Re: [Freeipa-devel] [PATCHES] 0536-0537 Add ACI for read-only admin attributes

2014-04-24 Thread Petr Viktorin
On 04/23/2014 08:56 PM, Simo Sorce wrote: On Wed, 2014-04-23 at 20:37 +0200, Petr Viktorin wrote: Admin access to read-only attributes such as ipaUniqueId, memberOf, krbPrincipalName is provided by the anonymous read ACI, which will go away. This patch adds a blanket read ACI for these. I also

Re: [Freeipa-devel] [PATCHES] 0532-0533 Extend anonymous read ACI for containers

2014-04-24 Thread Martin Kosek
On 04/22/2014 01:07 PM, Petr Viktorin wrote: On 04/18/2014 04:17 PM, Simo Sorce wrote: On Fri, 2014-04-18 at 16:11 +0200, Martin Kosek wrote: On 04/18/2014 04:07 PM, Simo Sorce wrote: On Fri, 2014-04-18 at 15:49 +0200, Martin Kosek wrote: On 04/18/2014 03:43 PM, Simo Sorce wrote: On Fri,

Re: [Freeipa-devel] Draft: Read permissions for user

2014-04-24 Thread Martin Kosek
On 04/23/2014 10:53 PM, Martin Kosek wrote: On 04/23/2014 08:07 PM, Simo Sorce wrote: On Wed, 2014-04-23 at 18:19 +0200, Martin Kosek wrote: On 04/23/2014 05:21 PM, Simo Sorce wrote: On Wed, 2014-04-23 at 16:37 +0200, Martin Kosek wrote: On 04/17/2014 01:45 PM, Petr Viktorin wrote: On

Re: [Freeipa-devel] [PATCH] 0520 Add managed read permission to service

2014-04-24 Thread Martin Kosek
On 04/23/2014 02:22 PM, Petr Viktorin wrote: On 04/14/2014 01:04 PM, Petr Viktorin wrote: Read access is given to all authenticated users. Exposed attributes are: [top] objectClass [ipaObject] ipaUniqueID [ipaService] managedBy memberOf ipaKrbAuthzData (a.k.a. pac_type)

[Freeipa-devel] Check out my profile on LinkedIn

2014-04-24 Thread Mohammad Reza Moeini
LinkedIn I'd like to include you in my network to share updates and stay in touch. - Mohammad Reza Mohammad Reza Moeini Unix/Linux Administrator at it's not about your bessiness (secret) Iran Confirm that you know Mohammad Reza Moeini:

Re: [Freeipa-devel] [PATCHES] 0534-0535 Add several managed read permissions under cn=etc

2014-04-24 Thread Martin Kosek
On 04/23/2014 02:48 PM, Simo Sorce wrote: On Wed, 2014-04-23 at 13:42 +0200, Petr Viktorin wrote: This adds managed read permissions to cn=etc. Since these permissions are not bound to objects, the first patch adds support for those. They're defined in the update plugin. The second patch

Re: [Freeipa-devel] [PATCHES] 0536-0537 Add ACI for read-only admin attributes

2014-04-24 Thread Martin Kosek
On 04/24/2014 09:41 AM, Petr Viktorin wrote: On 04/23/2014 08:56 PM, Simo Sorce wrote: On Wed, 2014-04-23 at 20:37 +0200, Petr Viktorin wrote: Admin access to read-only attributes such as ipaUniqueId, memberOf, krbPrincipalName is provided by the anonymous read ACI, which will go away. This

Re: [Freeipa-devel] [PATCHES] 0534-0535 Add several managed read permissions under cn=etc

2014-04-24 Thread Simo Sorce
On Thu, 2014-04-24 at 13:53 +0200, Martin Kosek wrote: On 04/23/2014 02:48 PM, Simo Sorce wrote: On Wed, 2014-04-23 at 13:42 +0200, Petr Viktorin wrote: This adds managed read permissions to cn=etc. Since these permissions are not bound to objects, the first patch adds support for those.

Re: [Freeipa-devel] [PATCHES] 0536-0537 Add ACI for read-only admin attributes

2014-04-24 Thread Simo Sorce
On Thu, 2014-04-24 at 14:17 +0200, Martin Kosek wrote: On 04/24/2014 09:41 AM, Petr Viktorin wrote: On 04/23/2014 08:56 PM, Simo Sorce wrote: On Wed, 2014-04-23 at 20:37 +0200, Petr Viktorin wrote: Admin access to read-only attributes such as ipaUniqueId, memberOf, krbPrincipalName is

Re: [Freeipa-devel] [PATCHES] 0534-0535 Add several managed read permissions under cn=etc

2014-04-24 Thread Martin Kosek
On 04/24/2014 02:24 PM, Simo Sorce wrote: On Thu, 2014-04-24 at 13:53 +0200, Martin Kosek wrote: On 04/23/2014 02:48 PM, Simo Sorce wrote: On Wed, 2014-04-23 at 13:42 +0200, Petr Viktorin wrote: This adds managed read permissions to cn=etc. Since these permissions are not bound to objects,

Re: [Freeipa-devel] [PATCH] 14 webui: select all checkbox remains selected after operation

2014-04-24 Thread Misnyovszki Adam
On Wed, 23 Apr 2014 16:57:35 +0200 Petr Vobornik pvobo...@redhat.com wrote: On 18.4.2014 10:43, Misnyovszki Adam wrote: Hi, this patch fixes select_all checkbox issue, after any bulk modify or delete operation, the checkbox is deselected. https://fedorahosted.org/freeipa/ticket/4245

Re: [Freeipa-devel] [PATCHES] 0536-0537 Add ACI for read-only admin attributes

2014-04-24 Thread Martin Kosek
On 04/24/2014 02:28 PM, Simo Sorce wrote: On Thu, 2014-04-24 at 14:17 +0200, Martin Kosek wrote: On 04/24/2014 09:41 AM, Petr Viktorin wrote: On 04/23/2014 08:56 PM, Simo Sorce wrote: On Wed, 2014-04-23 at 20:37 +0200, Petr Viktorin wrote: Admin access to read-only attributes such as

Re: [Freeipa-devel] [PATCHES] 0536-0537 Add ACI for read-only admin attributes

2014-04-24 Thread Petr Viktorin
On 04/24/2014 03:18 PM, Martin Kosek wrote: On 04/24/2014 02:28 PM, Simo Sorce wrote: On Thu, 2014-04-24 at 14:17 +0200, Martin Kosek wrote: On 04/24/2014 09:41 AM, Petr Viktorin wrote: On 04/23/2014 08:56 PM, Simo Sorce wrote: On Wed, 2014-04-23 at 20:37 +0200, Petr Viktorin wrote: Admin

Re: [Freeipa-devel] [PATCHES] 0536-0537 Add ACI for read-only admin attributes

2014-04-24 Thread Simo Sorce
On Thu, 2014-04-24 at 15:18 +0200, Martin Kosek wrote: On 04/24/2014 02:28 PM, Simo Sorce wrote: On Thu, 2014-04-24 at 14:17 +0200, Martin Kosek wrote: On 04/24/2014 09:41 AM, Petr Viktorin wrote: On 04/23/2014 08:56 PM, Simo Sorce wrote: On Wed, 2014-04-23 at 20:37 +0200, Petr Viktorin

[Freeipa-devel] First beta release of ConnID FreeIPA connector

2014-04-24 Thread Massimiliano Perrone (tirasa.net)
Hi guys, this mail only to share with you that ConnID FreeIPA connector (beta version) is released. You can find more informations here [1] Massimiliano [1] http://blog.tirasa.net/unlock-full-freeipa-features.html -- Massimiliano Perrone Tel +39 393 9121310 Tirasa S.r.l. Viale D'Annunzio

Re: [Freeipa-devel] [PATCHES] 0536-0537 Add ACI for read-only admin attributes

2014-04-24 Thread Martin Kosek
On 04/24/2014 03:42 PM, Simo Sorce wrote: On Thu, 2014-04-24 at 15:18 +0200, Martin Kosek wrote: On 04/24/2014 02:28 PM, Simo Sorce wrote: On Thu, 2014-04-24 at 14:17 +0200, Martin Kosek wrote: On 04/24/2014 09:41 AM, Petr Viktorin wrote: On 04/23/2014 08:56 PM, Simo Sorce wrote: On Wed,

Re: [Freeipa-devel] [PATCHES] 0536-0537 Add ACI for read-only admin attributes

2014-04-24 Thread Simo Sorce
On Thu, 2014-04-24 at 16:47 +0200, Martin Kosek wrote: On 04/24/2014 03:42 PM, Simo Sorce wrote: On Thu, 2014-04-24 at 15:18 +0200, Martin Kosek wrote: On 04/24/2014 02:28 PM, Simo Sorce wrote: On Thu, 2014-04-24 at 14:17 +0200, Martin Kosek wrote: On 04/24/2014 09:41 AM, Petr Viktorin

Re: [Freeipa-devel] [PATCHES] 241-253 CA certificate renewal

2014-04-24 Thread Rob Crittenden
Jan Cholasta wrote: On 10.4.2014 22:06, Rob Crittenden wrote: Some in-line, a whole ton of data appended to end. Jan Cholasta wrote: On 7.4.2014 20:09, Rob Crittenden wrote: Rob Crittenden wrote: 242 I wonder if it would be clearer to use variables instead of a raw list in the return

Re: [Freeipa-devel] First beta release of ConnID FreeIPA connector

2014-04-24 Thread Dmitri Pal
On 04/24/2014 09:58 AM, Massimiliano Perrone (tirasa.net) wrote: Hi guys, this mail only to share with you that ConnID FreeIPA connector (beta version) is released. You can find more informations here [1] Massimiliano [1] http://blog.tirasa.net/unlock-full-freeipa-features.html Cool! It