Re: [Freeipa-devel] [PATCH] Always record that pkicreate has been executed

2014-07-22 Thread Martin Kosek
On 07/21/2014 04:08 PM, David Kupka wrote: > https://fedorahosted.org/freeipa/ticket/2796 This works fine. It will help us remove some user frustration when stuck with partially installed Dogtag (JFTR, the cure is "pkidestroy -s CA -i pki-tomcat"). ACK. Pushed to: master: 41b057e38757c0acf1d6002

Re: [Freeipa-devel] FYI: Cert for https://www.freeipa.org/ is invalid

2014-07-22 Thread Martin Kosek
On 06/26/2014 10:39 AM, Martin Kosek wrote: > On 06/26/2014 07:28 AM, James wrote: >> I think it's kind of funny that the cert for: https://www.freeipa.org/ >> is invalid, particularly since this is a security product. >> >> In any case, feel free to forward to whoever maintains this in case >> som

Re: [Freeipa-devel] [PATCHES] 295-299 Allow changing chaining of the IPA CA certificate

2014-07-22 Thread Rob Crittenden
Rob Crittenden wrote: > Jan Cholasta wrote: >> On 2.7.2014 19:37, Jan Cholasta wrote: >>> On 2.7.2014 19:08, Rob Crittenden wrote: Trimming to respond to your questions. >> Not sure if this is related: >> # pki cert-find >> PKIException: Internal Server Error I'm pretty s

[Freeipa-devel] #4450: how to allow password migration?

2014-07-22 Thread Martin Kosek
Hello, I was thinking more about the solution to fix migration in FreeIPA 4.0 as proposed in https://fedorahosted.org/freeipa/ticket/4450#comment:6 and I realized it will be more complicated. Conditionally enabling nsslapd-allow-hashed-passwords in cn=config when migration mode is enabled is tric

[Freeipa-devel] [PATCH] 129 ipa-kdb: fix unit tests

2014-07-22 Thread Sumit Bose
Hi, it looks like the ipa-kdb unit test is broken. This patch tries to fix it. bye, Sumit From 5de7f5790d895251c7a22b6af804ac5c61c553c4 Mon Sep 17 00:00:00 2001 From: Sumit Bose Date: Tue, 22 Jul 2014 17:17:45 +0200 Subject: [PATCH] ipa-kdb: fix unit tests --- daemons/ipa-kdb/Makefile.am

Re: [Freeipa-devel] [PATCH] ipa trust-add command should be interactive

2014-07-22 Thread Gabe Alford
Forgot about --trust-secret. Here is an updated patch. On Mon, Jul 21, 2014 at 2:31 AM, Jan Cholasta wrote: > On 21.7.2014 10:28, Martin Kosek wrote: > >> On 07/21/2014 09:56 AM, Jan Cholasta wrote: >> >>> Hi, >>> >>> On 16.7.2014 05:48, Gabe Alford wrote: >>> Hello, Adds AD admi

Re: [Freeipa-devel] #4450: how to allow password migration?

2014-07-22 Thread Ludwig Krispenz
On 07/22/2014 05:01 PM, Martin Kosek wrote: Hello, I was thinking more about the solution to fix migration in FreeIPA 4.0 as proposed in https://fedorahosted.org/freeipa/ticket/4450#comment:6 and I realized it will be more complicated. Conditionally enabling nsslapd-allow-hashed-passwords in c