Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-11-07 Thread Jan Cholasta
On 3.11.2016 00:18, Ben Lipton wrote: On 10/20/2016 03:52 PM, Ben Lipton wrote: On 10/17/2016 02:16 AM, Jan Cholasta wrote: On 13.10.2016 17:23, Ben Lipton wrote: Thank you, this was a really helpful clarification of your point. Comments below. Once again, I'm sorry I missed the email for so

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-11-02 Thread Ben Lipton
On 10/20/2016 03:52 PM, Ben Lipton wrote: On 10/17/2016 02:16 AM, Jan Cholasta wrote: On 13.10.2016 17:23, Ben Lipton wrote: Thank you, this was a really helpful clarification of your point. Comments below. Once again, I'm sorry I missed the email for so long. Ben On 09/05/2016 06:52 AM, Jan

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-10-20 Thread Ben Lipton
On 10/17/2016 02:16 AM, Jan Cholasta wrote: On 13.10.2016 17:23, Ben Lipton wrote: Thank you, this was a really helpful clarification of your point. Comments below. Once again, I'm sorry I missed the email for so long. Ben On 09/05/2016 06:52 AM, Jan Cholasta wrote: On 27.8.2016 22:40, Ben

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-10-17 Thread Jan Cholasta
On 13.10.2016 17:23, Ben Lipton wrote: Thank you, this was a really helpful clarification of your point. Comments below. Once again, I'm sorry I missed the email for so long. Ben On 09/05/2016 06:52 AM, Jan Cholasta wrote: On 27.8.2016 22:40, Ben Lipton wrote: On 08/25/2016 04:11 PM, Rob

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-10-13 Thread Ben Lipton
Thank you, this was a really helpful clarification of your point. Comments below. Once again, I'm sorry I missed the email for so long. Ben On 09/05/2016 06:52 AM, Jan Cholasta wrote: On 27.8.2016 22:40, Ben Lipton wrote: On 08/25/2016 04:11 PM, Rob Crittenden wrote: Ben Lipton wrote: On

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-09-05 Thread Jan Cholasta
On 27.8.2016 22:40, Ben Lipton wrote: On 08/25/2016 04:11 PM, Rob Crittenden wrote: Ben Lipton wrote: On 08/23/2016 03:54 AM, Jan Cholasta wrote: On 8.8.2016 22:23, Ben Lipton wrote: On 07/25/2016 07:45 AM, Jan Cholasta wrote: On 25.7.2016 13:11, Alexander Bokovoy wrote: On Mon, 25 Jul

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-08-27 Thread Ben Lipton
On 08/25/2016 04:11 PM, Rob Crittenden wrote: Ben Lipton wrote: On 08/23/2016 03:54 AM, Jan Cholasta wrote: On 8.8.2016 22:23, Ben Lipton wrote: On 07/25/2016 07:45 AM, Jan Cholasta wrote: On 25.7.2016 13:11, Alexander Bokovoy wrote: On Mon, 25 Jul 2016, Jan Cholasta wrote: On 20.7.2016

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-08-25 Thread Rob Crittenden
Ben Lipton wrote: On 08/23/2016 03:54 AM, Jan Cholasta wrote: On 8.8.2016 22:23, Ben Lipton wrote: On 07/25/2016 07:45 AM, Jan Cholasta wrote: On 25.7.2016 13:11, Alexander Bokovoy wrote: On Mon, 25 Jul 2016, Jan Cholasta wrote: On 20.7.2016 16:05, Ben Lipton wrote: Hi, Thanks very much

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-08-25 Thread Ben Lipton
On 08/23/2016 03:54 AM, Jan Cholasta wrote: On 8.8.2016 22:23, Ben Lipton wrote: On 07/25/2016 07:45 AM, Jan Cholasta wrote: On 25.7.2016 13:11, Alexander Bokovoy wrote: On Mon, 25 Jul 2016, Jan Cholasta wrote: On 20.7.2016 16:05, Ben Lipton wrote: Hi, Thanks very much for the feedback!

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-08-23 Thread Jan Cholasta
On 8.8.2016 22:23, Ben Lipton wrote: On 07/25/2016 07:45 AM, Jan Cholasta wrote: On 25.7.2016 13:11, Alexander Bokovoy wrote: On Mon, 25 Jul 2016, Jan Cholasta wrote: On 20.7.2016 16:05, Ben Lipton wrote: Hi, Thanks very much for the feedback! Some responses below; I hope you'll let me know

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-08-08 Thread Ben Lipton
On 07/25/2016 07:45 AM, Jan Cholasta wrote: On 25.7.2016 13:11, Alexander Bokovoy wrote: On Mon, 25 Jul 2016, Jan Cholasta wrote: On 20.7.2016 16:05, Ben Lipton wrote: Hi, Thanks very much for the feedback! Some responses below; I hope you'll let me know what you think of my reasoning. On

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-07-25 Thread Rob Crittenden
Simo Sorce wrote: On Mon, 2016-07-25 at 18:05 +0300, Alexander Bokovoy wrote: But maybe I'm not seeing the proper priorities here. Perhaps it's more of a problem because clients are easier to update with bugfixes than the server? Or maybe the preference for the client is for scalability

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-07-25 Thread Alexander Bokovoy
On Mon, 25 Jul 2016, Simo Sorce wrote: On Mon, 2016-07-25 at 12:13 -0400, Ben Lipton wrote: On 07/25/2016 11:07 AM, Simo Sorce wrote: > On Mon, 2016-07-25 at 11:04 -0400, Simo Sorce wrote: >> On Mon, 2016-07-25 at 10:51 -0400, Ben Lipton wrote: >>> On 07/25/2016 05:07 AM, Simo Sorce wrote:

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-07-25 Thread Alexander Bokovoy
On Mon, 25 Jul 2016, Simo Sorce wrote: On Mon, 2016-07-25 at 12:09 -0400, Ben Lipton wrote: On 07/25/2016 12:03 PM, Simo Sorce wrote: > On Mon, 2016-07-25 at 18:05 +0300, Alexander Bokovoy wrote: >>> But maybe I'm not seeing the proper priorities here. Perhaps it's >> more >>> of a problem

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-07-25 Thread Simo Sorce
On Mon, 2016-07-25 at 12:13 -0400, Ben Lipton wrote: > On 07/25/2016 11:07 AM, Simo Sorce wrote: > > On Mon, 2016-07-25 at 11:04 -0400, Simo Sorce wrote: > >> On Mon, 2016-07-25 at 10:51 -0400, Ben Lipton wrote: > >>> On 07/25/2016 05:07 AM, Simo Sorce wrote: > On Mon, 2016-07-25 at 10:50

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-07-25 Thread Simo Sorce
On Mon, 2016-07-25 at 12:09 -0400, Ben Lipton wrote: > On 07/25/2016 12:03 PM, Simo Sorce wrote: > > On Mon, 2016-07-25 at 18:05 +0300, Alexander Bokovoy wrote: > >>> But maybe I'm not seeing the proper priorities here. Perhaps it's > >> more > >>> of a problem because clients are easier to update

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-07-25 Thread Ben Lipton
On 07/25/2016 11:07 AM, Simo Sorce wrote: On Mon, 2016-07-25 at 11:04 -0400, Simo Sorce wrote: On Mon, 2016-07-25 at 10:51 -0400, Ben Lipton wrote: On 07/25/2016 05:07 AM, Simo Sorce wrote: On Mon, 2016-07-25 at 10:50 +0200, Jan Cholasta wrote: Anyway, my main grudge is that the

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-07-25 Thread Ben Lipton
On 07/25/2016 12:03 PM, Simo Sorce wrote: On Mon, 2016-07-25 at 18:05 +0300, Alexander Bokovoy wrote: But maybe I'm not seeing the proper priorities here. Perhaps it's more of a problem because clients are easier to update with bugfixes than the server? Or maybe the preference for the client

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-07-25 Thread Simo Sorce
On Mon, 2016-07-25 at 18:05 +0300, Alexander Bokovoy wrote: > >But maybe I'm not seeing the proper priorities here. Perhaps it's > more > >of a problem because clients are easier to update with bugfixes than > >the server? Or maybe the preference for the client is for > scalability > >reasons?

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-07-25 Thread Simo Sorce
On Mon, 2016-07-25 at 11:04 -0400, Simo Sorce wrote: > On Mon, 2016-07-25 at 10:51 -0400, Ben Lipton wrote: > > On 07/25/2016 05:07 AM, Simo Sorce wrote: > > > On Mon, 2016-07-25 at 10:50 +0200, Jan Cholasta wrote: > > >> Anyway, my main grudge is that the transformation rules shouldn't > > >>

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-07-25 Thread Alexander Bokovoy
On Mon, 25 Jul 2016, Ben Lipton wrote: On 07/25/2016 05:07 AM, Simo Sorce wrote: On Mon, 2016-07-25 at 10:50 +0200, Jan Cholasta wrote: Anyway, my main grudge is that the transformation rules shouldn't really be stored on and processed by the server. The server should know the *what* (mapping

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-07-25 Thread Simo Sorce
On Mon, 2016-07-25 at 10:51 -0400, Ben Lipton wrote: > On 07/25/2016 05:07 AM, Simo Sorce wrote: > > On Mon, 2016-07-25 at 10:50 +0200, Jan Cholasta wrote: > >> Anyway, my main grudge is that the transformation rules shouldn't > >> really > >> be stored on and processed by the server. The server

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-07-25 Thread Ben Lipton
On 07/25/2016 05:07 AM, Simo Sorce wrote: On Mon, 2016-07-25 at 10:50 +0200, Jan Cholasta wrote: Anyway, my main grudge is that the transformation rules shouldn't really be stored on and processed by the server. The server should know the *what* (mapping rules), but not the *how*

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-07-25 Thread Ben Lipton
On 07/25/2016 08:12 AM, Alexander Bokovoy wrote: On Mon, 25 Jul 2016, Jan Cholasta wrote: This is turning out to be a common (and, I think, reasonable) reaction to the proposal. It is rather complex, and I worry that it will be difficult to configure. On the other hand, there is some hidden

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-07-25 Thread Alexander Bokovoy
On Mon, 25 Jul 2016, Jan Cholasta wrote: This is turning out to be a common (and, I think, reasonable) reaction to the proposal. It is rather complex, and I worry that it will be difficult to configure. On the other hand, there is some hidden complexity to enabling a simpler config format, as

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-07-25 Thread Jan Cholasta
On 25.7.2016 13:11, Alexander Bokovoy wrote: On Mon, 25 Jul 2016, Jan Cholasta wrote: On 20.7.2016 16:05, Ben Lipton wrote: Hi, Thanks very much for the feedback! Some responses below; I hope you'll let me know what you think of my reasoning. On 07/20/2016 04:20 AM, Jan Cholasta wrote: Hi,

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-07-25 Thread Alexander Bokovoy
On Mon, 25 Jul 2016, Jan Cholasta wrote: On 20.7.2016 16:05, Ben Lipton wrote: Hi, Thanks very much for the feedback! Some responses below; I hope you'll let me know what you think of my reasoning. On 07/20/2016 04:20 AM, Jan Cholasta wrote: Hi, On 17.6.2016 00:06, Ben Lipton wrote: On

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-07-25 Thread Simo Sorce
On Mon, 2016-07-25 at 10:50 +0200, Jan Cholasta wrote: > Anyway, my main grudge is that the transformation rules shouldn't > really > be stored on and processed by the server. The server should know the > *what* (mapping rules), but not the *how* (transformation rules). The > *how* is an

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-07-25 Thread Jan Cholasta
On 20.7.2016 16:05, Ben Lipton wrote: Hi, Thanks very much for the feedback! Some responses below; I hope you'll let me know what you think of my reasoning. On 07/20/2016 04:20 AM, Jan Cholasta wrote: Hi, On 17.6.2016 00:06, Ben Lipton wrote: On 06/14/2016 08:27 AM, Ben Lipton wrote:

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-07-20 Thread Jan Cholasta
Hi, On 17.6.2016 00:06, Ben Lipton wrote: On 06/14/2016 08:27 AM, Ben Lipton wrote: Hello all, I have written up a design proposal for making certificate requests easier to generate when using alternate certificate profiles:

Re: [Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-06-16 Thread Ben Lipton
On 06/14/2016 08:27 AM, Ben Lipton wrote: Hello all, I have written up a design proposal for making certificate requests easier to generate when using alternate certificate profiles: http://www.freeipa.org/page/V4/Automatic_Certificate_Request_Generation. The use case for this is described

[Freeipa-devel] [Design Review Request] V4/Automatic_Certificate_Request_Generation

2016-06-14 Thread Ben Lipton
Hello all, I have written up a design proposal for making certificate requests easier to generate when using alternate certificate profiles: http://www.freeipa.org/page/V4/Automatic_Certificate_Request_Generation. The use case for this is described in