Re: [Freeipa-devel] [PATCH] 1063 Allow no reverse domain

2012-10-17 Thread Martin Kosek
On 10/16/2012 07:27 PM, Rob Crittenden wrote: Martin Kosek wrote: On 10/16/2012 05:21 PM, Rob Crittenden wrote: A reverse zone is always created unless --no-reverse is passed. rob Yeah, this is much better. I would just unify our summary printed before installation. Now when running

Re: [Freeipa-devel] [PATCH] 0087 Warn about DNA plugin configuration when working with local ID ranges

2012-10-17 Thread Sumit Bose
On Wed, Oct 10, 2012 at 12:59:53PM +0300, Alexander Bokovoy wrote: On Wed, 10 Oct 2012, Sumit Bose wrote: On Wed, Oct 10, 2012 at 10:51:11AM +0300, Alexander Bokovoy wrote: Warn about manual DNA plugin configuration when working with local ID ranges since we currently do not support

[Freeipa-devel] [PATCH] 222 Fixed incorrect link to browser config after session expiration

2012-10-17 Thread Petr Vobornik
Fixed typo in message placeholder. https://fedorahosted.org/freeipa/ticket/3187 -- Petr Vobornik From 7c87acf4de28a80a9bd3a3c050aebd40917a8091 Mon Sep 17 00:00:00 2001 From: Petr Vobornik pvobo...@redhat.com Date: Wed, 17 Oct 2012 10:14:20 +0200 Subject: [PATCH] Fixed incorrect link to browser

Re: [Freeipa-devel] [PATCH] 0087 Warn about DNA plugin configuration when working with local ID ranges

2012-10-17 Thread Martin Kosek
On 10/17/2012 11:43 AM, Sumit Bose wrote: On Wed, Oct 10, 2012 at 12:59:53PM +0300, Alexander Bokovoy wrote: On Wed, 10 Oct 2012, Sumit Bose wrote: On Wed, Oct 10, 2012 at 10:51:11AM +0300, Alexander Bokovoy wrote: Warn about manual DNA plugin configuration when working with local ID ranges

Re: [Freeipa-devel] [PATCH] 0087 Warn about DNA plugin configuration when working with local ID ranges

2012-10-17 Thread Alexander Bokovoy
On Wed, 17 Oct 2012, Sumit Bose wrote: On Wed, Oct 10, 2012 at 12:59:53PM +0300, Alexander Bokovoy wrote: On Wed, 10 Oct 2012, Sumit Bose wrote: On Wed, Oct 10, 2012 at 10:51:11AM +0300, Alexander Bokovoy wrote: Warn about manual DNA plugin configuration when working with local ID ranges since

Re: [Freeipa-devel] [PATCH] 0087 Warn about DNA plugin configuration when working with local ID ranges

2012-10-17 Thread Petr Viktorin
On 10/17/2012 12:10 PM, Alexander Bokovoy wrote: On Wed, 17 Oct 2012, Sumit Bose wrote: On Wed, Oct 10, 2012 at 12:59:53PM +0300, Alexander Bokovoy wrote: On Wed, 10 Oct 2012, Sumit Bose wrote: On Wed, Oct 10, 2012 at 10:51:11AM +0300, Alexander Bokovoy wrote: Warn about manual DNA plugin

Re: [Freeipa-devel] [PATCH] 0087 Warn about DNA plugin configuration when working with local ID ranges

2012-10-17 Thread Alexander Bokovoy
On Wed, 17 Oct 2012, Martin Kosek wrote: On 10/17/2012 12:14 PM, Petr Viktorin wrote: On 10/17/2012 12:10 PM, Alexander Bokovoy wrote: On Wed, 17 Oct 2012, Sumit Bose wrote: On Wed, Oct 10, 2012 at 12:59:53PM +0300, Alexander Bokovoy wrote: On Wed, 10 Oct 2012, Sumit Bose wrote: On Wed, Oct

Re: [Freeipa-devel] [PATCH] 0087 Warn about DNA plugin configuration when working with local ID ranges

2012-10-17 Thread Martin Kosek
On 10/17/2012 12:42 PM, Alexander Bokovoy wrote: On Wed, 17 Oct 2012, Petr Viktorin wrote: On 10/17/2012 12:10 PM, Alexander Bokovoy wrote: On Wed, 17 Oct 2012, Sumit Bose wrote: On Wed, Oct 10, 2012 at 12:59:53PM +0300, Alexander Bokovoy wrote: On Wed, 10 Oct 2012, Sumit Bose wrote: On Wed,

Re: [Freeipa-devel] [PATCH] 0089 Clarify trust-add help regarding multiple runs against the same domain

2012-10-17 Thread Sumit Bose
On Wed, Oct 10, 2012 at 06:05:02PM +0300, Alexander Bokovoy wrote: Hi, this patch originated from off-list discussion regarding multiple runs of ipa trust-add against the same domain. Since trust-add re-establishes the trust every time it is run and all the other information fetched from

[Freeipa-devel] [PATCH] 223 Simpler instructions to generate certificate

2012-10-17 Thread Petr Vobornik
Instructions to generate certificate were simplified. New instructions: 1) Create a certificate database or use an existing one. To create a new database: # certutil -N -d database path 2) Create a CSR with subject CN=hostname,O=realm, for example: # certutil -R -d database path -a

Re: [Freeipa-devel] [PATCH] 0087 Warn about DNA plugin configuration when working with local ID ranges

2012-10-17 Thread Alexander Bokovoy
On Wed, 17 Oct 2012, Martin Kosek wrote: On 10/17/2012 12:42 PM, Alexander Bokovoy wrote: On Wed, 17 Oct 2012, Petr Viktorin wrote: On 10/17/2012 12:10 PM, Alexander Bokovoy wrote: On Wed, 17 Oct 2012, Sumit Bose wrote: On Wed, Oct 10, 2012 at 12:59:53PM +0300, Alexander Bokovoy wrote: On

Re: [Freeipa-devel] [PATCH] 0089 Clarify trust-add help regarding multiple runs against the same domain

2012-10-17 Thread Martin Kosek
On 10/17/2012 12:52 PM, Sumit Bose wrote: On Wed, Oct 10, 2012 at 06:05:02PM +0300, Alexander Bokovoy wrote: Hi, this patch originated from off-list discussion regarding multiple runs of ipa trust-add against the same domain. Since trust-add re-establishes the trust every time it is run and

Re: [Freeipa-devel] [PATCH 0019] Forbid overlapping primary and secondary rid ranges

2012-10-17 Thread Tomas Babej
On 10/17/2012 11:14 AM, Sumit Bose wrote: On Tue, Oct 16, 2012 at 02:26:24PM +0200, Tomas Babej wrote: Hi, commands ipa idrange-add / idrange-mod no longer allows the user to enter primary or secondary rid range such that has non-zero intersection with primary or secondary rid range of another

[Freeipa-devel] Hide private symbols in the bind-dyndb-ldap

2012-10-17 Thread Adam Tkac
Hello, attached patch hides all symbols except dynamic_driver_{init,destroy}. Feedback is appreciated. Regards, Adam -- Adam Tkac, Red Hat, Inc. From 126929489baf4f69fe0444860776f7e76c1411f2 Mon Sep 17 00:00:00 2001 From: Adam Tkac von...@gmail.com Date: Wed, 17 Oct 2012 13:00:31 +0200

Re: [Freeipa-devel] [PATCH] 0087 Warn about DNA plugin configuration when working with local ID ranges

2012-10-17 Thread Petr Viktorin
On 10/17/2012 12:42 PM, Alexander Bokovoy wrote: On Wed, 17 Oct 2012, Petr Viktorin wrote: On 10/17/2012 12:10 PM, Alexander Bokovoy wrote: On Wed, 17 Oct 2012, Sumit Bose wrote: On Wed, Oct 10, 2012 at 12:59:53PM +0300, Alexander Bokovoy wrote: On Wed, 10 Oct 2012, Sumit Bose wrote: On

[Freeipa-devel] [PATCH] 323 Report ipa-upgradeconfig errors during RPM upgrade

2012-10-17 Thread Martin Kosek
Report errors just like with ipa-ldap-updater. These messages should warn user that some parts of the upgrades may have not been successful and he should follow up on them. Otherwise, user may not notice them at all. ipa-upgradeconfig logging has been made consistent with ipa-ldap-updater logging

Re: [Freeipa-devel] [PATCH] support AES for cross-realm TGTs

2012-10-17 Thread Sumit Bose
On Wed, Sep 26, 2012 at 06:36:40PM -0400, Simo Sorce wrote: This patch allows Windows to send us TGTs using AES. Simo. -- Simo Sorce * Red Hat, Inc. * New York (sorry for the long delay) ACK, patch is working as expected with w2k8r2. bye, Sumit

Re: [Freeipa-devel] [PATCH] support AES for cross-realm TGTs

2012-10-17 Thread Martin Kosek
On 10/17/2012 01:29 PM, Sumit Bose wrote: On Wed, Sep 26, 2012 at 06:36:40PM -0400, Simo Sorce wrote: This patch allows Windows to send us TGTs using AES. Simo. -- Simo Sorce * Red Hat, Inc. * New York (sorry for the long delay) ACK, patch is working as expected with w2k8r2. bye,

Re: [Freeipa-devel] [PATCH] Fix various issues found by Coverity

2012-10-17 Thread Alexander Bokovoy
On Tue, 02 Oct 2012, Sumit Bose wrote: Hi, this patch fixes a couple of resource leaks and unchecked return and an uninitialised value found by Coverity. ACK. -- / Alexander Bokovoy ___ Freeipa-devel mailing list Freeipa-devel@redhat.com

Re: [Freeipa-devel] [PATCH] 87 extdom: handle INP_POSIX_UID and INP_POSIX_GID requests

2012-10-17 Thread Alexander Bokovoy
On Thu, 11 Oct 2012, Sumit Bose wrote: Hi, I found this issue while working on a related sssd bug https://fedorahosted.org/sssd/ticket/1561 . This patch allows the clients to send a request map a UID or GID for a trusted user to the name of the user. To achieve this the Posix ID is mapped to

Re: [Freeipa-devel] [PATCH 0019] Forbid overlapping primary and secondary rid ranges

2012-10-17 Thread Sumit Bose
On Wed, Oct 17, 2012 at 12:59:52PM +0200, Tomas Babej wrote: On 10/17/2012 11:14 AM, Sumit Bose wrote: On Tue, Oct 16, 2012 at 02:26:24PM +0200, Tomas Babej wrote: Hi, commands ipa idrange-add / idrange-mod no longer allows the user to enter primary or secondary rid range such that has

Re: [Freeipa-devel] [PATCH] Fix various issues found by Coverity

2012-10-17 Thread Martin Kosek
On 10/17/2012 02:14 PM, Alexander Bokovoy wrote: On Tue, 02 Oct 2012, Sumit Bose wrote: Hi, this patch fixes a couple of resource leaks and unchecked return and an uninitialised value found by Coverity. ACK. Pushed to master, ipa-3-0. Martin

Re: [Freeipa-devel] [PATCH 0019] Forbid overlapping primary and secondary rid ranges

2012-10-17 Thread Tomas Babej
On 10/17/2012 02:34 PM, Sumit Bose wrote: On Wed, Oct 17, 2012 at 12:59:52PM +0200, Tomas Babej wrote: On 10/17/2012 11:14 AM, Sumit Bose wrote: On Tue, Oct 16, 2012 at 02:26:24PM +0200, Tomas Babej wrote: Hi, commands ipa idrange-add / idrange-mod no longer allows the user to enter primary

Re: [Freeipa-devel] [PATCH] convert the base platform modules into packages

2012-10-17 Thread Petr Viktorin
On 09/21/2012 04:57 PM, Timo Aaltonen wrote: Ok, so this is the first step before we can start to rewrite bits from ipaserver/install to make them support other distros. There are no real functional changes yet. had some dependency issues installing the resulting rpm's, so didn't test the

Re: [Freeipa-devel] Hide private symbols in the bind-dyndb-ldap

2012-10-17 Thread Simo Sorce
On Wed, 2012-10-17 at 13:04 +0200, Adam Tkac wrote: Hello, attached patch hides all symbols except dynamic_driver_{init,destroy}. Feedback is appreciated. Any reason not to use a simple export file ? Anyway strong ACK, keeping private symbols private is good hygiene. Simo. -- Simo Sorce

Re: [Freeipa-devel] Hide private symbols in the bind-dyndb-ldap

2012-10-17 Thread Adam Tkac
On Wed, Oct 17, 2012 at 09:58:36AM -0400, Simo Sorce wrote: On Wed, 2012-10-17 at 13:04 +0200, Adam Tkac wrote: Hello, attached patch hides all symbols except dynamic_driver_{init,destroy}. Feedback is appreciated. Any reason not to use a simple export file ? This is also possible

[Freeipa-devel] [PATCH 0020] Refactoring of default.conf man page

2012-10-17 Thread Tomas Babej
Hi, Description for the 'server' and 'wait_for_attr' option has been added. Option 'server' has been marked as deprecated, as it is not used anywhere in IPA code. All the options have been sorted lexicographically. Please provide feedback for added descriptions: +.TP +.B server hostname

Re: [Freeipa-devel] Hide private symbols in the bind-dyndb-ldap

2012-10-17 Thread Simo Sorce
On Wed, 2012-10-17 at 17:06 +0200, Adam Tkac wrote: On Wed, Oct 17, 2012 at 09:58:36AM -0400, Simo Sorce wrote: On Wed, 2012-10-17 at 13:04 +0200, Adam Tkac wrote: Hello, attached patch hides all symbols except dynamic_driver_{init,destroy}. Feedback is appreciated. Any

Re: [Freeipa-devel] Hide private symbols in the bind-dyndb-ldap

2012-10-17 Thread Petr Spacek
On 10/17/2012 05:16 PM, Simo Sorce wrote: On Wed, 2012-10-17 at 17:06 +0200, Adam Tkac wrote: On Wed, Oct 17, 2012 at 09:58:36AM -0400, Simo Sorce wrote: On Wed, 2012-10-17 at 13:04 +0200, Adam Tkac wrote: Hello, attached patch hides all symbols except dynamic_driver_{init,destroy}. Feedback

[Freeipa-devel] [PATCH] 1064 Improve error messages during ipa-replica-manage

2012-10-17 Thread Rob Crittenden
Make some of the errors in ipa-replica-manage clearer. See ticket for more reproduction details. rob From f676e25754b3194fc03b9404239c0a51094b44d1 Mon Sep 17 00:00:00 2001 From: Rob Crittenden rcrit...@redhat.com Date: Wed, 17 Oct 2012 11:54:14 -0400 Subject: [PATCH] Improve error messages in

Re: [Freeipa-devel] [PATCH 0019] Forbid overlapping primary and secondary rid ranges

2012-10-17 Thread Sumit Bose
On Wed, Oct 17, 2012 at 03:29:11PM +0200, Tomas Babej wrote: On 10/17/2012 02:34 PM, Sumit Bose wrote: On Wed, Oct 17, 2012 at 12:59:52PM +0200, Tomas Babej wrote: On 10/17/2012 11:14 AM, Sumit Bose wrote: On Tue, Oct 16, 2012 at 02:26:24PM +0200, Tomas Babej wrote: Hi, commands ipa

Re: [Freeipa-devel] [PATCH 75] log dogtag errors

2012-10-17 Thread John Dennis
On 10/12/2012 04:35 AM, Petr Viktorin wrote: On 10/11/2012 06:53 PM, John Dennis wrote: On 04/28/2012 09:50 AM, John Dennis wrote: On 04/27/2012 04:45 AM, Petr Viktorin wrote: On 04/20/2012 08:07 PM, John Dennis wrote: Ticket #2622 If we get an error from dogtag we always did raise a

Re: [Freeipa-devel] Unit tests failing on F18

2012-10-17 Thread Rob Crittenden
Martin Kosek wrote: Hello, I was investigating global unit test failure on Fedora 18 for most of today, I would like to share results I found so far. Unit test and its related scripts on F18 now reports NSS BUSY exception, just like this one: # ./make-testcert Traceback (most recent call

[Freeipa-devel] using 389-ds-base with betxn plugins enabled

2012-10-17 Thread Rich Megginson
I'm testing with f18, freeipa-server 3.0.0, 389-ds-base-1.3.0.a1, with betxn manually enabled in all plugins in 389. I did an ipa-server-install. I have ipa user-add --all --raw working - it returns the mep and memberof attributes immediately. I had to do something like this: diff --git