[Freeipa-devel] [PATCH] 0086 Make sure samba{, 4}-winbind-krb5-locator package is not installed when trusts are in use

2012-10-10 Thread Alexander Bokovoy
Hi, Since use of winbind on FreeIPA server that is configured with trusts is conflicting with krb5 locator based on winbind, make sure there is conflict that will force removing samba{,4}-winbind-krb5-locator package when -server-trust-ad subpackage is installed. Please note that since

[Freeipa-devel] [PATCH] 0087 Warn about DNA plugin configuration when working with local ID ranges

2012-10-10 Thread Alexander Bokovoy
Warn about manual DNA plugin configuration when working with local ID ranges since we currently do not support automatic pick up of the changed settings for local ID ranges by the DNA plugin. https://fedorahosted.org/freeipa/ticket/3116 -- / Alexander Bokovoy From

[Freeipa-devel] [PATCH] 0088 Fix typo in the documentation for trusts: RID for Domain Admins is -512

2012-10-10 Thread Alexander Bokovoy
Hi, Domain Admins RID is -512, not -513. Fix the documentation text. -- / Alexander Bokovoy From 152c2f7aae533594599bd86f5779978cf656e600 Mon Sep 17 00:00:00 2001 From: Alexander Bokovoy aboko...@redhat.com Date: Wed, 10 Oct 2012 10:04:25 +0300 Subject: [PATCH 5/5] Fix wrong RID for Domain

Re: [Freeipa-devel] [PATCH] 0086 Make sure samba{, 4}-winbind-krb5-locator package is not installed when trusts are in use

2012-10-10 Thread Alexander Bokovoy
On Wed, 10 Oct 2012, Alexander Bokovoy wrote: Hi, Since use of winbind on FreeIPA server that is configured with trusts is conflicting with krb5 locator based on winbind, make sure there is conflict that will force removing samba{,4}-winbind-krb5-locator package when -server-trust-ad subpackage

Re: [Freeipa-devel] [PATCHES] 0086-0088 Generate Firefox extension on upgrades

2012-10-10 Thread Petr Viktorin
On 10/09/2012 06:01 PM, Petr Vobornik wrote: On 10/09/2012 05:26 PM, Petr Viktorin wrote: On 10/09/2012 05:16 PM, Petr Viktorin wrote: https://fedorahosted.org/freeipa/ticket/3150 Patch 0086: I found an old unused function while working on this, the patch removes it. Patch 0087: Replica

Re: [Freeipa-devel] [PATCH] 0086 Make sure samba{, 4}-winbind-krb5-locator package is not installed when trusts are in use

2012-10-10 Thread Alexander Bokovoy
On Wed, 10 Oct 2012, Alexander Bokovoy wrote: On Wed, 10 Oct 2012, Alexander Bokovoy wrote: Hi, Since use of winbind on FreeIPA server that is configured with trusts is conflicting with krb5 locator based on winbind, make sure there is conflict that will force removing

Re: [Freeipa-devel] [PATCH] 321 Move CRL publish directory to IPA owned directory

2012-10-10 Thread Petr Viktorin
On 10/09/2012 04:11 PM, Martin Kosek wrote: On 10/09/2012 03:48 PM, Rob Crittenden wrote: Martin Kosek wrote: On 10/08/2012 09:29 PM, Rob Crittenden wrote: Martin Kosek wrote: - Original Message - From: Rob Crittenden rcrit...@redhat.com To: Martin Kosek mko...@redhat.com Cc:

Re: [Freeipa-devel] [PATCH] 0086 Make sure samba{, 4}-winbind-krb5-locator package is not installed when trusts are in use

2012-10-10 Thread Alexander Bokovoy
On Wed, 10 Oct 2012, Alexander Bokovoy wrote: On Wed, 10 Oct 2012, Alexander Bokovoy wrote: On Wed, 10 Oct 2012, Alexander Bokovoy wrote: Hi, Since use of winbind on FreeIPA server that is configured with trusts is conflicting with krb5 locator based on winbind, make sure there is conflict

Re: [Freeipa-devel] [PATCH] 0088 Fix typo in the documentation for trusts: RID for Domain Admins is -512

2012-10-10 Thread Sumit Bose
On Wed, Oct 10, 2012 at 10:52:18AM +0300, Alexander Bokovoy wrote: Hi, Domain Admins RID is -512, not -513. Fix the documentation text. -- / Alexander Bokovoy ACK bye, Sumit ___ Freeipa-devel mailing list Freeipa-devel@redhat.com

Re: [Freeipa-devel] [PATCH] 0087 Warn about DNA plugin configuration when working with local ID ranges

2012-10-10 Thread Sumit Bose
On Wed, Oct 10, 2012 at 10:51:11AM +0300, Alexander Bokovoy wrote: Warn about manual DNA plugin configuration when working with local ID ranges since we currently do not support automatic pick up of the changed settings for local ID ranges by the DNA plugin.

Re: [Freeipa-devel] [PATCH] 0087 Warn about DNA plugin configuration when working with local ID ranges

2012-10-10 Thread Alexander Bokovoy
On Wed, 10 Oct 2012, Sumit Bose wrote: On Wed, Oct 10, 2012 at 10:51:11AM +0300, Alexander Bokovoy wrote: Warn about manual DNA plugin configuration when working with local ID ranges since we currently do not support automatic pick up of the changed settings for local ID ranges by the DNA

Re: [Freeipa-devel] [PATCH] 1051 Fix CS replica management

2012-10-10 Thread Jan Cholasta
On 9.10.2012 21:31, Rob Crittenden wrote: Martin Kosek wrote: On 10/08/2012 05:12 PM, Jan Cholasta wrote: Hi, On 20.9.2012 19:38, Rob Crittenden wrote: Jan Cholasta wrote: Hi, Dne 31.8.2012 19:43, Rob Crittenden napsal(a): The naming in CS replication agreements is different from IPA

Re: [Freeipa-devel] [PATCH] 321 Move CRL publish directory to IPA owned directory

2012-10-10 Thread Martin Kosek
On 10/10/2012 11:07 AM, Petr Viktorin wrote: On 10/09/2012 04:11 PM, Martin Kosek wrote: On 10/09/2012 03:48 PM, Rob Crittenden wrote: Martin Kosek wrote: On 10/08/2012 09:29 PM, Rob Crittenden wrote: Martin Kosek wrote: - Original Message - From: Rob Crittenden rcrit...@redhat.com

[Freeipa-devel] [PATCH] 322 Fix CA CRL migration crash in ipa-upgradeconfig

2012-10-10 Thread Martin Kosek
CRL migrate procedure did not check if a CA was actually configured on an updated master/replica. This caused ipa-upgradeconfig to crash on replicas without a CA. Make sure that CRL migrate procedure is not run when CA is not configured on given master. Also add few try..except clauses to make

Re: [Freeipa-devel] [PATCH] 322 Fix CA CRL migration crash in ipa-upgradeconfig

2012-10-10 Thread Petr Viktorin
On 10/10/2012 01:05 PM, Martin Kosek wrote: CRL migrate procedure did not check if a CA was actually configured on an updated master/replica. This caused ipa-upgradeconfig to crash on replicas without a CA. Make sure that CRL migrate procedure is not run when CA is not configured on given

Re: [Freeipa-devel] [PATCH] 0086 Make sure samba{, 4}-winbind-krb5-locator package is not installed when trusts are in use

2012-10-10 Thread Sumit Bose
On Wed, Oct 10, 2012 at 12:04:06PM +0300, Alexander Bokovoy wrote: On Wed, 10 Oct 2012, Alexander Bokovoy wrote: On Wed, 10 Oct 2012, Alexander Bokovoy wrote: Hi, Since use of winbind on FreeIPA server that is configured with trusts is conflicting with krb5 locator based on winbind, make

Re: [Freeipa-devel] [PATCH] 0086 Make sure samba{, 4}-winbind-krb5-locator package is not installed when trusts are in use

2012-10-10 Thread Alexander Bokovoy
On Wed, 10 Oct 2012, Sumit Bose wrote: On Wed, Oct 10, 2012 at 12:04:06PM +0300, Alexander Bokovoy wrote: On Wed, 10 Oct 2012, Alexander Bokovoy wrote: On Wed, 10 Oct 2012, Alexander Bokovoy wrote: Hi, Since use of winbind on FreeIPA server that is configured with trusts is conflicting with

Re: [Freeipa-devel] [PATCH] 0088 Fix typo in the documentation for trusts: RID for Domain Admins is -512

2012-10-10 Thread Martin Kosek
On 10/10/2012 11:40 AM, Sumit Bose wrote: On Wed, Oct 10, 2012 at 10:52:18AM +0300, Alexander Bokovoy wrote: Hi, Domain Admins RID is -512, not -513. Fix the documentation text. -- / Alexander Bokovoy ACK bye, Sumit Pushed to master, ipa-3-0. Martin

Re: [Freeipa-devel] [PATCH] 1051 Fix CS replica management

2012-10-10 Thread Rob Crittenden
Jan Cholasta wrote: On 9.10.2012 21:31, Rob Crittenden wrote: Martin Kosek wrote: On 10/08/2012 05:12 PM, Jan Cholasta wrote: Hi, On 20.9.2012 19:38, Rob Crittenden wrote: Jan Cholasta wrote: Hi, Dne 31.8.2012 19:43, Rob Crittenden napsal(a): The naming in CS replication agreements is

Re: [Freeipa-devel] [PATCH] 0085 optimize SELinux setup in ipa-adtrust-install

2012-10-10 Thread Rob Crittenden
Alexander Bokovoy wrote: Hi, this patch avoids reconfiguring SELinux if required variable is already enabled. This would save you couple minutes on re-run of ipa-adtrust-install. No ticket for it yet and the patch might wait until 3.0.1 but I had enogh patience :) I think we need a set of

Re: [Freeipa-devel] [PATCH] 1059 single CRL generator

2012-10-10 Thread Martin Kosek
On 10/10/2012 12:46 AM, Rob Crittenden wrote: Rob Crittenden wrote: Martin Kosek wrote: On 10/09/2012 04:43 PM, Rob Crittenden wrote: Martin Kosek wrote: On 10/04/2012 06:17 PM, Rob Crittenden wrote: This changes the way IPA generates CRLs for new installs only. The first master installed

Re: [Freeipa-devel] [PATCHES] 0086-0088 Generate Firefox extension on upgrades

2012-10-10 Thread Martin Kosek
On 10/10/2012 10:55 AM, Petr Viktorin wrote: On 10/09/2012 06:01 PM, Petr Vobornik wrote: On 10/09/2012 05:26 PM, Petr Viktorin wrote: On 10/09/2012 05:16 PM, Petr Viktorin wrote: https://fedorahosted.org/freeipa/ticket/3150 Patch 0086: I found an old unused function while working on this,

Re: [Freeipa-devel] [PATCH] 1059 single CRL generator

2012-10-10 Thread Rob Crittenden
Martin Kosek wrote: On 10/10/2012 12:46 AM, Rob Crittenden wrote: Rob Crittenden wrote: Martin Kosek wrote: On 10/09/2012 04:43 PM, Rob Crittenden wrote: Martin Kosek wrote: On 10/04/2012 06:17 PM, Rob Crittenden wrote: This changes the way IPA generates CRLs for new installs only. The

Re: [Freeipa-devel] [PATCH 0016] Adds port to connection error message in ipa-client-install

2012-10-10 Thread Rob Crittenden
Tomas Babej wrote: On 10/04/2012 11:06 AM, Tomas Babej wrote: On 10/03/2012 07:27 PM, Rob Crittenden wrote: Tomas Babej wrote: On 10/03/2012 03:31 PM, Tomas Babej wrote: On 10/02/2012 08:48 PM, Rob Crittenden wrote: Tomas Babej wrote: On 09/26/2012 09:32 PM, Rob Crittenden wrote: Tomas

Re: [Freeipa-devel] [PATCHES] 0086-0088 Generate Firefox extension on upgrades

2012-10-10 Thread Petr Viktorin
On 10/10/2012 03:37 PM, Martin Kosek wrote: On 10/10/2012 10:55 AM, Petr Viktorin wrote: On 10/09/2012 06:01 PM, Petr Vobornik wrote: On 10/09/2012 05:26 PM, Petr Viktorin wrote: On 10/09/2012 05:16 PM, Petr Viktorin wrote: https://fedorahosted.org/freeipa/ticket/3150 Patch 0086: I found

Re: [Freeipa-devel] [PATCH] 1059 single CRL generator

2012-10-10 Thread Martin Kosek
On 10/10/2012 04:12 PM, Rob Crittenden wrote: Martin Kosek wrote: On 10/10/2012 12:46 AM, Rob Crittenden wrote: Rob Crittenden wrote: Martin Kosek wrote: On 10/09/2012 04:43 PM, Rob Crittenden wrote: Martin Kosek wrote: On 10/04/2012 06:17 PM, Rob Crittenden wrote: This changes the way IPA

[Freeipa-devel] [PATCH] 1060 - one-liner to fix update file

2012-10-10 Thread Rob Crittenden
I was tempted to push this as a one-liner but an extra set of eyes won't hurt. The lack of quotes around this member causes it to be comma-parsed so it adds each component separately as a member. rob From b54f78a7d9ce2175ed906225e7efb0ba6093b0c9 Mon Sep 17 00:00:00 2001 From: Rob Crittenden

Re: [Freeipa-devel] [PATCH] 1060 - one-liner to fix update file

2012-10-10 Thread Alexander Bokovoy
On Wed, 10 Oct 2012, Rob Crittenden wrote: I was tempted to push this as a one-liner but an extra set of eyes won't hurt. The lack of quotes around this member causes it to be comma-parsed so it adds each component separately as a member. I removed this code in my patch 0084 so it is

[Freeipa-devel] [PATCH] 0089 Clarify trust-add help regarding multiple runs against the same domain

2012-10-10 Thread Alexander Bokovoy
Hi, this patch originated from off-list discussion regarding multiple runs of ipa trust-add against the same domain. Since trust-add re-establishes the trust every time it is run and all the other information fetched from the remote domain controller stays the same, it can be run multiple

Re: [Freeipa-devel] [PATCH] 1059 single CRL generator

2012-10-10 Thread Rob Crittenden
Martin Kosek wrote: On 10/10/2012 04:12 PM, Rob Crittenden wrote: Martin Kosek wrote: On 10/10/2012 12:46 AM, Rob Crittenden wrote: Rob Crittenden wrote: Martin Kosek wrote: On 10/09/2012 04:43 PM, Rob Crittenden wrote: Martin Kosek wrote: On 10/04/2012 06:17 PM, Rob Crittenden wrote:

Re: [Freeipa-devel] [PATCH] 0084 Add cifs principal to S4U2Proxy targets only when running ipa-adtrust-install

2012-10-10 Thread Rob Crittenden
Alexander Bokovoy wrote: Hi, attached patch moves S4U2Proxy configuration for CIFS service to ipa-adtrust-install. Since CIFS service is only available after running ipa-adtrust-install, we cannot reference its principal in advance. This means bootstrap template and updates processes cannot

Re: [Freeipa-devel] [PATCH] 1060 - one-liner to fix update file

2012-10-10 Thread Rob Crittenden
Alexander Bokovoy wrote: On Wed, 10 Oct 2012, Rob Crittenden wrote: I was tempted to push this as a one-liner but an extra set of eyes won't hurt. The lack of quotes around this member causes it to be comma-parsed so it adds each component separately as a member. I removed this code in my

Re: [Freeipa-devel] [PATCHES] 0086-0088 Generate Firefox extension on upgrades

2012-10-10 Thread Martin Kosek
On 10/10/2012 04:23 PM, Petr Viktorin wrote: On 10/10/2012 03:37 PM, Martin Kosek wrote: On 10/10/2012 10:55 AM, Petr Viktorin wrote: On 10/09/2012 06:01 PM, Petr Vobornik wrote: On 10/09/2012 05:26 PM, Petr Viktorin wrote: On 10/09/2012 05:16 PM, Petr Viktorin wrote:

Re: [Freeipa-devel] [PATCH] 0086 Make sure samba{, 4}-winbind-krb5-locator package is not installed when trusts are in use

2012-10-10 Thread Andreas Schneider
On Wednesday 10 October 2012 15:40:17 Alexander Bokovoy wrote: On Wed, 10 Oct 2012, Sumit Bose wrote: On Wed, Oct 10, 2012 at 12:04:06PM +0300, Alexander Bokovoy wrote: On Wed, 10 Oct 2012, Alexander Bokovoy wrote: On Wed, 10 Oct 2012, Alexander Bokovoy wrote: Hi, Since use of winbind

Re: [Freeipa-devel] [PATCH] 1059 single CRL generator

2012-10-10 Thread Martin Kosek
On 10/10/2012 05:29 PM, Rob Crittenden wrote: Martin Kosek wrote: On 10/10/2012 04:12 PM, Rob Crittenden wrote: Martin Kosek wrote: On 10/10/2012 12:46 AM, Rob Crittenden wrote: Rob Crittenden wrote: Martin Kosek wrote: On 10/09/2012 04:43 PM, Rob Crittenden wrote: Martin Kosek wrote: On

Re: [Freeipa-devel] [PATCH] 1059 single CRL generator

2012-10-10 Thread Rob Crittenden
Martin Kosek wrote: On 10/10/2012 05:29 PM, Rob Crittenden wrote: Martin Kosek wrote: On 10/10/2012 04:12 PM, Rob Crittenden wrote: Martin Kosek wrote: On 10/10/2012 12:46 AM, Rob Crittenden wrote: Rob Crittenden wrote: Martin Kosek wrote: On 10/09/2012 04:43 PM, Rob Crittenden wrote:

Re: [Freeipa-devel] [PATCH] 0086 Make sure samba{, 4}-winbind-krb5-locator package is not installed when trusts are in use

2012-10-10 Thread Simo Sorce
On Wed, 2012-10-10 at 17:57 +0200, Andreas Schneider wrote: On Wednesday 10 October 2012 15:40:17 Alexander Bokovoy wrote: On Wed, 10 Oct 2012, Sumit Bose wrote: On Wed, Oct 10, 2012 at 12:04:06PM +0300, Alexander Bokovoy wrote: On Wed, 10 Oct 2012, Alexander Bokovoy wrote: On Wed, 10

Re: [Freeipa-devel] [PATCH] 0086 Make sure samba{, 4}-winbind-krb5-locator package is not installed when trusts are in use

2012-10-10 Thread Rob Crittenden
Simo Sorce wrote: On Wed, 2012-10-10 at 17:57 +0200, Andreas Schneider wrote: On Wednesday 10 October 2012 15:40:17 Alexander Bokovoy wrote: On Wed, 10 Oct 2012, Sumit Bose wrote: On Wed, Oct 10, 2012 at 12:04:06PM +0300, Alexander Bokovoy wrote: On Wed, 10 Oct 2012, Alexander Bokovoy wrote:

[Freeipa-devel] FYI: pushed oneliner to improve spec requires

2012-10-10 Thread Simo Sorce
Hi I pushed the following oneliner: Subject: Use stricter requirement for krb5-server Our code strictly depends on 1.10 as the KDC DAL plugin interface is not guaranteed stable and indeed is different in 1.9 and will be different in 1.11 So we cannot allow upgrades to 1.11 until we can provide a

[Freeipa-devel] [PATCH] 1061 disable betxn plugins

2012-10-10 Thread Rob Crittenden
389-ds-base 1.3.0 was released to Fedora 18 updates-testing this week. There is the chance of deadlock in the schema compat plugin at the moment. We have a candidate patch for addressing it but it is not yet reviewed. This is an interim patch that disables betxn explicitly for now. It should