Re: [Freeipa-devel] [PATCH 0034] Deny LDAP binds for user accounts with expired principal

2014-05-05 Thread Alexander Bokovoy
On Wed, 30 Apr 2014, Tomas Babej wrote: +if (current_time expire_time expire_time 0) { +LOG_FATAL(kerberos principal in %s is expired\n, dn); +errMesg = Kerberos principal is expired.; +auth_failed = true; +

Re: [Freeipa-devel] [PATCH 0034] Deny LDAP binds for user accounts with expired principal

2014-05-05 Thread Alexander Bokovoy
On Mon, 05 May 2014, Alexander Bokovoy wrote: On Wed, 30 Apr 2014, Tomas Babej wrote: +if (current_time expire_time expire_time 0) { +LOG_FATAL(kerberos principal in %s is expired\n, dn); +errMesg = Kerberos principal is expired.; +

Re: [Freeipa-devel] [PATCH 0034] Deny LDAP binds for user accounts with expired principal

2014-04-30 Thread Tomas Babej
On 01/07/2014 01:47 PM, Tomas Babej wrote: On 01/07/2014 07:23 AM, Alexander Bokovoy wrote: On Mon, 06 Jan 2014, Tomas Babej wrote: On 01/06/2014 12:16 PM, Tomas Babej wrote: On 04/15/2013 12:43 PM, Tomas Babej wrote: On 04/08/2013 03:55 PM, Martin Kosek wrote: On 04/01/2013 09:52 PM, Rob

Re: [Freeipa-devel] [PATCH 0034] Deny LDAP binds for user accounts with expired principal

2014-04-30 Thread Simo Sorce
On Wed, 2014-04-30 at 17:07 +0200, Tomas Babej wrote: On 01/07/2014 01:47 PM, Tomas Babej wrote: On 01/07/2014 07:23 AM, Alexander Bokovoy wrote: On Mon, 06 Jan 2014, Tomas Babej wrote: On 01/06/2014 12:16 PM, Tomas Babej wrote: On 04/15/2013 12:43 PM, Tomas Babej wrote: On 04/08/2013

Re: [Freeipa-devel] [PATCH 0034] Deny LDAP binds for user accounts with expired principal

2014-04-30 Thread Alexander Bokovoy
On Wed, 30 Apr 2014, Simo Sorce wrote: Updated version attached. Tomas This version is rebased on top of OTP patches, addresses Simo's comments and brings unit tests to cover the functionality (however, they need to be applied on top of my patches 183-185). LGTM, but I haven't tested the

Re: [Freeipa-devel] [PATCH 0034] Deny LDAP binds for user accounts with expired principal

2014-04-08 Thread Martin Kosek
On 03/27/2014 02:40 PM, Martin Kosek wrote: On 01/07/2014 01:47 PM, Tomas Babej wrote: On 01/07/2014 07:23 AM, Alexander Bokovoy wrote: On Mon, 06 Jan 2014, Tomas Babej wrote: On 01/06/2014 12:16 PM, Tomas Babej wrote: On 04/15/2013 12:43 PM, Tomas Babej wrote: On 04/08/2013 03:55 PM,

Re: [Freeipa-devel] [PATCH 0034] Deny LDAP binds for user accounts with expired principal

2014-04-08 Thread Alexander Bokovoy
On Tue, 08 Apr 2014, Martin Kosek wrote: +auth_failed = true; +goto done; +} +} I think indenting is broken for these two brackets. Thanks Alexander, fixed. Updated version attached. Tomas Simo, Alexander - are

Re: [Freeipa-devel] [PATCH 0034] Deny LDAP binds for user accounts with expired principal

2014-04-08 Thread Martin Kosek
On 04/08/2014 04:23 PM, Alexander Bokovoy wrote: On Tue, 08 Apr 2014, Martin Kosek wrote: +auth_failed = true; +goto done; +} +} I think indenting is broken for these two brackets. Thanks Alexander, fixed.

Re: [Freeipa-devel] [PATCH 0034] Deny LDAP binds for user accounts with expired principal

2014-03-27 Thread Martin Kosek
On 01/07/2014 01:47 PM, Tomas Babej wrote: On 01/07/2014 07:23 AM, Alexander Bokovoy wrote: On Mon, 06 Jan 2014, Tomas Babej wrote: On 01/06/2014 12:16 PM, Tomas Babej wrote: On 04/15/2013 12:43 PM, Tomas Babej wrote: On 04/08/2013 03:55 PM, Martin Kosek wrote: On 04/01/2013 09:52 PM, Rob

Re: [Freeipa-devel] [PATCH 0034] Deny LDAP binds for user accounts with expired principal

2014-03-27 Thread Simo Sorce
this need rebasing due to OTP patches, however comments inline. On Tue, 2014-01-07 at 13:47 +0100, Tomas Babej wrote: diff --git a/daemons/ipa-slapi-plugins/ipa-pwd-extop/prepost.c b/daemons/ipa-slapi-plugins/ipa-pwd-extop/prepost.c index

Re: [Freeipa-devel] [PATCH 0034] Deny LDAP binds for user accounts with expired principal

2014-01-07 Thread Tomas Babej
On 01/07/2014 07:23 AM, Alexander Bokovoy wrote: On Mon, 06 Jan 2014, Tomas Babej wrote: On 01/06/2014 12:16 PM, Tomas Babej wrote: On 04/15/2013 12:43 PM, Tomas Babej wrote: On 04/08/2013 03:55 PM, Martin Kosek wrote: On 04/01/2013 09:52 PM, Rob Crittenden wrote: Tomas Babej wrote: On

Re: [Freeipa-devel] [PATCH 0034] Deny LDAP binds for user accounts with expired principal

2014-01-06 Thread Tomas Babej
On 04/15/2013 12:43 PM, Tomas Babej wrote: On 04/08/2013 03:55 PM, Martin Kosek wrote: On 04/01/2013 09:52 PM, Rob Crittenden wrote: Tomas Babej wrote: On 02/12/2013 06:23 PM, Simo Sorce wrote: On Tue, 2013-02-12 at 18:03 +0100, Tomas Babej wrote: On 02/12/2013 05:50 PM, Tomas Babej wrote:

Re: [Freeipa-devel] [PATCH 0034] Deny LDAP binds for user accounts with expired principal

2014-01-06 Thread Tomas Babej
On 01/06/2014 12:16 PM, Tomas Babej wrote: On 04/15/2013 12:43 PM, Tomas Babej wrote: On 04/08/2013 03:55 PM, Martin Kosek wrote: On 04/01/2013 09:52 PM, Rob Crittenden wrote: Tomas Babej wrote: On 02/12/2013 06:23 PM, Simo Sorce wrote: On Tue, 2013-02-12 at 18:03 +0100, Tomas Babej wrote:

Re: [Freeipa-devel] [PATCH 0034] Deny LDAP binds for user accounts with expired principal

2014-01-06 Thread Alexander Bokovoy
On Mon, 06 Jan 2014, Tomas Babej wrote: On 01/06/2014 12:16 PM, Tomas Babej wrote: On 04/15/2013 12:43 PM, Tomas Babej wrote: On 04/08/2013 03:55 PM, Martin Kosek wrote: On 04/01/2013 09:52 PM, Rob Crittenden wrote: Tomas Babej wrote: On 02/12/2013 06:23 PM, Simo Sorce wrote: On Tue,

Re: [Freeipa-devel] [PATCH 0034] Deny LDAP binds for user accounts with expired principal

2013-04-15 Thread Tomas Babej
On 04/08/2013 03:55 PM, Martin Kosek wrote: On 04/01/2013 09:52 PM, Rob Crittenden wrote: Tomas Babej wrote: On 02/12/2013 06:23 PM, Simo Sorce wrote: On Tue, 2013-02-12 at 18:03 +0100, Tomas Babej wrote: On 02/12/2013 05:50 PM, Tomas Babej wrote: Hi, This patch adds a check for

Re: [Freeipa-devel] [PATCH 0034] Deny LDAP binds for user accounts with expired principal

2013-04-08 Thread Martin Kosek
On 04/01/2013 09:52 PM, Rob Crittenden wrote: Tomas Babej wrote: On 02/12/2013 06:23 PM, Simo Sorce wrote: On Tue, 2013-02-12 at 18:03 +0100, Tomas Babej wrote: On 02/12/2013 05:50 PM, Tomas Babej wrote: Hi, This patch adds a check for krbprincipalexpiration attribute to pre_bind operation

Re: [Freeipa-devel] [PATCH 0034] Deny LDAP binds for user accounts with expired principal

2013-04-01 Thread Rob Crittenden
Tomas Babej wrote: On 02/12/2013 06:23 PM, Simo Sorce wrote: On Tue, 2013-02-12 at 18:03 +0100, Tomas Babej wrote: On 02/12/2013 05:50 PM, Tomas Babej wrote: Hi, This patch adds a check for krbprincipalexpiration attribute to pre_bind operation in ipa-pwd-extop dirsrv plugin. If the

Re: [Freeipa-devel] [PATCH 0034] Deny LDAP binds for user accounts with expired principal

2013-02-13 Thread Tomas Babej
On 02/12/2013 06:23 PM, Simo Sorce wrote: On Tue, 2013-02-12 at 18:03 +0100, Tomas Babej wrote: On 02/12/2013 05:50 PM, Tomas Babej wrote: Hi, This patch adds a check for krbprincipalexpiration attribute to pre_bind operation in ipa-pwd-extop dirsrv plugin. If the principal is expired, auth