Re: [Freeipa-devel] [PATCH 0060] Incomplete ports for IPA AD Trust

2015-10-30 Thread Petr Spacek
On 30.10.2015 07:54, Alexander Bokovoy wrote: > On Thu, 29 Oct 2015, Gabe Alford wrote: >> Hello, >> >> Fix for https://fedorahosted.org/freeipa/ticket/5414 >> >> Thanks, >> >> Gabe > >> From 515582d66252521a3cbf6a6a48f33745bd788c86 Mon Sep 17 00:00:00 2001 >> From: Gabe >> Date: Thu, 29 Oct 2015

[Freeipa-devel] [PATCH 0338] Drop configure.jar file

2015-10-30 Thread Martin Basti
https://fedorahosted.org/freeipa/ticket/5144 Patch attached. From 9101589ee9236586e68db764c63255397c4b20dd Mon Sep 17 00:00:00 2001 From: Martin Basti Date: Tue, 27 Oct 2015 15:36:55 +0100 Subject: [PATCH] Drop configure.jar Configure.jar used to be used with firefox version < 10 which is not s

Re: [Freeipa-devel] [PATCH 0020-0021] some topology plugin fixes

2015-10-30 Thread Ludwig Krispenz
On 10/29/2015 01:28 PM, thierry bordaz wrote: On 10/23/2015 10:44 AM, Ludwig Krispenz wrote: Hi, the attached two patches address issues I found when testing ca management in the topology plugin Thanks for review, Ludwig Hi Ludwig, Patch 20 is good to me. I have one remark, you call ipa

Re: [Freeipa-devel] [PATCH 0020-0021] some topology plugin fixes

2015-10-30 Thread thierry bordaz
On 10/30/2015 09:57 AM, Ludwig Krispenz wrote: On 10/29/2015 01:28 PM, thierry bordaz wrote: On 10/23/2015 10:44 AM, Ludwig Krispenz wrote: Hi, the attached two patches address issues I found when testing ca management in the topology plugin Thanks for review, Ludwig Hi Ludwig, Patch 20

[Freeipa-devel] [PATCH 0060-0061] DNSSEC improvements in uninstaller

2015-10-30 Thread Petr Spacek
Hello, DNSSEC: on uninstall, do not restore OpenDNSSEC kasp.db if backup failed DNSSEC: improve log messages in uninstaller This is suitable for ipa-4-2 branch and newer. -- Petr^2 Spacek From b4618410c8f5c833f5828dd6196989e83df603b7 Mon Sep 17 00:00:00 2001 From: Petr Spacek Date: Fri, 30 Oct

Re: [Freeipa-devel] [draft] Fate of ipa-replica-manage and ipa-csreplica-manage tools

2015-10-30 Thread Martin Kosek
On 10/27/2015 04:40 PM, Ludwig Krispenz wrote: On 10/27/2015 03:54 PM, Petr Vobornik wrote: Both tools serve primarily for managing replication agreements and replicas. ipa-replica-manage also manages winsync agreements and DNA ranges. FreeIPA 4.3 will introduce managed topology which affects

Re: [Freeipa-devel] [PATCH 0060-0061] DNSSEC improvements in uninstaller

2015-10-30 Thread Martin Basti
On 30.10.2015 10:41, Petr Spacek wrote: Hello, DNSSEC: on uninstall, do not restore OpenDNSSEC kasp.db if backup failed DNSSEC: improve log messages in uninstaller This is suitable for ipa-4-2 branch and newer. NACK Please extract the list from for cycle to separate variable and do extend

Re: [Freeipa-devel] [PATCH 0060] Incomplete ports for IPA AD Trust

2015-10-30 Thread Alexander Bokovoy
On Fri, 30 Oct 2015, Petr Spacek wrote: On 30.10.2015 07:54, Alexander Bokovoy wrote: On Thu, 29 Oct 2015, Gabe Alford wrote: Hello, Fix for https://fedorahosted.org/freeipa/ticket/5414 Thanks, Gabe From 515582d66252521a3cbf6a6a48f33745bd788c86 Mon Sep 17 00:00:00 2001 From: Gabe Date: T

Re: [Freeipa-devel] [PATCH 0060] Incomplete ports for IPA AD Trust

2015-10-30 Thread Petr Spacek
On 30.10.2015 11:10, Alexander Bokovoy wrote: > On Fri, 30 Oct 2015, Petr Spacek wrote: >> On 30.10.2015 07:54, Alexander Bokovoy wrote: >>> On Thu, 29 Oct 2015, Gabe Alford wrote: Hello, Fix for https://fedorahosted.org/freeipa/ticket/5414 Thanks, Gabe >>> F

Re: [Freeipa-devel] [PATCH 0060-0061] DNSSEC improvements in uninstaller

2015-10-30 Thread Petr Spacek
On 30.10.2015 10:55, Martin Basti wrote: > > > On 30.10.2015 10:41, Petr Spacek wrote: >> Hello, >> >> DNSSEC: on uninstall, do not restore OpenDNSSEC kasp.db if backup failed >> DNSSEC: improve log messages in uninstaller >> >> This is suitable for ipa-4-2 branch and newer. >> > NACK > > Please

Re: [Freeipa-devel] [PATCH 0090] show optionally configured components in server-find/show command output

2015-10-30 Thread Martin Babinsky
On 10/26/2015 01:41 PM, Martin Babinsky wrote: On 10/22/2015 04:13 PM, Martin Basti wrote: On 22.10.2015 10:44, Martin Babinsky wrote: https://fedorahosted.org/freeipa/ticket/5181 Thank you for the patch. 1) +OPTIONAL_SERVICES = { +'DNS', +'CA', +'KRA', +'ADTRUST', +

Re: [Freeipa-devel] [PATCH 0061] Remove 50-lockout-policy.update file

2015-10-30 Thread Gabe Alford
Can do Alexander. Here is the updated patch. Gabe On Fri, Oct 30, 2015 at 12:56 AM, Alexander Bokovoy wrote: > On Thu, 29 Oct 2015, Gabe Alford wrote: > >> Hello, >> >> Fix for https://fedorahosted.org/freeipa/ticket/5418 >> > ACK but can you please add something like this in the commit messag

Re: [Freeipa-devel] [PATCH 0060-0061] DNSSEC improvements in uninstaller

2015-10-30 Thread Martin Basti
On 30.10.2015 11:16, Petr Spacek wrote: On 30.10.2015 10:55, Martin Basti wrote: On 30.10.2015 10:41, Petr Spacek wrote: Hello, DNSSEC: on uninstall, do not restore OpenDNSSEC kasp.db if backup failed DNSSEC: improve log messages in uninstaller This is suitable for ipa-4-2 branch and newer

Re: [Freeipa-devel] [PATCH 0020-0021] some topology plugin fixes

2015-10-30 Thread Martin Basti
On 30.10.2015 10:08, thierry bordaz wrote: On 10/30/2015 09:57 AM, Ludwig Krispenz wrote: On 10/29/2015 01:28 PM, thierry bordaz wrote: On 10/23/2015 10:44 AM, Ludwig Krispenz wrote: Hi, the attached two patches address issues I found when testing ca management in the topology plugin Tha

Re: [Freeipa-devel] [PATCH 0061] Remove 50-lockout-policy.update file

2015-10-30 Thread Alexander Bokovoy
On Fri, 30 Oct 2015, Gabe Alford wrote: From 24bcde6042d90322883350b5fd97aa41f2e4d77d Mon Sep 17 00:00:00 2001 From: Gabe Date: Fri, 30 Oct 2015 06:27:11 -0600 Subject: [PATCH] Remove 50-lockout-policy.update file Remove lockout policy update file because all currently supported versions have k

[Freeipa-devel] [PATCH 0339] ipa-csreplica-manage: disable connect/disconnect/del subcommands

2015-10-30 Thread Martin Basti
https://fedorahosted.org/freeipa/ticket/5405 Patch attached From 5b0ac9ea79ed657022cdca164eda3313e790aab6 Mon Sep 17 00:00:00 2001 From: Martin Basti Date: Fri, 30 Oct 2015 13:06:21 +0100 Subject: [PATCH] ipa-csreplica-manage: disable connect/disconnect/del with domain level > 0 * ipa-csrepli

Re: [Freeipa-devel] [PATCH 0061] Remove 50-lockout-policy.update file

2015-10-30 Thread Martin Basti
On 30.10.2015 13:57, Alexander Bokovoy wrote: On Fri, 30 Oct 2015, Gabe Alford wrote: From 24bcde6042d90322883350b5fd97aa41f2e4d77d Mon Sep 17 00:00:00 2001 From: Gabe Date: Fri, 30 Oct 2015 06:27:11 -0600 Subject: [PATCH] Remove 50-lockout-policy.update file Remove lockout policy update fil

Re: [Freeipa-devel] [PATCH 0339] ipa-csreplica-manage: disable connect/disconnect/del subcommands

2015-10-30 Thread Martin Babinsky
On 10/30/2015 02:09 PM, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/5405 Patch attached Hi Martin, NACK since I'm not a big fan of having (nearly) the same function defined in multiple modules: """ $ git grep -n 'def exit_on_managed_topology' install/tools/ipa-csreplica-m

[Freeipa-devel] [PATCH] ca-less tests updated - POC

2015-10-30 Thread Oleg Fayans
Hi, The following patches contain updates to ca-less integration tests. It's still a proof of concept: 2 tests still fail seemingly due to the change in target system logic (marked as xfail with "ask jcholast comment") The test output looks like this: $ ipa-run-tests test_integration/test_cal

[Freeipa-devel] [PATCH 0093] perform connectivity checks for all topology suffixes during node deletion

2015-10-30 Thread Martin Babinsky
patch for https://fedorahosted.org/freeipa/ticket/5309 The ticket itself is about connectivity checks in topology suffixes, but there is a code (install/tools/ipa-replica-manage starting at line 788 after applying my patch) which monitors whether the segments pointing to/from the deleted host

Re: [Freeipa-devel] [PATCH 0093] perform connectivity checks for all topology suffixes during node deletion

2015-10-30 Thread Petr Vobornik
On 10/30/2015 03:26 PM, Martin Babinsky wrote: patch for https://fedorahosted.org/freeipa/ticket/5309 The ticket itself is about connectivity checks in topology suffixes, but there is a code (install/tools/ipa-replica-manage starting at line 788 after applying my patch) which monitors whether th

Re: [Freeipa-devel] [PATCH 0339] ipa-csreplica-manage: disable connect/disconnect/del subcommands

2015-10-30 Thread Martin Basti
On 30.10.2015 14:49, Martin Babinsky wrote: On 10/30/2015 02:09 PM, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/5405 Patch attached Hi Martin, NACK since I'm not a big fan of having (nearly) the same function defined in multiple modules: """ $ git grep -n 'def exit_on_

Re: [Freeipa-devel] [PATCH 0339] ipa-csreplica-manage: disable connect/disconnect/del subcommands

2015-10-30 Thread Rob Crittenden
Martin Basti wrote: > > > On 30.10.2015 14:49, Martin Babinsky wrote: >> On 10/30/2015 02:09 PM, Martin Basti wrote: >>> https://fedorahosted.org/freeipa/ticket/5405 >>> >>> >>> Patch attached >>> >>> >> Hi Martin, >> >> NACK since I'm not a big fan of having (nearly) the same function >> defined

Re: [Freeipa-devel] [PATCH 0339] ipa-csreplica-manage: disable connect/disconnect/del subcommands

2015-10-30 Thread Martin Babinsky
On 10/30/2015 03:47 PM, Martin Basti wrote: On 30.10.2015 14:49, Martin Babinsky wrote: On 10/30/2015 02:09 PM, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/5405 Patch attached Hi Martin, NACK since I'm not a big fan of having (nearly) the same function defined in multipl

Re: [Freeipa-devel] [PATCH 0339] ipa-csreplica-manage: disable connect/disconnect/del subcommands

2015-10-30 Thread Martin Basti
On 30.10.2015 15:49, Rob Crittenden wrote: Martin Basti wrote: On 30.10.2015 14:49, Martin Babinsky wrote: On 10/30/2015 02:09 PM, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/5405 Patch attached Hi Martin, NACK since I'm not a big fan of having (nearly) the same functi

Re: [Freeipa-devel] [PATCH 0093] perform connectivity checks for all topology suffixes during node deletion

2015-10-30 Thread Martin Babinsky
On 10/30/2015 03:38 PM, Petr Vobornik wrote: On 10/30/2015 03:26 PM, Martin Babinsky wrote: patch for https://fedorahosted.org/freeipa/ticket/5309 The ticket itself is about connectivity checks in topology suffixes, but there is a code (install/tools/ipa-replica-manage starting at line 788 afte

Re: [Freeipa-devel] [draft] Fate of ipa-replica-manage and ipa-csreplica-manage tools

2015-10-30 Thread Petr Vobornik
On 10/30/2015 10:42 AM, Martin Kosek wrote: On 10/27/2015 04:40 PM, Ludwig Krispenz wrote: On 10/27/2015 03:54 PM, Petr Vobornik wrote: Both tools serve primarily for managing replication agreements and replicas. ipa-replica-manage also manages winsync agreements and DNA ranges. FreeIPA 4.3 w

Re: [Freeipa-devel] [PATCH 0060] Incomplete ports for IPA AD Trust

2015-10-30 Thread Gabe Alford
Okay. Added the port range to ipa-adtrust-install and updated the man page to reflect firewall requirements. The firewall section seems a little rough, so let me know what you think it would need to be smoothed over (if anything). thanks, Gabe On Fri, Oct 30, 2015 at 4:12 AM, Petr Spacek wrote: