Re: [Freeipa-devel] [PATCH] 236 Log unhandled exceptions in certificate renewal scripts

2014-03-10 Thread Jan Cholasta
On 28.1.2014 14:44, Petr Viktorin wrote: On 01/23/2014 03:47 PM, Jan Cholasta wrote: Hi, the attached patch fixes https://fedorahosted.org/freeipa/ticket/4093. Honza This needs a rebase for the new LDAP API. Fixed and rebased on top of current master. -- Jan Cholasta From

Re: [Freeipa-devel] DNSSEC design page: key wrapping

2014-03-10 Thread Petr Spacek
On 7.3.2014 17:33, Dmitri Pal wrote: I do not think it is the right architectural approach to try to fix a specific use case with one off solution while we already know that we need a key storage. I would rather do things right and reusable than jam them into the currently proposed release

Re: [Freeipa-devel] [PATCH] 0481 permission-find: Cache the root entry for legacy permissions

2014-03-10 Thread Petr Viktorin
On 03/07/2014 04:45 PM, Martin Kosek wrote: On 02/28/2014 03:51 PM, Petr Viktorin wrote: Hello, This reduces LDAP searches in permission-find when there are legacy permissions. The root entry (which contains all legacy permission ACIs) is only looked up once. There is a conflict on one

Re: [Freeipa-devel] DNSSEC design page: key wrapping

2014-03-10 Thread Martin Kosek
On 03/10/2014 11:49 AM, Petr Spacek wrote: On 7.3.2014 17:33, Dmitri Pal wrote: I do not think it is the right architectural approach to try to fix a specific use case with one off solution while we already know that we need a key storage. I would rather do things right and reusable than

Re: [Freeipa-devel] FreeIPA ConnId connector for usage with Apache Syncope

2014-03-10 Thread Petr Viktorin
On 03/07/2014 04:39 PM, Marco Di Sabatino Di Diodoro wrote: Hi all, Il giorno 03/feb/2014, alle ore 11:41, Francesco Chicchiriccò ilgro...@apache.org mailto:ilgro...@apache.org ha scritto: On 31/01/2014 18:57, Dmitri Pal wrote: On 01/31/2014 08:17 AM, Francesco Chicchiriccò wrote: Are you

Re: [Freeipa-devel] [PATCH 0044] Periodically refresh global ipa-kdb configuration

2014-03-10 Thread Nathaniel McCallum
On Mon, 2014-02-24 at 14:26 -0500, Nathaniel McCallum wrote: Before this patch, ipa-kdb would load global configuration on startup and never update it. This means that if global configuration is changed, the KDC never receives the new configuration until it is restarted. This patch enables

Re: [Freeipa-devel] [PATCH] 1106 IPA REST smart proxy

2014-03-10 Thread Petr Viktorin
On 02/27/2014 10:18 PM, Rob Crittenden wrote: Rob Crittenden wrote: Dmitri Pal wrote: On 02/17/2014 04:57 PM, Rob Crittenden wrote: Dmitri Pal wrote: On 02/17/2014 04:13 PM, Rob Crittenden wrote: Dmitri Pal wrote: On 02/17/2014 02:33 PM, Rob Crittenden wrote: Dmitri Pal wrote: On

Re: [Freeipa-devel] [PATCH] 236 Log unhandled exceptions in certificate renewal scripts

2014-03-10 Thread Petr Viktorin
On 03/10/2014 11:23 AM, Jan Cholasta wrote: On 28.1.2014 14:44, Petr Viktorin wrote: On 01/23/2014 03:47 PM, Jan Cholasta wrote: Hi, the attached patch fixes https://fedorahosted.org/freeipa/ticket/4093. Honza This needs a rebase for the new LDAP API. Fixed and rebased on top of current

Re: [Freeipa-devel] FreeIPA ConnId connector for usage with Apache Syncope

2014-03-10 Thread Dmitri Pal
On 03/10/2014 08:24 AM, Petr Viktorin wrote: On 03/07/2014 04:39 PM, Marco Di Sabatino Di Diodoro wrote: Hi all, Il giorno 03/feb/2014, alle ore 11:41, Francesco Chicchiriccò ilgro...@apache.org mailto:ilgro...@apache.org ha scritto: On 31/01/2014 18:57, Dmitri Pal wrote: On 01/31/2014

Re: [Freeipa-devel] FreeIPA ConnId connector for usage with Apache Syncope

2014-03-10 Thread Petr Viktorin
On 03/10/2014 07:17 PM, Dmitri Pal wrote: On 03/10/2014 08:24 AM, Petr Viktorin wrote: On 03/07/2014 04:39 PM, Marco Di Sabatino Di Diodoro wrote: Hi all, Il giorno 03/feb/2014, alle ore 11:41, Francesco Chicchiriccò ilgro...@apache.org mailto:ilgro...@apache.org ha scritto: On 31/01/2014

Re: [Freeipa-devel] [PATCH] 1106 IPA REST smart proxy

2014-03-10 Thread Rob Crittenden
Petr Viktorin wrote: On 02/27/2014 10:18 PM, Rob Crittenden wrote: Rob Crittenden wrote: Updated patch based on feedback from Foreman team. I added a new URI, /features, which Foreman uses to determine what capabilities a proxy has. rob On my VMs, where the first request is handled properly

Re: [Freeipa-devel] [PATCH] 1106 IPA REST smart proxy

2014-03-10 Thread Rob Crittenden
Rob Crittenden wrote: Petr Viktorin wrote: On 02/27/2014 10:18 PM, Rob Crittenden wrote: Rob Crittenden wrote: Updated patch based on feedback from Foreman team. I added a new URI, /features, which Foreman uses to determine what capabilities a proxy has. rob On my VMs, where the first

Re: [Freeipa-devel] FreeIPA ConnId connector for usage with Apache Syncope

2014-03-10 Thread Dmitri Pal
On 03/10/2014 03:14 PM, Petr Viktorin wrote: On 03/10/2014 07:17 PM, Dmitri Pal wrote: On 03/10/2014 08:24 AM, Petr Viktorin wrote: On 03/07/2014 04:39 PM, Marco Di Sabatino Di Diodoro wrote: Hi all, Il giorno 03/feb/2014, alle ore 11:41, Francesco Chicchiriccò ilgro...@apache.org