URL: https://github.com/freeipa/freeipa/pull/733
Author: stlaz
Title: #733: [4.5] Fix CA/server cert validation in FIPS
Action: opened
PR body:
"""
In FIPS, the NSS library needs to be passed passwords to perform
certificate validation. Should we not have passed it and the NSS
guys have not
URL: https://github.com/freeipa/freeipa/pull/702
Title: #702: Correct PyPI package dependencies
Label: +ack
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code
URL: https://github.com/freeipa/freeipa/pull/734
Author: pvoborni
Title: #734: kerberos session: use CA cert with full cert chain for obtaining
cookie
Action: opened
PR body:
"""
Http request performed in finalize_kerberos_acquisition doesn't use
CA certificate/certificate store with full
URL: https://github.com/freeipa/freeipa/pull/688
Title: #688: Update get_attr_filter in LDAPSearch to handle nsaccountlock user
searches
Label: +ack
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/688
Title: #688: Update get_attr_filter in LDAPSearch to handle nsaccountlock user
searches
Label: +pushed
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/688
Title: #688: Update get_attr_filter in LDAPSearch to handle nsaccountlock user
searches
HonzaCholasta commented:
"""
master:
* 38276d3473ecf2a4cc5b5e2a107347f046625626 Update get_attr_filter in LDAPSearch
to handle nsaccountlock user searches
URL: https://github.com/freeipa/freeipa/pull/688
Author: redhatrises
Title: #688: Update get_attr_filter in LDAPSearch to handle nsaccountlock user
searches
Action: closed
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa
URL: https://github.com/freeipa/freeipa/pull/702
Title: #702: Correct PyPI package dependencies
Label: +pushed
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/702
Title: #702: Correct PyPI package dependencies
MartinBasti commented:
"""
master:
* 26ab51ddf47f421f3404709052db89f08c05adaa Correct PyPI package dependencies
* 994d24d288080e924e039ca0a7b0b0dfc2355ac1 Band-aid for pip dependency bug
"""
See
On 25.04.2017 16:57, Martin Bašti wrote:
Hello all,
I'm going to implement automatic URI records for kdc proxy and I'd
like to clarify if following URI records are the right one.
_kerberos-adm.example.com. IN URI 0
"krb5srv:M:kkdcp:https://ipaserver.example.com/KdcProxy;
URL: https://github.com/freeipa/freeipa/pull/730
Title: #730: spec file: bump python-netaddr Requires
Label: +ack
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/702
Author: tiran
Title: #702: Correct PyPI package dependencies
Action: closed
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/702/head:pr702
git checkout pr702
--
Manage your
URL: https://github.com/freeipa/freeipa/pull/730
Title: #730: spec file: bump python-netaddr Requires
MartinBasti commented:
"""
If this should go into 4.5 please open a new PR
"""
See the full comment at
https://github.com/freeipa/freeipa/pull/730#issuecomment-297346926
--
Manage your
URL: https://github.com/freeipa/freeipa/pull/694
Author: martbab
Title: #694: RFC: implement local PKINIT deployment in server/replica install
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/694/head:pr694
URL: https://github.com/freeipa/freeipa/pull/730
Title: #730: spec file: bump python-netaddr Requires
MartinBasti commented:
"""
master:
* 0784e53f7f8a323acafbbff26a9d1c0276a229b0 spec file: bump python-netaddr
Requires
"""
See the full comment at
URL: https://github.com/freeipa/freeipa/pull/730
Author: HonzaCholasta
Title: #730: spec file: bump python-netaddr Requires
Action: closed
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/730/head:pr730
git checkout pr730
--
URL: https://github.com/freeipa/freeipa/pull/730
Title: #730: spec file: bump python-netaddr Requires
Label: +pushed
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/bind-dyndb-ldap/pull/17
Title: #17: settings: skip unconfigured values
Label: +ack
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/bind-dyndb-ldap/pull/17
Author: tomaskrizek
Title: #17: settings: skip unconfigured values
Action: closed
To pull the PR as Git branch:
git remote add ghbind-dyndb-ldap https://github.com/freeipa/bind-dyndb-ldap
git fetch ghbind-dyndb-ldap pull/17/head:pr17
git
URL: https://github.com/freeipa/bind-dyndb-ldap/pull/17
Title: #17: settings: skip unconfigured values
Label: +pushed
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/bind-dyndb-ldap/pull/17
Title: #17: settings: skip unconfigured values
tomaskrizek commented:
"""
master
- 41461fc444170ffd9b5459e2f0b2480f3288cc1d
- 7a67f77b66a680df1c21429e7c4e2dd001e86046
"""
See the full comment at
URL: https://github.com/freeipa/freeipa/pull/731
Author: HonzaCholasta
Title: #731: spec file: bump krb5 Requires for certauth fixes
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/731/head:pr731
git
URL: https://github.com/freeipa/freeipa/pull/735
Title: #735: automount install: do not wait for sssd restart on uninstallation
rcritten commented:
"""
I guess I have more issues with the commit message than the patch content. What
would you suggest ensure that sssd is up? A typical user
URL: https://github.com/freeipa/freeipa/pull/731
Author: HonzaCholasta
Title: #731: spec file: bump krb5 Requires for certauth fixes
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/731/head:pr731
git
URL: https://github.com/freeipa/freeipa/pull/735
Author: pvoborni
Title: #735: automount install: do not wait for sssd restart on uninstallation
Action: opened
PR body:
"""
Change in 2d4d1a9dc0ef2bbe86751768d6e6b009a52c0dc9 no longer initializes
api in `ipa-client-automount --uninstallation`
URL: https://github.com/freeipa/freeipa/pull/736
Author: felipevolpone
Title: #736: Fixing the cert-request command comparing whole email address
case-sensitively.
Action: opened
PR body:
"""
Now, the cert-request command compares the domain part of the email
case-insensitively.
Fixes:
New builds of 389 on F25 and F26 breaks server installation. Or at least
I think it's 389 issue on f26.
f25
https://bodhi.fedoraproject.org/updates/FEDORA-2017-8bb5a83e04
f26:
https://bodhi.fedoraproject.org/updates/FEDORA-2017-7f0a10c808
https://bugzilla.redhat.com/show_bug.cgi?id=1445776
--
URL: https://github.com/freeipa/freeipa/pull/694
Author: martbab
Title: #694: RFC: implement local PKINIT deployment in server/replica install
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/694/head:pr694
URL: https://github.com/freeipa/freeipa/pull/731
Title: #731: spec file: bump krb5 Requires for certauth fixes
Label: +ack
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA:
URL: https://github.com/freeipa/freeipa/pull/738
Author: pvoborni
Title: #738: restore: restart gssproxy after restore
Action: opened
PR body:
"""
So that gssproxy picks up new configuration and therefore related
usages like authentication of CLI against server works
URL: https://github.com/freeipa/freeipa/pull/738
Title: #738: restore: restart gssproxy after restore
simo5 commented:
"""
The name of the project is GSS-Proxy, the package name is gssproxy.
"""
See the full comment at
https://github.com/freeipa/freeipa/pull/738#issuecomment-297484796
--
URL: https://github.com/freeipa/freeipa/pull/731
Title: #731: spec file: bump krb5 Requires for certauth fixes
martbab commented:
"""
We will need a separate PR for ipa-4-5 branch.
"""
See the full comment at
https://github.com/freeipa/freeipa/pull/731#issuecomment-297455136
--
Manage your
URL: https://github.com/freeipa/freeipa/pull/735
Author: pvoborni
Title: #735: automount install: do not wait for sssd restart on uninstallation
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa
URL: https://github.com/freeipa/freeipa/pull/737
Author: tiran
Title: #737: Vault: Explicitly default to 3DES CBC
Action: opened
PR body:
"""
The server-side plugin for IPA Vault relied on the fact that the default
oid for encryption algorithm is 3DES in CBC mode (DES-EDE3-CBC). Dogtag
10.4
URL: https://github.com/freeipa/freeipa/pull/737
Title: #737: Vault: Explicitly default to 3DES CBC
tiran commented:
"""
* I haven't verified that the patch actually solves the problem
* Needs backport to at least 4.5
* Either needs backport to 4.4 or 4.4 must required Dogtag < 10.4
"""
See
URL: https://github.com/freeipa/freeipa/pull/737
Title: #737: Vault: Explicitly default to 3DES CBC
pvoborni commented:
"""
Should go to 4.4.5 unless pki-core-10.4.0-1 is removed from f25. Blocking new
Dogtag update in 4.4 doesn't seem right to me.
"""
See the full comment at
URL: https://github.com/freeipa/freeipa/pull/735
Author: pvoborni
Title: #735: automount install: do not wait for sssd restart on uninstallation
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa
URL: https://github.com/freeipa/freeipa/pull/735
Title: #735: automount install: do not wait for sssd restart on uninstallation
pvoborni commented:
"""
Thanks Rob, this reason for the wait didn't occurred to me. New patch changes
api initialization so that it works for both install and
URL: https://github.com/freeipa/freeipa/pull/729
Author: pvomacka
Title: #729: Turn on NSSOCSP check in mod_nss conf
Action: synchronized
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/729/head:pr729
git checkout pr729
From
On Wed, 2017-04-26 at 12:57 +0200, Martin Bašti wrote:
>
> On 25.04.2017 16:57, Martin Bašti wrote:
> > Hello all,
> >
> > I'm going to implement automatic URI records for kdc proxy and I'd
> > like to clarify if following URI records are the right one.
> >
> >
> > _kerberos-adm.example.com. IN
On Fri, 2017-04-21 at 10:17 +0200, Petr Vobornik wrote:
> On 04/21/2017 08:49 AM, Standa Laznicka wrote:
> > On 04/21/2017 08:12 AM, Abhijeet Kasurde wrote:
> >> +1
> >>
> >> On 20/04/17 9:36 PM, Petr Vobornik wrote:
> >>> Hi all,
> >>>
> >>> I'd like to improve quality of bug reports and RFEs.
>
URL: https://github.com/freeipa/freeipa/pull/738
Title: #738: restore: restart gssproxy after restore
simo5 commented:
"""
will a "systemctl reload gssproxy" do the right thing @frozencemetery ?
"""
See the full comment at
https://github.com/freeipa/freeipa/pull/738#issuecomment-297543414
--
URL: https://github.com/freeipa/freeipa/pull/738
Title: #738: restore: restart gssproxy after restore
frozencemetery commented:
"""
The systemd-portable way to do this is as I understand it is `systemctl
try-reload-or-restart gssproxy` (unless you want to start it if it's not
running, at
URL: https://github.com/freeipa/freeipa/pull/739
Author: HonzaCholasta
Title: #739: [4.5] spec file: bump krb5 Requires for certauth fixes
Action: opened
PR body:
"""
Bump krb5-* Requires to the version which includes the final version of
certauth support.
URL: https://github.com/freeipa/freeipa/pull/731
Title: #731: spec file: bump krb5 Requires for certauth fixes
HonzaCholasta commented:
"""
@martbab, #739.
"""
See the full comment at
https://github.com/freeipa/freeipa/pull/731#issuecomment-297614960
--
Manage your subscription for the
45 matches
Mail list logo