Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Martin Basti
On 03/03/15 07:31, Jan Cholasta wrote: Dne 2.3.2015 v 13:51 Martin Basti napsal(a): On 02/03/15 13:12, Jan Cholasta wrote: Dne 2.3.2015 v 12:23 Martin Kosek napsal(a): On 03/02/2015 07:49 AM, Jan Cholasta wrote: Hi, Dne 24.2.2015 v 19:10 Martin Basti napsal(a): Hello all, please read the

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Jan Cholasta
Dne 3.3.2015 v 10:55 Martin Kosek napsal(a): On 03/03/2015 09:55 AM, Martin Basti wrote: On 03/03/15 09:33, Jan Cholasta wrote: Dne 3.3.2015 v 09:06 Martin Basti napsal(a): On 03/03/15 07:31, Jan Cholasta wrote: Dne 2.3.2015 v 13:51 Martin Basti napsal(a): On 02/03/15 13:12, Jan Cholasta

Re: [Freeipa-devel] [PATCHES 399-401] Allow multiple API instances

2015-03-03 Thread Tomas Babej
On 03/03/2015 04:01 PM, Martin Kosek wrote: On 03/03/2015 03:49 PM, Jan Cholasta wrote: Hi, the attached patches provide an attempt to fix https://fedorahosted.org/freeipa/ticket/3090. Patch 401 serves as an example and modifies ipa-advise to use its own API instance for Advice plugins.

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Simo Sorce
On Tue, 2015-03-03 at 10:04 -0500, Rob Crittenden wrote: Martin Basti wrote: On 03/03/15 15:33, Martin Kosek wrote: On 03/03/2015 03:16 PM, Simo Sorce wrote: On Mon, 2015-03-02 at 18:54 +0100, Martin Basti wrote: On 02/03/15 18:28, Martin Kosek wrote: On 03/02/2015 06:12 PM, Martin

Re: [Freeipa-devel] [PATCHES 399-401] Allow multiple API instances

2015-03-03 Thread Martin Kosek
On 03/03/2015 04:09 PM, Jan Cholasta wrote: Dne 3.3.2015 v 16:04 Tomas Babej napsal(a): On 03/03/2015 04:01 PM, Martin Kosek wrote: On 03/03/2015 03:49 PM, Jan Cholasta wrote: Hi, the attached patches provide an attempt to fix https://fedorahosted.org/freeipa/ticket/3090. Patch 401

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Rob Crittenden
Martin Basti wrote: On 03/03/15 15:33, Martin Kosek wrote: On 03/03/2015 03:16 PM, Simo Sorce wrote: On Mon, 2015-03-02 at 18:54 +0100, Martin Basti wrote: On 02/03/15 18:28, Martin Kosek wrote: On 03/02/2015 06:12 PM, Martin Basti wrote: On 02/03/15 15:43, Rob Crittenden wrote: Martin

Re: [Freeipa-devel] [PATCHES 399-401] Allow multiple API instances

2015-03-03 Thread Jan Cholasta
Dne 3.3.2015 v 16:04 Tomas Babej napsal(a): On 03/03/2015 04:01 PM, Martin Kosek wrote: On 03/03/2015 03:49 PM, Jan Cholasta wrote: Hi, the attached patches provide an attempt to fix https://fedorahosted.org/freeipa/ticket/3090. Patch 401 serves as an example and modifies ipa-advise to use

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Martin Basti
On 03/03/15 16:11, Simo Sorce wrote: On Tue, 2015-03-03 at 10:04 -0500, Rob Crittenden wrote: Martin Basti wrote: On 03/03/15 15:33, Martin Kosek wrote: On 03/03/2015 03:16 PM, Simo Sorce wrote: On Mon, 2015-03-02 at 18:54 +0100, Martin Basti wrote: On 02/03/15 18:28, Martin Kosek wrote:

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Martin Kosek
On 03/03/2015 04:43 PM, Martin Basti wrote: On 03/03/15 16:11, Simo Sorce wrote: On Tue, 2015-03-03 at 10:04 -0500, Rob Crittenden wrote: Martin Basti wrote: On 03/03/15 15:33, Martin Kosek wrote: On 03/03/2015 03:16 PM, Simo Sorce wrote: On Mon, 2015-03-02 at 18:54 +0100, Martin Basti

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Martin Basti
On 03/03/15 16:47, Martin Kosek wrote: On 03/03/2015 04:43 PM, Martin Basti wrote: On 03/03/15 16:11, Simo Sorce wrote: On Tue, 2015-03-03 at 10:04 -0500, Rob Crittenden wrote: Martin Basti wrote: On 03/03/15 15:33, Martin Kosek wrote: On 03/03/2015 03:16 PM, Simo Sorce wrote: On Mon,

Re: [Freeipa-devel] [PATCHES 399-401] Allow multiple API instances

2015-03-03 Thread Martin Kosek
On 03/03/2015 03:49 PM, Jan Cholasta wrote: Hi, the attached patches provide an attempt to fix https://fedorahosted.org/freeipa/ticket/3090. Patch 401 serves as an example and modifies ipa-advise to use its own API instance for Advice plugins. Honza Thanks. At least patches 399 and

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Martin Basti
On 03/03/15 16:10, Martin Kosek wrote: On 03/03/2015 04:04 PM, Rob Crittenden wrote: Martin Basti wrote: On 03/03/15 15:33, Martin Kosek wrote: On 03/03/2015 03:16 PM, Simo Sorce wrote: On Mon, 2015-03-02 at 18:54 +0100, Martin Basti wrote: On 02/03/15 18:28, Martin Kosek wrote: On

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Petr Spacek
On 3.3.2015 10:58, Martin Kosek wrote: On 03/03/2015 09:36 AM, Petr Spacek wrote: On 3.3.2015 09:33, Jan Cholasta wrote: Dne 3.3.2015 v 09:06 Martin Basti napsal(a): On 03/03/15 07:31, Jan Cholasta wrote: Dne 2.3.2015 v 13:51 Martin Basti napsal(a): On 02/03/15 13:12, Jan Cholasta wrote:

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Jan Cholasta
Dne 3.3.2015 v 11:04 Petr Spacek napsal(a): On 3.3.2015 10:58, Martin Kosek wrote: On 03/03/2015 09:36 AM, Petr Spacek wrote: On 3.3.2015 09:33, Jan Cholasta wrote: Dne 3.3.2015 v 09:06 Martin Basti napsal(a): On 03/03/15 07:31, Jan Cholasta wrote: Dne 2.3.2015 v 13:51 Martin Basti

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Martin Kosek
On 03/03/2015 11:06 AM, Jan Cholasta wrote: Dne 3.3.2015 v 11:04 Petr Spacek napsal(a): On 3.3.2015 10:58, Martin Kosek wrote: On 03/03/2015 09:36 AM, Petr Spacek wrote: On 3.3.2015 09:33, Jan Cholasta wrote: Dne 3.3.2015 v 09:06 Martin Basti napsal(a): On 03/03/15 07:31, Jan Cholasta wrote:

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Martin Basti
On 03/03/15 11:04, Petr Spacek wrote: On 3.3.2015 10:58, Martin Kosek wrote: On 03/03/2015 09:36 AM, Petr Spacek wrote: On 3.3.2015 09:33, Jan Cholasta wrote: Dne 3.3.2015 v 09:06 Martin Basti napsal(a): On 03/03/15 07:31, Jan Cholasta wrote: Dne 2.3.2015 v 13:51 Martin Basti napsal(a): On

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Martin Kosek
On 03/03/2015 09:36 AM, Petr Spacek wrote: On 3.3.2015 09:33, Jan Cholasta wrote: Dne 3.3.2015 v 09:06 Martin Basti napsal(a): On 03/03/15 07:31, Jan Cholasta wrote: Dne 2.3.2015 v 13:51 Martin Basti napsal(a): On 02/03/15 13:12, Jan Cholasta wrote: Dne 2.3.2015 v 12:23 Martin Kosek

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Jan Cholasta
Dne 3.3.2015 v 12:08 Martin Kosek napsal(a): On 03/03/2015 11:06 AM, Jan Cholasta wrote: Dne 3.3.2015 v 11:04 Petr Spacek napsal(a): On 3.3.2015 10:58, Martin Kosek wrote: On 03/03/2015 09:36 AM, Petr Spacek wrote: On 3.3.2015 09:33, Jan Cholasta wrote: Dne 3.3.2015 v 09:06 Martin Basti

Re: [Freeipa-devel] [PATCH 0001] ipa-client-install: attempt to get host TGT several times before aborting client installation

2015-03-03 Thread Rob Crittenden
Martin Babinsky wrote: On 03/02/2015 04:28 PM, Rob Crittenden wrote: Petr Vobornik wrote: On 01/12/2015 05:45 PM, Martin Babinsky wrote: related to ticket https://fedorahosted.org/freeipa/ticket/4808 this patch seems to be a bit forgotten. It works, looks fine. One minor issue: trailing

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Simo Sorce
On Mon, 2015-03-02 at 18:54 +0100, Martin Basti wrote: On 02/03/15 18:28, Martin Kosek wrote: On 03/02/2015 06:12 PM, Martin Basti wrote: On 02/03/15 15:43, Rob Crittenden wrote: Martin Basti wrote: ... But you haven't explained any case why LDAPI would fail. If LDAPI fails then

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Petr Spacek
On 3.3.2015 11:01, Jan Cholasta wrote: I would very much prefer to do it the other way around, so that most bugs in the code are caught early, instead of hidden behind the version comparison. +1 -- Petr^2 Spacek ___ Freeipa-devel mailing list

Re: [Freeipa-devel] [PATCH 0001] ipa-client-install: attempt to get host TGT several times before aborting client installation

2015-03-03 Thread Martin Babinsky
On 03/03/2015 02:32 PM, Rob Crittenden wrote: Martin Babinsky wrote: On 03/02/2015 04:28 PM, Rob Crittenden wrote: Petr Vobornik wrote: On 01/12/2015 05:45 PM, Martin Babinsky wrote: related to ticket https://fedorahosted.org/freeipa/ticket/4808 this patch seems to be a bit forgotten. It

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Jan Cholasta
Dne 3.3.2015 v 09:06 Martin Basti napsal(a): On 03/03/15 07:31, Jan Cholasta wrote: Dne 2.3.2015 v 13:51 Martin Basti napsal(a): On 02/03/15 13:12, Jan Cholasta wrote: Dne 2.3.2015 v 12:23 Martin Kosek napsal(a): On 03/02/2015 07:49 AM, Jan Cholasta wrote: Hi, Dne 24.2.2015 v 19:10 Martin

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Martin Basti
On 03/03/15 09:33, Jan Cholasta wrote: Dne 3.3.2015 v 09:06 Martin Basti napsal(a): On 03/03/15 07:31, Jan Cholasta wrote: Dne 2.3.2015 v 13:51 Martin Basti napsal(a): On 02/03/15 13:12, Jan Cholasta wrote: Dne 2.3.2015 v 12:23 Martin Kosek napsal(a): On 03/02/2015 07:49 AM, Jan Cholasta

Re: [Freeipa-devel] One-way trust design

2015-03-03 Thread Alexander Bokovoy
On Tue, 03 Mar 2015, Jan Pazdziora wrote: On Mon, Feb 23, 2015 at 06:02:53PM +0200, Alexander Bokovoy wrote: trust-related functionality would be limited to IPA admins or TDO object in LDAP would have to be more accessible. Given that TDO credentials can be used to compromise access to our

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Martin Kosek
On 03/03/2015 11:05 AM, Jan Cholasta wrote: Dne 3.3.2015 v 10:58 Martin Kosek napsal(a): On 03/03/2015 09:36 AM, Petr Spacek wrote: On 3.3.2015 09:33, Jan Cholasta wrote: Dne 3.3.2015 v 09:06 Martin Basti napsal(a): On 03/03/15 07:31, Jan Cholasta wrote: Dne 2.3.2015 v 13:51 Martin Basti

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Petr Spacek
On 3.3.2015 09:33, Jan Cholasta wrote: Dne 3.3.2015 v 09:06 Martin Basti napsal(a): On 03/03/15 07:31, Jan Cholasta wrote: Dne 2.3.2015 v 13:51 Martin Basti napsal(a): On 02/03/15 13:12, Jan Cholasta wrote: Dne 2.3.2015 v 12:23 Martin Kosek napsal(a): On 03/02/2015 07:49 AM, Jan Cholasta

Re: [Freeipa-devel] One-way trust design

2015-03-03 Thread Jan Pazdziora
On Mon, Feb 23, 2015 at 06:02:53PM +0200, Alexander Bokovoy wrote: trust-related functionality would be limited to IPA admins or TDO object in LDAP would have to be more accessible. Given that TDO credentials can be used to compromise access to our domain, it is not Could you clarify which

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Jan Cholasta
Dne 3.3.2015 v 10:58 Martin Kosek napsal(a): On 03/03/2015 09:36 AM, Petr Spacek wrote: On 3.3.2015 09:33, Jan Cholasta wrote: Dne 3.3.2015 v 09:06 Martin Basti napsal(a): On 03/03/15 07:31, Jan Cholasta wrote: Dne 2.3.2015 v 13:51 Martin Basti napsal(a): On 02/03/15 13:12, Jan Cholasta

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Jan Cholasta
Dne 3.3.2015 v 11:00 Martin Basti napsal(a): On 03/03/15 10:55, Jan Cholasta wrote: Dne 3.3.2015 v 09:55 Martin Basti napsal(a): On 03/03/15 09:33, Jan Cholasta wrote: Dne 3.3.2015 v 09:06 Martin Basti napsal(a): On 03/03/15 07:31, Jan Cholasta wrote: Dne 2.3.2015 v 13:51 Martin Basti

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Martin Kosek
On 03/03/2015 09:55 AM, Martin Basti wrote: On 03/03/15 09:33, Jan Cholasta wrote: Dne 3.3.2015 v 09:06 Martin Basti napsal(a): On 03/03/15 07:31, Jan Cholasta wrote: Dne 2.3.2015 v 13:51 Martin Basti napsal(a): On 02/03/15 13:12, Jan Cholasta wrote: Dne 2.3.2015 v 12:23 Martin Kosek

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Jan Cholasta
Dne 3.3.2015 v 09:55 Martin Basti napsal(a): On 03/03/15 09:33, Jan Cholasta wrote: Dne 3.3.2015 v 09:06 Martin Basti napsal(a): On 03/03/15 07:31, Jan Cholasta wrote: Dne 2.3.2015 v 13:51 Martin Basti napsal(a): On 02/03/15 13:12, Jan Cholasta wrote: Dne 2.3.2015 v 12:23 Martin Kosek

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Petr Spacek
On 2.3.2015 18:54, Martin Basti wrote: On 02/03/15 18:28, Martin Kosek wrote: On 03/02/2015 06:12 PM, Martin Basti wrote: On 02/03/15 15:43, Rob Crittenden wrote: Martin Basti wrote: ... But you haven't explained any case why LDAPI would fail. If LDAPI fails then you've got more serious

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Martin Basti
On 03/03/15 10:55, Jan Cholasta wrote: Dne 3.3.2015 v 09:55 Martin Basti napsal(a): On 03/03/15 09:33, Jan Cholasta wrote: Dne 3.3.2015 v 09:06 Martin Basti napsal(a): On 03/03/15 07:31, Jan Cholasta wrote: Dne 2.3.2015 v 13:51 Martin Basti napsal(a): On 02/03/15 13:12, Jan Cholasta wrote:

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Martin Kosek
On 03/03/2015 03:16 PM, Simo Sorce wrote: On Mon, 2015-03-02 at 18:54 +0100, Martin Basti wrote: On 02/03/15 18:28, Martin Kosek wrote: On 03/02/2015 06:12 PM, Martin Basti wrote: On 02/03/15 15:43, Rob Crittenden wrote: Martin Basti wrote: ... But you haven't explained any case why LDAPI

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Simo Sorce
On Tue, 2015-03-03 at 15:33 +0100, Martin Kosek wrote: On 03/03/2015 03:16 PM, Simo Sorce wrote: On Mon, 2015-03-02 at 18:54 +0100, Martin Basti wrote: On 02/03/15 18:28, Martin Kosek wrote: On 03/02/2015 06:12 PM, Martin Basti wrote: On 02/03/15 15:43, Rob Crittenden wrote: Martin

[Freeipa-devel] [PATCHES 399-401] Allow multiple API instances

2015-03-03 Thread Jan Cholasta
Hi, the attached patches provide an attempt to fix https://fedorahosted.org/freeipa/ticket/3090. Patch 401 serves as an example and modifies ipa-advise to use its own API instance for Advice plugins. Honza -- Jan Cholasta From 3715c9b4ca43eab6c5ad01b34cd1b14838241bde Mon Sep 17 00:00:00

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Simo Sorce
On Tue, 2015-03-03 at 15:40 +0100, Martin Basti wrote: On 03/03/15 15:33, Martin Kosek wrote: On 03/03/2015 03:16 PM, Simo Sorce wrote: On Mon, 2015-03-02 at 18:54 +0100, Martin Basti wrote: On 02/03/15 18:28, Martin Kosek wrote: On 03/02/2015 06:12 PM, Martin Basti wrote: On 02/03/15

Re: [Freeipa-devel] IPA Server upgrade 4.2 design

2015-03-03 Thread Martin Kosek
On 03/03/2015 03:49 PM, Simo Sorce wrote: On Tue, 2015-03-03 at 15:33 +0100, Martin Kosek wrote: On 03/03/2015 03:16 PM, Simo Sorce wrote: On Mon, 2015-03-02 at 18:54 +0100, Martin Basti wrote: On 02/03/15 18:28, Martin Kosek wrote: On 03/02/2015 06:12 PM, Martin Basti wrote: On 02/03/15