Re: [Freeipa-devel] [PATCH] 0020 Handle missing /etc/ipa in ipa-client-install

2013-04-22 Thread Martin Kosek
On 04/19/2013 04:58 PM, Rob Crittenden wrote: Ana Krivokapic wrote: On 04/19/2013 03:58 PM, Rob Crittenden wrote: Rob Crittenden wrote: Ana Krivokapic wrote: Hello, Make sure /etc/ipa is created and owned by freeipa-python package. Report correct error to user if /etc/ipa is missing

Re: [Freeipa-devel] [PATCH] 130 Drop support for OpenSSH versions before 6.2

2013-04-22 Thread Martin Kosek
On 04/19/2013 07:39 PM, Rob Crittenden wrote: Jan Cholasta wrote: Hi, this patch fixes https://fedorahosted.org/freeipa/ticket/3571. OpenSSH6.2 brings upstream support forAuthorizedKeysCommand, which is required for OpenSSH integration. Until now, we relied on downstream patches

Re: [Freeipa-devel] [PATCH] 0020 Handle missing /etc/ipa in ipa-client-install

2013-04-22 Thread Ana Krivokapic
On 04/22/2013 08:16 AM, Martin Kosek wrote: On 04/19/2013 04:58 PM, Rob Crittenden wrote: Ana Krivokapic wrote: On 04/19/2013 03:58 PM, Rob Crittenden wrote: Rob Crittenden wrote: Ana Krivokapic wrote: Hello, Make sure /etc/ipa is created and owned by freeipa-python package. Report

Re: [Freeipa-devel] [PATCH] 0020 Handle missing /etc/ipa in ipa-client-install

2013-04-22 Thread Ana Krivokapic
On 04/22/2013 11:29 AM, Ana Krivokapic wrote: On 04/22/2013 08:16 AM, Martin Kosek wrote: On 04/19/2013 04:58 PM, Rob Crittenden wrote: Ana Krivokapic wrote: On 04/19/2013 03:58 PM, Rob Crittenden wrote: Rob Crittenden wrote: Ana Krivokapic wrote: Hello, Make sure /etc/ipa is created and

Re: [Freeipa-devel] [PATCH] 0020 Handle missing /etc/ipa in ipa-client-install

2013-04-22 Thread Martin Kosek
On 04/22/2013 11:53 AM, Ana Krivokapic wrote: On 04/22/2013 11:29 AM, Ana Krivokapic wrote: On 04/22/2013 08:16 AM, Martin Kosek wrote: On 04/19/2013 04:58 PM, Rob Crittenden wrote: Ana Krivokapic wrote: On 04/19/2013 03:58 PM, Rob Crittenden wrote: Rob Crittenden wrote: Ana Krivokapic

Re: [Freeipa-devel] Integration with the provisioning systems

2013-04-22 Thread Martin Kosek
On 04/21/2013 09:14 PM, Dmitri Pal wrote: Hello, Please review the design page for the following ticket: https://fedorahosted.org/freeipa/ticket/3583 http://www.freeipa.org/page/V3/Integration_with_a_provisioning_systems Hello Dmitri, The design looks fine, I would just like to discuss

Re: [Freeipa-devel] Integration with the provisioning systems

2013-04-22 Thread Dmitri Pal
On 04/22/2013 07:34 AM, Martin Kosek wrote: On 04/21/2013 09:14 PM, Dmitri Pal wrote: Hello, Please review the design page for the following ticket: https://fedorahosted.org/freeipa/ticket/3583 http://www.freeipa.org/page/V3/Integration_with_a_provisioning_systems Hello Dmitri, The

Re: [Freeipa-devel] [PATCH] 130 Drop support for OpenSSH versions before 6.2

2013-04-22 Thread Jan Cholasta
On 19.4.2013 19:39, Rob Crittenden wrote: Jan Cholasta wrote: Also, this does not fix SSH integration not working on Fedora 18, as that is caused by backward incompatiblity in openssh-server-6.1p1-6 and later (see https://bugzilla.redhat.com/show_bug.cgi?id=953534). FYI this bug was fixed.

Re: [Freeipa-devel] Integration with the provisioning systems

2013-04-22 Thread Martin Kosek
On 04/22/2013 02:48 PM, Dmitri Pal wrote: On 04/22/2013 07:34 AM, Martin Kosek wrote: On 04/21/2013 09:14 PM, Dmitri Pal wrote: ... So here is what I suggest: Split the ticket into two steps (tickets): Step 1: add the userClass attribute to ipaHost - do it now. That should be a very low

Re: [Freeipa-devel] Integration with the provisioning systems

2013-04-22 Thread Simo Sorce
On Mon, 2013-04-22 at 08:48 -0400, Dmitri Pal wrote: On 04/22/2013 07:34 AM, Martin Kosek wrote: On 04/21/2013 09:14 PM, Dmitri Pal wrote: Hello, Please review the design page for the following ticket: https://fedorahosted.org/freeipa/ticket/3583

Re: [Freeipa-devel] Integration with the provisioning systems

2013-04-22 Thread Rob Crittenden
Simo Sorce wrote: On Mon, 2013-04-22 at 08:48 -0400, Dmitri Pal wrote: On 04/22/2013 07:34 AM, Martin Kosek wrote: On 04/21/2013 09:14 PM, Dmitri Pal wrote: Hello, Please review the design page for the following ticket: https://fedorahosted.org/freeipa/ticket/3583

[Freeipa-devel] [PATCH] 0022 Do not display an interactive mode message in unattended mode

2013-04-22 Thread Ana Krivokapic
Do not display an interactive mode message in unattended mode https://fedorahosted.org/freeipa/ticket/3576 -- Regards, Ana Krivokapic Associate Software Engineer FreeIPA team Red Hat Inc. From 8b8a1ccdfae5c69f202ceb2e5f31a351a0c3493d Mon Sep 17 00:00:00 2001 From: Ana Krivokapic

[Freeipa-devel] [PATCH 0023 Do not display ports to open when password is incorrect during ipa-client-install

2013-04-22 Thread Ana Krivokapic
Do not display ports to open when password is incorrect during ipa-client-install https://fedorahosted.org/freeipa/ticket/3573 -- Regards, Ana Krivokapic Associate Software Engineer FreeIPA team Red Hat Inc. From ac63792645d7c2a5c68e5dda0664e2dcf1b7e809 Mon Sep 17 00:00:00 2001 From: Ana

[Freeipa-devel] Web UI refactoring effort ready for review

2013-04-22 Thread Petr Vobornik
Hello, Web UI refactoring is ready for review. Code is available at usual location: git://fedorapeople.org/~pvoborni/freeipa.git branch menu I would like to ask Endi and Ana to comment the design of Builder/Registry/Global registry/Providers. I will work with Ana and Varun on testing the

[Freeipa-devel] [PATCHES] 0218-0219 https://fedorahosted.org/freeipa/ticket/3578

2013-04-22 Thread Petr Viktorin
Hello, These patches fix errors in our schema files. The syntax errors would prevent future versions of 389 from starting. I haven't done functional testing with development 389 versions, I'll get in touch with mreynolds for that. So don't push these yet.

[Freeipa-devel] [PATCH] 1096 handle gethostbyaddr() exceptions

2013-04-22 Thread Rob Crittenden
This was seen during the Test Day where a user had an empty /etc/resolv.conf and /etc/hosts. He was trying to set up IPA as the DNS server. By just logging this error we still handle it properly later, even with --no-host-dns. rob From a5d9ca738ccba6471c02296c797938b16487d26b Mon Sep 17

[Freeipa-devel] [PATCH] 0024 Add missing permissions to Host Administrators privilege

2013-04-22 Thread Ana Krivokapic
The 'Host Administrators' privilege was missing two permissions ('Retrieve Certificates from the CA' and 'Revoke Certificate'), causing the inability to remove a host with a certificate. https://fedorahosted.org/freeipa/ticket/3585 -- Regards, Ana Krivokapic Associate Software Engineer FreeIPA

Re: [Freeipa-devel] [PATCH] 0022 Do not display an interactive mode message in unattended mode

2013-04-22 Thread Rob Crittenden
Ana Krivokapic wrote: Do not display an interactive mode message in unattended mode https://fedorahosted.org/freeipa/ticket/3576 ACK ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel

Re: [Freeipa-devel] [PATCH 0023 Do not display ports to open when password is incorrect during ipa-client-install

2013-04-22 Thread Rob Crittenden
Ana Krivokapic wrote: Do not display ports to open when password is incorrect during ipa-client-install https://fedorahosted.org/freeipa/ticket/3573 What happens if port 88 is not open so it can't connect to the KDC? I'm not sure how the best way to determine one vs the other, I don't think