbclient -k -L' on my test system wit hthe recent samba > > > patch. > > > > So

Re: [Freeipa-devel] [PATCH] 872 allow csr file to be provided interactively

2011-09-14 Thread Rob Crittenden
Martin Kosek wrote: On Wed, 2011-09-14 at 14:23 +0200, Martin Kosek wrote: On Tue, 2011-09-13 at 14:35 -0400, Rob Crittenden wrote: Add an escape clause to the CSR validator in the cert plugin. If the csr is a file just return and let the load_files() call slurp in the contents. It will still g

Re: [Freeipa-devel] [PATCH] 871 add hostname regex

2011-09-14 Thread Rob Crittenden
Alexander Bokovoy wrote: On Tue, 13 Sep 2011, Jan Cholasta wrote: What about IDN hosts? With this change we would require them to be always in Punycode? Oh, hadn't considered that, I was just following the relevent RFCs. Is there a way we can easily support those as well? The easiest way wo

[Freeipa-devel] Structured DNS record API proposal

2011-09-14 Thread Martin Kosek
Attached in the txt file. If you have any comments or suggestions to this proposal, please let me know. https://fedorahosted.org/freeipa/ticket/1766 https://fedorahosted.org/freeipa/ticket/1766 This is a proposal for API for per-DNS-type interface in FreeIPA. There are many structured DNS RR typ

Re: [Freeipa-devel] [PATCH] 872 allow csr file to be provided interactively

2011-09-14 Thread Martin Kosek
On Wed, 2011-09-14 at 11:29 -0400, Rob Crittenden wrote: > Martin Kosek wrote: > > On Wed, 2011-09-14 at 14:23 +0200, Martin Kosek wrote: > >> On Tue, 2011-09-13 at 14:35 -0400, Rob Crittenden wrote: > >>> Add an escape clause to the CSR validator in the cert plugin. If the csr > >>> is a file just

[Freeipa-devel] [PATCH] 874 suppress managed netgroups as indirect members of hosts

2011-09-14 Thread Rob Crittenden
Suppress managed netgroups as indirect members of hosts. This enhances a previous patch that I did for hostgroups. rob >From 5ab1b8b8f82e419c4b6c80e01e6a0805ab62bffe Mon Sep 17 00:00:00 2001 From: Rob Crittenden Date: Wed, 14 Sep 2011 16:33:33 -0400 Subject: [PATCH] Suppress managed netgroups a

Re: [Freeipa-devel] Upgrading a machine to use the proxy.

2011-09-14 Thread Rob Crittenden
Adam Young wrote: To convert an older build where the PKI system wasn't proxied: awk '{print $0} /Define an AJP 1.3 Connector on port/ {print "}" }' /etc/pki-ca/server.xml > server.xml.new ; mv server.xml.new /etc/pki-ca/server.xml sed -e "s/\[PKI_MACHINE_NAME\]/$HOSTNAME/g" -e "s/\[PKI_AJP_PO

Re: [Freeipa-devel] Upgrading a machine to use the proxy.

2011-09-14 Thread Dmitri Pal
On 09/14/2011 04:46 PM, Rob Crittenden wrote: > Adam Young wrote: >> To convert an older build where the PKI system wasn't proxied: >> >> >> awk '{print $0} /Define an AJP 1.3 Connector on port/ {print "> port=\"9447\" protocol=\"AJP/1.3\" redirectPort=\"9444\" />}" }' >> /etc/pki-ca/server.xml > s

Re: [Freeipa-devel] [PATCH] 1 Add ipa-adtrust-install utility

2011-09-14 Thread Simo Sorce
On Wed, 2011-09-14 at 14:50 +0200, Sumit Bose wrote: > a recent commit in master made another change necesary. Additionally I > renamed smbinstance to adtrustinstance and check for more samba client > binaries which are needed by the utility. New version attached. Tested and works great! ACK, Pus

Re: [Freeipa-devel] [PATCH] 016 Fixed: Some widgets do not have space for validation error message

2011-09-14 Thread Endi Sukma Dewata
On 9/14/2011 7:23 AM, Petr Vobornik wrote: Forgot to update tests - to address newly added validation row in table_widget. One issue, in all search and association facets we now have 2 rows of footer (there are 2 horizontal lines at the bottom). I think it would be better to use a single row

[Freeipa-devel] [PATCH] 269 Fixed problem opening host adder dialog.

2011-09-14 Thread Endi Sukma Dewata
The hidden fqdn field in the host adder dialog has been changed to use a generic widget instead of text widget to avoid null pointer error since the UI elements are never created. Ticket #1788 Pushed to master and ipa-2-1 under one-liner/trivial rule. -- Endi S. Dewata From 5e7a5bdfa92cd63f96aa

[Freeipa-devel] [PATCH] 270 Fixed posix group checkbox.

2011-09-14 Thread Endi Sukma Dewata
In the adder dialog for groups the checkbox has been modified to use the correct field name "nonposix" and be checked by default. Note: This is a temporary fix to minimize the changes due to release schedule. Eventually the field label will be changed into "Non-POSIX group" and the checkbox will

Re: [Freeipa-devel] [PATCH] 25 Create Tool for Enabling Disabling Managed Entry

2011-09-14 Thread JR Aquino
On Jul 22, 2011, at 7:05 AM, Martin Kosek wrote: > On Thu, 2011-07-21 at 23:52 +, JR Aquino wrote: >> On Apr 25, 2011, at 9:00 AM, Simo Sorce wrote: >> >>> On Mon, 2011-04-25 at 14:59 +, JR Aquino wrote: On Apr 25, 2011, at 6:43 AM, Simo Sorce wrote: > On Thu, 2011-04-21 a