Re: [Freeipa-devel] [PATCH] slapi-nis support for trusted domains

2013-07-23 Thread Nalin Dahyabhai
Apologies for the delay. On Mon, Jul 15, 2013 at 08:30:03PM +0300, Alexander Bokovoy wrote: Here is the logic: 0. Configuration is performed by setting schema-compat-lookup-sssd: user|group schema-compat-sssd-min-id: value in corresponding schema-compat plugin tree (cn=users and

Re: [Freeipa-devel] [PATCH] 436 Remove word 'field' from GECOS param label

2013-07-23 Thread Martin Kosek
On 07/23/2013 01:31 AM, Dmitri Pal wrote: On 07/22/2013 08:38 AM, Petr Vobornik wrote: On 07/19/2013 11:19 PM, Dmitri Pal wrote: On 07/19/2013 09:26 AM, Jan Pazdziora wrote: On Fri, Jul 19, 2013 at 03:17:49PM +0200, Petr Vobornik wrote: Disclaimer: I have no strong feelings in this matter, it

Re: [Freeipa-devel] [PATCH] slapi-nis support for trusted domains

2013-07-23 Thread Alexander Bokovoy
On Tue, 23 Jul 2013, Nalin Dahyabhai wrote: Apologies for the delay. Thanks for the review! One short comment -- PAM code is from PAM pass-through plugin from 389-ds. That's the reason why its code doesn't follow slapi-nis way and why it has that license. I tried to keep it mostly intact to

Re: [Freeipa-devel] DNSSEC support design considerations: key material handling

2013-07-23 Thread Petr Spacek
On 19.7.2013 19:55, Simo Sorce wrote: I will reply to the rest of the message later if necessary, still digesting some of your answers, but I wanted to address the following first. On Fri, 2013-07-19 at 18:29 +0200, Petr Spacek wrote: The most important question at the moment is What can we

Re: [Freeipa-devel] [PATCH 0076] Use AD LDAP probing to create trusted domain ID range

2013-07-23 Thread Tomas Babej
This improved revision creates ranges of sizes that are multiples of default range size (20). Tomas -- / Alexander Bokovoy From 629428d12fcfafdf2695dad2b2861980a18cceb4 Mon Sep 17 00:00:00 2001 From: Tomas Babej tba...@redhat.com Date: Wed, 17 Jul 2013 15:55:36 +0200 Subject: [PATCH] Use

Re: [Freeipa-devel] [PATCH] 436 Remove word 'field' from GECOS param label

2013-07-23 Thread Petr Vobornik
On 07/22/2013 05:33 PM, Ana Krivokapic wrote: On 07/22/2013 09:01 AM, Martin Kosek wrote: On 07/19/2013 11:19 PM, Dmitri Pal wrote: On 07/19/2013 09:26 AM, Jan Pazdziora wrote: On Fri, Jul 19, 2013 at 03:17:49PM +0200, Petr Vobornik wrote: Disclaimer: I have no strong feelings in this

Re: [Freeipa-devel] [PATCH] 436 Remove word 'field' from GECOS param label

2013-07-23 Thread Ana Krivokapic
On 07/23/2013 12:58 PM, Petr Vobornik wrote: On 07/22/2013 05:33 PM, Ana Krivokapic wrote: On 07/22/2013 09:01 AM, Martin Kosek wrote: On 07/19/2013 11:19 PM, Dmitri Pal wrote: On 07/19/2013 09:26 AM, Jan Pazdziora wrote: On Fri, Jul 19, 2013 at 03:17:49PM +0200, Petr Vobornik wrote:

Re: [Freeipa-devel] [PATCHES] 143-147 Improve performance with large groups

2013-07-23 Thread Martin Kosek
On 07/19/2013 01:10 PM, Petr Vobornik wrote: On 07/18/2013 05:29 PM, Jan Cholasta wrote: On 18.7.2013 17:26, Martin Kosek wrote: On 07/18/2013 05:22 PM, Jan Cholasta wrote: On 18.7.2013 17:07, Martin Kosek wrote: On 07/18/2013 04:53 PM, Jan Cholasta wrote: Added patch which adds new hidden

Re: [Freeipa-devel] [PATCH] 0109-0110 Support querying AD DC when establishing trust as HTTP/ipa.server principal

2013-07-23 Thread Simo Sorce
On Thu, 2013-07-18 at 18:37 +0300, Alexander Bokovoy wrote: Hi! Attached patches make possible to use HTTP/ipa.server@REALM to query AD DC over LDAP immediately after trust is established. We need this to get range discovery working prior to creating range for trusted domain. The patch

[Freeipa-devel] [PATCH] Two minor IPA KDB MS-PAC fixes

2013-07-23 Thread Jakub Hrozek
clang found one branch with undefined variable return and one unused variable. From 09962a9a40cd589c4694ecab4b4faa3c39e8a4a3 Mon Sep 17 00:00:00 2001 From: Jakub Hrozek jhro...@redhat.com Date: Tue, 23 Jul 2013 15:07:39 +0200 Subject: [PATCH 1/2] IPA KDB MS-PAC: return ENOMEM if allocation fails

Re: [Freeipa-devel] [PATCH] 0109-0110 Support querying AD DC when establishing trust as HTTP/ipa.server principal

2013-07-23 Thread Alexander Bokovoy
On Tue, 23 Jul 2013, Simo Sorce wrote: On Thu, 2013-07-18 at 18:37 +0300, Alexander Bokovoy wrote: Hi! Attached patches make possible to use HTTP/ipa.server@REALM to query AD DC over LDAP immediately after trust is established. We need this to get range discovery working prior to creating

Re: [Freeipa-devel] [PATCH] Two minor IPA KDB MS-PAC fixes

2013-07-23 Thread Alexander Bokovoy
On Tue, 23 Jul 2013, Jakub Hrozek wrote: clang found one branch with undefined variable return and one unused variable. ACK. Pushed both to master together with my 0109-0111 and Tomas' 0076 as your patches are on top of mine. -- / Alexander Bokovoy

Re: [Freeipa-devel] [PATCH] 436 Remove word 'field' from GECOS param label

2013-07-23 Thread Petr Vobornik
On 07/23/2013 09:02 AM, Martin Kosek wrote: On 07/23/2013 01:31 AM, Dmitri Pal wrote: On 07/22/2013 08:38 AM, Petr Vobornik wrote: On 07/19/2013 11:19 PM, Dmitri Pal wrote: On 07/19/2013 09:26 AM, Jan Pazdziora wrote: On Fri, Jul 19, 2013 at 03:17:49PM +0200, Petr Vobornik wrote:

Re: [Freeipa-devel] [PATCH] 436 Remove word 'field' from GECOS param label

2013-07-23 Thread Petr Vobornik
On 07/23/2013 01:12 PM, Ana Krivokapic wrote: On 07/23/2013 12:58 PM, Petr Vobornik wrote: On 07/22/2013 05:33 PM, Ana Krivokapic wrote: On 07/22/2013 09:01 AM, Martin Kosek wrote: On 07/19/2013 11:19 PM, Dmitri Pal wrote: On 07/19/2013 09:26 AM, Jan Pazdziora wrote: On Fri, Jul 19, 2013 at

Re: [Freeipa-devel] [PATCH] 430 Break long words in notification area

2013-07-23 Thread Petr Vobornik
On 07/22/2013 05:19 PM, Ana Krivokapic wrote: On 07/18/2013 12:58 PM, Petr Vobornik wrote: Long words (ie. service principal) breaks out of notification area. It doesn't look good. Patch adds word-wrap to break them to multiple pieces. Reproduction: modify a service in Web UI ACK Pushed

Re: [Freeipa-devel] [PATCH] 0109-0110 Support querying AD DC when establishing trust as HTTP/ipa.server principal

2013-07-23 Thread Simo Sorce
On Tue, 2013-07-23 at 16:11 +0300, Alexander Bokovoy wrote: On Tue, 23 Jul 2013, Simo Sorce wrote: On Thu, 2013-07-18 at 18:37 +0300, Alexander Bokovoy wrote: Hi! Attached patches make possible to use HTTP/ipa.server@REALM to query AD DC over LDAP immediately after trust is established.

Re: [Freeipa-devel] [PATCHES] 143-147 Improve performance with large groups

2013-07-23 Thread Petr Viktorin
On 07/23/2013 01:30 PM, Martin Kosek wrote: On 07/19/2013 01:10 PM, Petr Vobornik wrote: On 07/18/2013 05:29 PM, Jan Cholasta wrote: On 18.7.2013 17:26, Martin Kosek wrote: On 07/18/2013 05:22 PM, Jan Cholasta wrote: On 18.7.2013 17:07, Martin Kosek wrote: On 07/18/2013 04:53 PM, Jan

Re: [Freeipa-devel] [PATCH] slapi-nis support for trusted domains

2013-07-23 Thread Nalin Dahyabhai
On Tue, Jul 23, 2013 at 10:15:47AM +0300, Alexander Bokovoy wrote: On Tue, 23 Jul 2013, Nalin Dahyabhai wrote: Apologies for the delay. Thanks for the review! One short comment -- PAM code is from PAM pass-through plugin from 389-ds. That's the reason why its code doesn't follow slapi-nis

Re: [Freeipa-devel] [PATCHES] 143-147 Improve performance with large groups

2013-07-23 Thread Petr Viktorin
On 07/23/2013 04:54 PM, Petr Viktorin wrote: On 07/23/2013 01:30 PM, Martin Kosek wrote: On 07/19/2013 01:10 PM, Petr Vobornik wrote: On 07/18/2013 05:29 PM, Jan Cholasta wrote: On 18.7.2013 17:26, Martin Kosek wrote: On 07/18/2013 05:22 PM, Jan Cholasta wrote: On 18.7.2013 17:07, Martin

Re: [Freeipa-devel] [PATCH] 431-434 Web UI integration tests continuation

2013-07-23 Thread Ana Krivokapic
On 07/18/2013 01:35 PM, Petr Vobornik wrote: On 07/18/2013 01:34 PM, Petr Vobornik wrote: [PATCH] 431 Web UI integration tests: Add trust tests [PATCH] 432 Web UI integration tests: Add ui_driver method descriptions [PATCH] 433 Web UI integration tests: Verify data after add and mod

Re: [Freeipa-devel] [PATCH] 431-434 Web UI integration tests continuation

2013-07-23 Thread Petr Viktorin
On 07/23/2013 05:50 PM, Ana Krivokapic wrote: On 07/18/2013 01:35 PM, Petr Vobornik wrote: On 07/18/2013 01:34 PM, Petr Vobornik wrote: [PATCH] 431 Web UI integration tests: Add trust tests [PATCH] 432 Web UI integration tests: Add ui_driver method descriptions [PATCH] 433 Web UI integration

Re: [Freeipa-devel] [PATCH] 0047 Honor 'enabled' option for widgets

2013-07-23 Thread Petr Vobornik
On 07/22/2013 04:46 PM, Ana Krivokapic wrote: On 07/18/2013 09:47 AM, Petr Vobornik wrote: On 07/17/2013 09:18 PM, Ana Krivokapic wrote: Hello, This patch addresses ticket https://fedorahosted.org/freeipa/ticket/3793. Hello, 1) IMO we should not create attribute which is just a negation

Re: [Freeipa-devel] [PATCH] 161 Use configured dogtag LDAP port instead of default one when renewing certs

2013-07-23 Thread Jan Cholasta
On 22.7.2013 17:40, Simo Sorce wrote: On Mon, 2013-07-22 at 17:36 +0200, Jan Cholasta wrote: if nickname == 'subsystemCert cert-pki-ca': -update_people_entry('pkidbuser', cert) +update_people_entry(dogtag_uri, 'pkidbuser', cert) This is probably wrong, there is no pkidbuser in old