[Freeipa-devel] [PATCH] 294 Read DM password from option in external CA install

2012-08-17 Thread Martin Kosek
ipa-server-install with external CA could not be run in an unattended mode as DM password was required to decipher answer cache. https://fedorahosted.org/freeipa/ticket/2793 >From faf4a1c5966be148e514fef93fcb7103edb14b6b Mon Sep 17 00:00:00 2001 From: Martin Kosek Date: Fri, 17 Aug 2012 09:51:36

[Freeipa-devel] [PATCH] 295 Fix managedBy label for DNS zone

2012-08-17 Thread Martin Kosek
Even though managedBy output parameter was only used for failed host managedBy memberships, it was defined in global baseldap.py classes. Incorrect label was then being displayed also for DNS zone per-zone permission attribute with the same name. Move managedBy output parameter to host plugin. Def

Re: [Freeipa-devel] [PATCH] 293 Bump bind-dyndb-ldap version in spec file

2012-08-17 Thread Simo Sorce
- Original Message - > The updated version of the BIND LDAP plugin includes completed > support of DNS zone transfers. With the new version, users will be > able to configure slave DNS servers for IPA master DNS server. ACK. Simo. ___ Freeipa-d

Re: [Freeipa-devel] [PATCH] 294 Read DM password from option in external CA install

2012-08-17 Thread Simo Sorce
- Original Message - > ipa-server-install with external CA could not be run in > an unattended mode as DM password was required to decipher answer > cache. > > https://fedorahosted.org/freeipa/ticket/2793 ACK Simo. ___ Freeipa-devel mailing li

Re: [Freeipa-devel] [PATCH] 293 Bump bind-dyndb-ldap version in spec file

2012-08-17 Thread Martin Kosek
On Fri, 2012-08-17 at 05:55 -0400, Simo Sorce wrote: > - Original Message - > > The updated version of the BIND LDAP plugin includes completed > > support of DNS zone transfers. With the new version, users will be > > able to configure slave DNS servers for IPA master DNS server. > > ACK.

Re: [Freeipa-devel] [PATCH] 294 Read DM password from option in external CA install

2012-08-17 Thread Martin Kosek
On Fri, 2012-08-17 at 05:57 -0400, Simo Sorce wrote: > - Original Message - > > ipa-server-install with external CA could not be run in > > an unattended mode as DM password was required to decipher answer > > cache. > > > > https://fedorahosted.org/freeipa/ticket/2793 > > ACK > > Simo.

[Freeipa-devel] [PATCH] client: include the directory with domain-realm mappings in krb5.conf

2012-08-17 Thread Jakub Hrozek
Hi, the attached patches add the directory the SSSD writes domain-realm mappings as includedir to krb5.conf when installing the client. [PATCH 1/3] ipachangeconf: allow specifying non-default delimeter for options ipachangeconf only allows one delimeter between keys and values. This patch adds th

[Freeipa-devel] [PATCH] 296 Fix client-only build

2012-08-17 Thread Martin Kosek
Client-only build unconditionally touched some files from freeipa-server package and thus the installation crashed. Fix spec file to enable client-only builds like "make client-rpms". -- Pushed to master as a one-liner. >From 60391e64157516c39547bd77ec4ff3e5e65ce455 Mon Sep 17 00:00:00 2001 From:

[Freeipa-devel] [PATCH] 0006 Removes sssd.conf after uninstall.

2012-08-17 Thread Tomas Babej
Hi, The sssd.conf file is no longer left behind in case sssd was not configured before the installation. https://fedorahosted.org/freeipa/ticket/2740 TomasFrom ae338576d912f494707653e311517070baedb986 Mon Sep 17 00:00:00 2001 From: Tomas Babej Date: Fri, 17 Aug 2012 08:56:45 -0400 Subject: [PAT

Re: [Freeipa-devel] [PATCH] Patch to allow IPA to work with dogtag 10 on f18

2012-08-17 Thread Ade Lee
On Thu, 2012-08-16 at 18:45 +0200, Martin Kosek wrote: > On 08/16/2012 01:28 PM, Ade Lee wrote: > > Patch attached this time. I should know better than to do this in the > > middle of the night .. > > > > On Thu, 2012-08-16 at 09:12 +0200, Martin Kosek wrote: > >> On 08/16/2012 07:53 AM, Ade Lee

[Freeipa-devel] Ticket #2866 - referential integrity in IPA

2012-08-17 Thread Martin Kosek
Hi guys, I am now investigating ticket #2866: https://fedorahosted.org/freeipa/ticket/2866 And I am thinking about possible solutions for this problem. In a nutshell, we do not properly check referential integrity in some IPA objects where we keep one-way DN references to other objects, e.g. in -

Re: [Freeipa-devel] Ticket #2866 - referential integrity in IPA

2012-08-17 Thread Rich Megginson
On 08/17/2012 07:44 AM, Martin Kosek wrote: Hi guys, I am now investigating ticket #2866: https://fedorahosted.org/freeipa/ticket/2866 And I am thinking about possible solutions for this problem. In a nutshell, we do not properly check referential integrity in some IPA objects where we keep one

Re: [Freeipa-devel] [PATCH] Patch to allow IPA to work with dogtag 10 on f18

2012-08-17 Thread Ade Lee
On Fri, 2012-08-17 at 09:34 -0400, Ade Lee wrote: > On Thu, 2012-08-16 at 18:45 +0200, Martin Kosek wrote: > > On 08/16/2012 01:28 PM, Ade Lee wrote: > > > Patch attached this time. I should know better than to do this in the > > > middle of the night .. > > > > > > On Thu, 2012-08-16 at 09:12 +0

Re: [Freeipa-devel] [PATCH] Patch to allow IPA to work with dogtag 10 on f18

2012-08-17 Thread Rob Crittenden
Ade Lee wrote: On Fri, 2012-08-17 at 09:34 -0400, Ade Lee wrote: On Thu, 2012-08-16 at 18:45 +0200, Martin Kosek wrote: On 08/16/2012 01:28 PM, Ade Lee wrote: Patch attached this time. I should know better than to do this in the middle of the night .. On Thu, 2012-08-16 at 09:12 +0200, Marti

[Freeipa-devel] Announcing FreeIPA v3.0.0 beta 2 Release

2012-08-17 Thread Rob Crittenden
The FreeIPA team is proud to announce version FreeIPA v3.0.0 beta 2. It can be downloaded from http://www.freeipa.org/page/Downloads. A build is available in the Fedora 18 and rawhide repositories or for Fedora 17 via the freeipa-devel repo on www.freeipa.org: http://freeipa.org/downloads/free

Re: [Freeipa-devel] [PATCH] client: include the directory with domain-realm mappings in krb5.conf

2012-08-17 Thread Simo Sorce
- Original Message - > Hi, > > the attached patches add the directory the SSSD writes domain-realm > mappings as includedir to krb5.conf when installing the client. > > [PATCH 1/3] ipachangeconf: allow specifying non-default delimeter for > options > ipachangeconf only allows one delime

[Freeipa-devel] [PATCH 79] Ticket #3008: DN objects hash differently depending on case

2012-08-17 Thread John Dennis
-- John Dennis Looking to carve out IT costs? www.redhat.com/carveoutcosts/ >From 18182bb02a01718a2fc837670521ab757f58bfd4 Mon Sep 17 00:00:00 2001 From: John Dennis Date: Fri, 17 Aug 2012 15:34:40 -0400 Subject: [PATCH 79] Ticket #3008: DN objects hash differently depending on case Content-T