Re: [Freeipa-devel] [PATCH 0042] Removed dead code from LDAPRemoveReverseMember

2016-06-07 Thread Jan Cholasta
On 6.6.2016 18:29, Martin Basti wrote: On 03.06.2016 14:28, Stanislav Laznicka wrote: On 06/03/2016 02:19 PM, Martin Basti wrote: On 03.06.2016 14:13, Stanislav Laznicka wrote: https://fedorahosted.org/freeipa/ticket/5892 NACK please remove it from LDAPAddReverseMember too, it contains

Re: [Freeipa-devel] [PATCH 0497] Py3: fix unicode/str error in LDAP*ReverseMember

2016-06-07 Thread Jan Cholasta
On 6.6.2016 14:33, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/5923 Patch attached. Could we drop the error message parsing and do something sane instead? -- Jan Cholasta -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/f

Re: [Freeipa-devel] [PATCH] 0042: Fix bad searching of reverse DNS zone

2016-06-07 Thread Petr Spacek
Hi, the commit message does not say what was wrong and why and what works now. Please improve the commit message before pushing this. Petr^2 Spacek On 6.6.2016 19:03, Pavel Vomacka wrote: > Fix bad searching of reverse DNS zone > > https://fedorahosted.org/freeipa/ticket/5796 > > -- > > Pave

Re: [Freeipa-devel] [PATCH] 0039-40: DNS Location: WebUI

2016-06-07 Thread Pavel Vomacka
On 06/06/2016 07:51 PM, Martin Basti wrote: On 05.06.2016 18:34, Pavel Vomacka wrote: Hello, please review attached patches which add WebUI part of DNS Locations feature. -- Pavel^3 Vomacka NACK 1) When I edit location description and click on revert button, then that nice locatio

[Freeipa-devel] [PATCH 0043] Stop uninstaller from failing if a service can't be started

2016-06-07 Thread Stanislav Laznicka
https://fedorahosted.org/freeipa/ticket/5775 From 8ba87072d8e998ccb8743390eb541e74f6b1aa96 Mon Sep 17 00:00:00 2001 From: Stanislav Laznicka Date: Tue, 7 Jun 2016 10:08:45 +0200 Subject: [PATCH] Uninstaller won't fail if service can't be started https://fedorahosted.org/freeipa/ticket/5775 ---

[Freeipa-devel] thin client regressions: otptoken

2016-06-07 Thread Alexander Bokovoy
ipa: ERROR: AttributeError: 'str' object has no attribute 'decode' Traceback (most recent call last): File "/usr/lib/python3.5/site-packages/ipalib/cli.py", line 1345, in run sys.exit(api.Backend.cli.run(argv)) File "/usr/lib/python3.5/site-packages/ipalib/cli.py", line 1110, in run rv = c

Re: [Freeipa-devel] thin client regressions: otptoken

2016-06-07 Thread Jan Cholasta
On 7.6.2016 10:17, Alexander Bokovoy wrote: ipa: ERROR: AttributeError: 'str' object has no attribute 'decode' Traceback (most recent call last): File "/usr/lib/python3.5/site-packages/ipalib/cli.py", line 1345, in run sys.exit(api.Backend.cli.run(argv)) File "/usr/lib/python3.5/site-package

Re: [Freeipa-devel] [PATCH 0042] Removed dead code from LDAPRemoveReverseMember

2016-06-07 Thread Martin Basti
On 07.06.2016 09:07, Jan Cholasta wrote: On 6.6.2016 18:29, Martin Basti wrote: On 03.06.2016 14:28, Stanislav Laznicka wrote: On 06/03/2016 02:19 PM, Martin Basti wrote: On 03.06.2016 14:13, Stanislav Laznicka wrote: https://fedorahosted.org/freeipa/ticket/5892 NACK please remove it

Re: [Freeipa-devel] [PATCH] 0042: Fix bad searching of reverse DNS zone

2016-06-07 Thread Pavel Vomacka
On 06/07/2016 09:08 AM, Petr Spacek wrote: Hi, the commit message does not say what was wrong and why and what works now. Please improve the commit message before pushing this. Commit message improved. Petr^2 Spacek On 6.6.2016 19:03, Pavel Vomacka wrote: Fix bad searching of reverse DNS

Re: [Freeipa-devel] [PATCH 0497] Py3: fix unicode/str error in LDAP*ReverseMember

2016-06-07 Thread Martin Basti
On 07.06.2016 09:08, Jan Cholasta wrote: On 6.6.2016 14:33, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/5923 Patch attached. Could we drop the error message parsing and do something sane instead? Not now, we can do it later and push this patch just as workaround -- Manag

Re: [Freeipa-devel] [PATCH 0497] Py3: fix unicode/str error in LDAP*ReverseMember

2016-06-07 Thread Jan Cholasta
On 7.6.2016 10:29, Martin Basti wrote: On 07.06.2016 09:08, Jan Cholasta wrote: On 6.6.2016 14:33, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/5923 Patch attached. Could we drop the error message parsing and do something sane instead? Not now, we can do it later and push

Re: [Freeipa-devel] [PATCH 0497] Py3: fix unicode/str error in LDAP*ReverseMember

2016-06-07 Thread Martin Basti
On 07.06.2016 10:35, Jan Cholasta wrote: On 7.6.2016 10:29, Martin Basti wrote: On 07.06.2016 09:08, Jan Cholasta wrote: On 6.6.2016 14:33, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/5923 Patch attached. Could we drop the error message parsing and do something sane inst

Re: [Freeipa-devel] [PATCH 0042] Removed dead code from LDAPRemoveReverseMember

2016-06-07 Thread Jan Cholasta
On 7.6.2016 10:22, Martin Basti wrote: On 07.06.2016 09:07, Jan Cholasta wrote: On 6.6.2016 18:29, Martin Basti wrote: On 03.06.2016 14:28, Stanislav Laznicka wrote: On 06/03/2016 02:19 PM, Martin Basti wrote: On 03.06.2016 14:13, Stanislav Laznicka wrote: https://fedorahosted.org/freei

Re: [Freeipa-devel] thin client regressions: otptoken

2016-06-07 Thread Alexander Bokovoy
On Tue, 07 Jun 2016, Jan Cholasta wrote: On 7.6.2016 10:17, Alexander Bokovoy wrote: ipa: ERROR: AttributeError: 'str' object has no attribute 'decode' Traceback (most recent call last): File "/usr/lib/python3.5/site-packages/ipalib/cli.py", line 1345, in run sys.exit(api.Backend.cli.run(argv)

Re: [Freeipa-devel] [PATCH 0042] Removed dead code from LDAPRemoveReverseMember

2016-06-07 Thread Martin Basti
On 07.06.2016 10:43, Jan Cholasta wrote: On 7.6.2016 10:22, Martin Basti wrote: On 07.06.2016 09:07, Jan Cholasta wrote: On 6.6.2016 18:29, Martin Basti wrote: On 03.06.2016 14:28, Stanislav Laznicka wrote: On 06/03/2016 02:19 PM, Martin Basti wrote: On 03.06.2016 14:13, Stanislav Laz

Re: [Freeipa-devel] [PATCHES 0146-0152] Server Roles v2

2016-06-07 Thread Martin Babinsky
On 06/03/2016 05:25 PM, Martin Babinsky wrote: I am sending rebased patches implementing http://www.freeipa.org/page/V4/Server_Roles I hope the patches work since I have had a lot of fun rebasing them on top of thin client and DNS locations effort. https://fedorahosted.org/freeipa/ticket/5181

[Freeipa-devel] [PATCH 0403-0407] Preparation work for per-server config in LDAP

2016-06-07 Thread Petr Spacek
Hello, this patch set is preparation work for per-server config in LDAP, which is required for DNS location in IPA. This patch set should not cause any user-visible changes. https://fedorahosted.org/bind-dyndb-ldap/ticket/162 -- Petr^2 Spacek From 5a4e0b7026dc4f7f786d1d59a3a9ad33bfe89e30 Mon S

Re: [Freeipa-devel] [PATCH 0492] Translations: update ipa-4-3 translations

2016-06-07 Thread Martin Babinsky
On 06/01/2016 05:10 PM, Martin Basti wrote: Patch attached. ACK -- Martin^3 Babinsky -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Re: [Freeipa-devel] [PATCH 0499] Pylint: exclude some files/dirs from check

2016-06-07 Thread Pavel Vomacka
On 06/06/2016 04:26 PM, Martin Basti wrote: See commit message, yacctab.py causes lint errors and must be excluded Patch attached. Works well, ACK. -- Pavel^3 Vomacka -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Co

Re: [Freeipa-devel] ipapwd_extop vs password_extop

2016-06-07 Thread thierry bordaz
On 06/06/2016 07:12 PM, Alexander Bokovoy wrote: On Mon, 06 Jun 2016, thierry bordaz wrote: On 06/06/2016 11:07 AM, Alexander Bokovoy wrote: On Mon, 06 Jun 2016, thierry bordaz wrote: Hello, In DS it is possible to register callbacks for extended op. For https://www.ietf.org/rfc/rfc3062

Re: [Freeipa-devel] ipapwd_extop vs password_extop

2016-06-07 Thread Alexander Bokovoy
On Tue, 07 Jun 2016, thierry bordaz wrote: On 06/06/2016 07:12 PM, Alexander Bokovoy wrote: On Mon, 06 Jun 2016, thierry bordaz wrote: On 06/06/2016 11:07 AM, Alexander Bokovoy wrote: On Mon, 06 Jun 2016, thierry bordaz wrote: Hello, In DS it is possible to register callbacks for extende

Re: [Freeipa-devel] [PATCH 0499] Pylint: exclude some files/dirs from check

2016-06-07 Thread Martin Basti
On 07.06.2016 12:58, Pavel Vomacka wrote: On 06/06/2016 04:26 PM, Martin Basti wrote: See commit message, yacctab.py causes lint errors and must be excluded Patch attached. Works well, ACK. -- Pavel^3 Vomacka Pushed to master: 1d9425dab7b16a0c518dadc5ba42c027045c4529 -- Manage y

Re: [Freeipa-devel] [PATCH] 0003 batch command can be used to trigger internal errors on server

2016-06-07 Thread Stanislav Laznicka
Hello, Thank you for your patch. As the thin-client patches were pushed in the meantime, the patch won't apply. Could you please send a rebased version? Also, I have a few comments to the patch: 1) I think that the commit message should be rather a brief conclusion to the changes made in the

Re: [Freeipa-devel] ipapwd_extop vs password_extop

2016-06-07 Thread thierry bordaz
On 06/07/2016 01:20 PM, Alexander Bokovoy wrote: On Tue, 07 Jun 2016, thierry bordaz wrote: On 06/06/2016 07:12 PM, Alexander Bokovoy wrote: On Mon, 06 Jun 2016, thierry bordaz wrote: On 06/06/2016 11:07 AM, Alexander Bokovoy wrote: On Mon, 06 Jun 2016, thierry bordaz wrote: Hello, In

Re: [Freeipa-devel] ipapwd_extop vs password_extop

2016-06-07 Thread Alexander Bokovoy
On Tue, 07 Jun 2016, thierry bordaz wrote: Well here we have IPA password extop that receives a 'compat' entry. This compat entry does not exist except in slapi-nis that can do the mapping to the real entry. What I was thinking of was some kind of call from IPA password extop to slapi-nis that

Re: [Freeipa-devel] ipapwd_extop vs password_extop

2016-06-07 Thread thierry bordaz
On 06/07/2016 03:47 PM, Alexander Bokovoy wrote: On Tue, 07 Jun 2016, thierry bordaz wrote: Well here we have IPA password extop that receives a 'compat' entry. This compat entry does not exist except in slapi-nis that can do the mapping to the real entry. What I was thinking of was some kin

Re: [Freeipa-devel] [PATCH] 0201 Add support for an external trust to Active Directory domain

2016-06-07 Thread Martin Babinsky
On 06/06/2016 12:33 PM, Alexander Bokovoy wrote: Hi, this patch adds support for external trust to Active Directory. External trust is a trust that can be created between Active Directory domains that are in different forests or between an Active Directory domain. Since FreeIPA does not support

Re: [Freeipa-devel] [PATCH] 0005 Always qualify requests for admin in ipa-replica-conncheck

2016-06-07 Thread Florence Blanc-Renaud
On 06/06/2016 07:18 PM, Martin Basti wrote: On 02.06.2016 14:58, Florence Blanc-Renaud wrote: Hi, this patch modifies ipa-replica-conncheck when it performs the SSH connection to the master, so that the username is always fully qualified. https://fedorahosted.org/freeipa/ticket/5812 -- F

Re: [Freeipa-devel] [PATCH] 0202 support UPNs for trusted domain users

2016-06-07 Thread Martin Babinsky
On 06/06/2016 12:34 PM, Alexander Bokovoy wrote: Hi, Add support for additional user name principal suffixes from trusted Active Directory forests. UPN suffixes are property of the forest and as such are associated with the forest root domain. FreeIPA stores UPN suffixes as ipaNTAdditionalSuffi

Re: [Freeipa-devel] [PATCH] 0201 Add support for an external trust to Active Directory domain

2016-06-07 Thread Alexander Bokovoy
On Tue, 07 Jun 2016, Martin Babinsky wrote: On 06/06/2016 12:33 PM, Alexander Bokovoy wrote: Hi, this patch adds support for external trust to Active Directory. External trust is a trust that can be created between Active Directory domains that are in different forests or between an Active Dir

Re: [Freeipa-devel] [PATCH] 0005 Always qualify requests for admin in ipa-replica-conncheck

2016-06-07 Thread Martin Basti
On 07.06.2016 17:25, Florence Blanc-Renaud wrote: On 06/06/2016 07:18 PM, Martin Basti wrote: On 02.06.2016 14:58, Florence Blanc-Renaud wrote: Hi, this patch modifies ipa-replica-conncheck when it performs the SSH connection to the master, so that the username is always fully qualifie

Re: [Freeipa-devel] [PATCH] 0201 Add support for an external trust to Active Directory domain

2016-06-07 Thread Martin Babinsky
On 06/07/2016 06:00 PM, Alexander Bokovoy wrote: On Tue, 07 Jun 2016, Martin Babinsky wrote: On 06/06/2016 12:33 PM, Alexander Bokovoy wrote: Hi, this patch adds support for external trust to Active Directory. External trust is a trust that can be created between Active Directory domains that

Re: [Freeipa-devel] [PATCH] 0202 support UPNs for trusted domain users

2016-06-07 Thread Alexander Bokovoy
On Tue, 07 Jun 2016, Martin Babinsky wrote: On 06/06/2016 12:34 PM, Alexander Bokovoy wrote: Hi, Add support for additional user name principal suffixes from trusted Active Directory forests. UPN suffixes are property of the forest and as such are associated with the forest root domain. FreeIP

[Freeipa-devel] [PATCH] 0206 adtrust optimize forest root LDAP filter

2016-06-07 Thread Alexander Bokovoy
Hi, `ipa trust-find' command should only show trusted forest root domains The child domains should be visible via ipa trustdomain-find forest.root The difference between forest root (or external domain) and child domains is that root domain gets ipaIDObject class to allow assigning a POSIX I

Re: [Freeipa-devel] [PATCH] 0201 Add support for an external trust to Active Directory domain

2016-06-07 Thread Alexander Bokovoy
On Tue, 07 Jun 2016, Martin Babinsky wrote: Again, we only require contributors to follow PEP8 when adding new code/directly touching old one. Please note that there are more serious transgressions than a couple of long lines that should _definitely_ be fixed (indentation errors, whitespace aro

Re: [Freeipa-devel] [PATCHES 0146-0152] Server Roles v2

2016-06-07 Thread Pavel Vomacka
On 06/07/2016 12:07 PM, Martin Babinsky wrote: On 06/03/2016 05:25 PM, Martin Babinsky wrote: I am sending rebased patches implementing http://www.freeipa.org/page/V4/Server_Roles I hope the patches work since I have had a lot of fun rebasing them on top of thin client and DNS locations effor

Re: [Freeipa-devel] [PATCH] 0202 support UPNs for trusted domain users

2016-06-07 Thread Martin Babinsky
On 06/07/2016 06:38 PM, Alexander Bokovoy wrote: On Tue, 07 Jun 2016, Martin Babinsky wrote: On 06/06/2016 12:34 PM, Alexander Bokovoy wrote: Hi, Add support for additional user name principal suffixes from trusted Active Directory forests. UPN suffixes are property of the forest and as such a

Re: [Freeipa-devel] [PATCH] 0034: webui: Authentication indicators

2016-06-07 Thread Petr Vobornik
On 06/06/2016 08:33 PM, Pavel Vomacka wrote: > > > On 06/06/2016 07:03 PM, Petr Vobornik wrote: >> On 06/06/2016 12:27 PM, Pavel Vomacka wrote: >>> >>> On 06/02/2016 06:22 PM, Petr Vobornik wrote: On 06/01/2016 10:41 AM, Pavel Vomacka wrote: > On 05/27/2016 05:58 PM, Pavel Vomacka wrote:

Re: [Freeipa-devel] [PATCH] 0202 support UPNs for trusted domain users

2016-06-07 Thread Alexander Bokovoy
On Tue, 07 Jun 2016, Martin Babinsky wrote: On 06/07/2016 06:38 PM, Alexander Bokovoy wrote: On Tue, 07 Jun 2016, Martin Babinsky wrote: On 06/06/2016 12:34 PM, Alexander Bokovoy wrote: Hi, Add support for additional user name principal suffixes from trusted Active Directory forests. UPN suff

Re: [Freeipa-devel] [PATCH] 0201 Add support for an external trust to Active Directory domain

2016-06-07 Thread Alexander Bokovoy
On Tue, 07 Jun 2016, Alexander Bokovoy wrote: > del attrs['ipanttrusttype'] > +if attributes: > +del attrs['ipanttrustattributes'] > """ Updated patch is attached. Another update, forgot one space in the allow_behavior(). I also spent some tim

Re: [Freeipa-devel] [PATCH] 0059..0064 Lightweight sub-CAs

2016-06-07 Thread Fraser Tweedale
On Tue, Jun 07, 2016 at 03:42:22PM +1000, Fraser Tweedale wrote: > On Wed, Jun 01, 2016 at 02:51:04PM +1000, Fraser Tweedale wrote: > > Hi team, > > > > This patchset implements the 'ca' plugin for creating and managing > > lightweight sub-CAs, and updates the 'caacl' plugin and > > 'cert-request'

[Freeipa-devel] [PATCH] 0066 Load server plugins in certmonger renewal helper

2016-06-07 Thread Fraser Tweedale
Client/server plugin split apparently broke the certmonger renewal helper (https://fedorahosted.org/freeipa/ticket/5943). Please review attached patch - hopefully it is correct way to fix it. Thanks, Fraser From 88845c834534eb4bb3b3755cef4f3d4fbb1513b8 Mon Sep 17 00:00:00 2001 From: Fraser Tweeda