Re: [Freeipa-devel] [PATCH] 459 Allow edit of ipakrbokasdelegate in Web UI when attrlevelrights are unknown

2013-09-26 Thread Petr Vobornik
On 09/25/2013 06:15 PM, Ana Krivokapic wrote: On 09/25/2013 05:44 PM, Petr Vobornik wrote: On 09/25/2013 02:17 PM, Ana Krivokapic wrote: On 09/24/2013 04:31 PM, Petr Vobornik wrote: Old host entries are missing object class with krbticketflags attribute. Therefore UI does not receive

Re: [Freeipa-devel] [PATCH 0018] Ensure credentials structure is initialized

2013-09-26 Thread Petr Vobornik
On 09/26/2013 12:07 AM, Nathaniel McCallum wrote: Patch attached. Fixes the issue. ACK -- Petr Vobornik ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel

Re: [Freeipa-devel] [PATCH 0113] ipa-client: Set NIS domain name in the installer

2013-09-26 Thread Jan Cholasta
On 26.9.2013 10:28, Tomas Babej wrote: Hi, Provides two new options for the ipa-client-install: --nisdomain: specifies the NIS domain name --no_nisdomain: flag to aviod setting the NIS domain name In case no --nisdomain is specified and --no_nisdomain flag was not set, the IPA domain

Re: [Freeipa-devel] [PATCH 0018] Ensure credentials structure is initialized

2013-09-26 Thread Petr Viktorin
On 09/26/2013 12:07 AM, Nathaniel McCallum wrote: Patch attached. There's a ticket to make FreeIPA build with stricter warnings: https://fedorahosted.org/freeipa/ticket/3896 AFAIU this will trip -Wmissing-field-initializers. -- Petr³ ___

[Freeipa-devel] Please use the new LDAPEntry API in new code

2013-09-26 Thread Jan Cholasta
Hi, I have seen in several recently submitted patches that some people still use the old LDAP API. It is deprecated and is going to be removed soon, so please don't use it anymore. Whenever you have an urge to do something like this: dn, entry_attrs = ldap.get_entry(...) ...

Re: [Freeipa-devel] [PATCH 111] ipa-client-install: Publish CA certificate to systemwide store

2013-09-26 Thread Jan Cholasta
On 24.9.2013 18:14, Nalin Dahyabhai wrote: On Tue, Sep 24, 2013 at 01:30:10PM +0200, Jan Cholasta wrote: We discussed this with Tomáš off-line and it turns out that ipa-client-install fails if the CA cert is not added to /etc/pki/nssdb. However, according to p11-kit docs it should work:

Re: [Freeipa-devel] [PATCH 111] ipa-client-install: Publish CA certificate to systemwide store

2013-09-26 Thread Tomas Babej
On 09/26/2013 12:54 PM, Jan Cholasta wrote: On 24.9.2013 18:14, Nalin Dahyabhai wrote: On Tue, Sep 24, 2013 at 01:30:10PM +0200, Jan Cholasta wrote: We discussed this with Tomáš off-line and it turns out that ipa-client-install fails if the CA cert is not added to /etc/pki/nssdb. However,

[Freeipa-devel] [PATCH] [Fedora] Update translations from Transifex

2013-09-26 Thread Petr Viktorin
Hello, There'll be a Fedora 20 L10n test on Thursday, and maintainers are asked to push packages with updated translations by Friday. We're planning another minor release after that deadline; in the mean time I will put this patch into Fedora 20 Rawhide only. The patch goes on top of the

Re: [Freeipa-devel] [PATCH 0113] ipa-client: Set NIS domain name in the installer

2013-09-26 Thread Martin Kosek
On 09/26/2013 10:28 AM, Tomas Babej wrote: Hi, Provides two new options for the ipa-client-install: --nisdomain: specifies the NIS domain name --no_nisdomain: flag to aviod setting the NIS domain name In case no --nisdomain is specified and --no_nisdomain flag was not set, the

Re: [Freeipa-devel] [PATCH 0113] ipa-client: Set NIS domain name in the installer

2013-09-26 Thread Tomas Babej
On 09/26/2013 12:20 PM, Jan Cholasta wrote: On 26.9.2013 10:28, Tomas Babej wrote: Hi, Provides two new options for the ipa-client-install: --nisdomain: specifies the NIS domain name --no_nisdomain: flag to aviod setting the NIS domain name In case no --nisdomain is specified and

[Freeipa-devel] [RFE] User Life-Cycle Management

2013-09-26 Thread Martin Kosek
Hello developers! I prepared a first draft of User Life-Cycle Management feature, which should appear in later FreeIPA release. http://www.freeipa.org/page/V3/User_Life-Cycle_Management There are still open questions, the main one from my perspective is if the staged users should be stored in

Re: [Freeipa-devel] [PATCH 0113] ipa-client: Set NIS domain name in the installer

2013-09-26 Thread Martin Kosek
On 09/26/2013 02:28 PM, Tomas Babej wrote: On 09/26/2013 12:20 PM, Jan Cholasta wrote: On 26.9.2013 10:28, Tomas Babej wrote: Hi, Provides two new options for the ipa-client-install: --nisdomain: specifies the NIS domain name --no_nisdomain: flag to aviod setting the NIS domain

Re: [Freeipa-devel] [PATCH 0113] ipa-client: Set NIS domain name in the installer

2013-09-26 Thread Jan Cholasta
On 26.9.2013 14:38, Martin Kosek wrote: On 09/26/2013 02:28 PM, Tomas Babej wrote: On 09/26/2013 12:20 PM, Jan Cholasta wrote: On 26.9.2013 10:28, Tomas Babej wrote: Hi, Provides two new options for the ipa-client-install: --nisdomain: specifies the NIS domain name

Re: [Freeipa-devel] [PATCH 0113] ipa-client: Set NIS domain name in the installer

2013-09-26 Thread Martin Kosek
On 09/26/2013 02:45 PM, Jan Cholasta wrote: On 26.9.2013 14:38, Martin Kosek wrote: On 09/26/2013 02:28 PM, Tomas Babej wrote: On 09/26/2013 12:20 PM, Jan Cholasta wrote: ... I just found --no-nisdomain more descriptive and explicit. If there is a consensus, I can remove it. I am not aware

[Freeipa-devel] [PATCH 0192] Prevent deadlock in PTR record synchronization (versions = 2.x)

2013-09-26 Thread Petr Spacek
Hello, attached patch prevents/hides deadlock in plugin versions versions = 2.x. I plan to push it to v2 branch. Branches v3 and newer shouldn't be affected. https://fedorahosted.org/bind-dyndb-ldap/ticket/113 -- Petr^2 Spacek diff --unified -r bind-dyndb-ldap-2.3.deadlock/README

Re: [Freeipa-devel] [PATCH 0113] ipa-client: Set NIS domain name in the installer

2013-09-26 Thread Petr Viktorin
On 09/26/2013 02:58 PM, Martin Kosek wrote: On 09/26/2013 02:45 PM, Jan Cholasta wrote: On 26.9.2013 14:38, Martin Kosek wrote: On 09/26/2013 02:28 PM, Tomas Babej wrote: On 09/26/2013 12:20 PM, Jan Cholasta wrote: ... I just found --no-nisdomain more descriptive and explicit. If there is a

Re: [Freeipa-devel] [PATCH 111] ipa-client-install: Publish CA certificate to systemwide store

2013-09-26 Thread Jan Cholasta
On 26.9.2013 12:59, Tomas Babej wrote: On 09/26/2013 12:54 PM, Jan Cholasta wrote: On 24.9.2013 18:14, Nalin Dahyabhai wrote: On Tue, Sep 24, 2013 at 01:30:10PM +0200, Jan Cholasta wrote: We discussed this with Tomáš off-line and it turns out that ipa-client-install fails if the CA cert is

Re: [Freeipa-devel] [PATCH 0018] Ensure credentials structure is initialized

2013-09-26 Thread Nathaniel McCallum
On Thu, 2013-09-26 at 12:36 +0200, Petr Viktorin wrote: On 09/26/2013 12:07 AM, Nathaniel McCallum wrote: Patch attached. There's a ticket to make FreeIPA build with stricter warnings: https://fedorahosted.org/freeipa/ticket/3896 AFAIU this will trip -Wmissing-field-initializers. C89