Re: [Freeipa-devel] FreeIPA OTP End-to-End

2014-01-13 Thread Jakub Hrozek
On Sun, Jan 12, 2014 at 10:07:49PM +0200, Alexander Bokovoy wrote: > >>There seem to be two parts, one is covered by this bug and another one > >>is related to SSSD/logind communication: > >> > >>allow sssd_t systemd_logind_var_run_t:dir search; > >>allow sssd_t systemd_logind_var_run_t:file { read

Re: [Freeipa-devel] FreeIPA OTP End-to-End

2014-01-12 Thread Alexander Bokovoy
On Sun, 12 Jan 2014, Jakub Hrozek wrote: On Sat, Jan 11, 2014 at 01:20:59AM +0200, Alexander Bokovoy wrote: On Thu, 09 Jan 2014, Nathaniel McCallum wrote: >New RPMs are up: http://npmccallum.fedorapeople.org/freeipa-otp/rpms/ Just as a note -- we can use copr service to provide a better experien

Re: [Freeipa-devel] FreeIPA OTP End-to-End

2014-01-12 Thread Jakub Hrozek
On Sat, Jan 11, 2014 at 01:20:59AM +0200, Alexander Bokovoy wrote: > On Thu, 09 Jan 2014, Nathaniel McCallum wrote: > >New RPMs are up: http://npmccallum.fedorapeople.org/freeipa-otp/rpms/ > Just as a note -- we can use copr service to provide a better experience > for testing. I made a copr repo w

Re: [Freeipa-devel] FreeIPA OTP End-to-End

2014-01-10 Thread Alexander Bokovoy
On Thu, 09 Jan 2014, Nathaniel McCallum wrote: New RPMs are up: http://npmccallum.fedorapeople.org/freeipa-otp/rpms/ Just as a note -- we can use copr service to provide a better experience for testing. I made a copr repo with previous patchset last year: http://copr.fedoraproject.org/coprs/abbr

Re: [Freeipa-devel] FreeIPA OTP End-to-End

2014-01-09 Thread Nathaniel McCallum
New RPMs are up: http://npmccallum.fedorapeople.org/freeipa-otp/rpms/ WHAT'S NEW IN THE RPMS? * 389ds OTP Last Token Plugin * 389ds OTP Sync Plugin * HOTP token support * OTP UI is now working All of the non-UI code is currently on the list. Petr is working on UI cleanup. You can see all the patc

Re: [Freeipa-devel] FreeIPA OTP End-to-End

2014-01-03 Thread Petr Vobornik
On 23.12.2013 10:54, Alexander Bokovoy wrote: - Original Message - From: "Dmitri Pal" To: freeipa-devel@redhat.com Sent: Saturday, December 14, 2013 12:45:28 AM Subject: Re: [Freeipa-devel] FreeIPA OTP End-to-End On 12/13/2013 03:57 PM, Nathaniel McCallum wrote: This is a

Re: [Freeipa-devel] FreeIPA OTP End-to-End

2013-12-24 Thread Alexander Bokovoy
Alexander Bokovoy wrote: > What does not yet work is end-to-end kinit without armoured ccache. > This also is the case for PAM-based logins through SSSD. This one is fixed now. There was a bug in SSSD's processing of a response from a krb5_child process in case FAST is activated -- SSS_OTP message

Re: [Freeipa-devel] FreeIPA OTP End-to-End

2013-12-23 Thread Simo Sorce
On Mon, 2013-12-23 at 11:07 -0500, Alexander Bokovoy wrote: > > > > > What I would like to see is either automated armouring or use of fully > > > anonymous principal for armouring. > > > > Automated canont be done if you are a regular user unless PKINIT is > > configured on the KDC. Unfortunat

Re: [Freeipa-devel] FreeIPA OTP End-to-End

2013-12-23 Thread Alexander Bokovoy
- Original Message - > From: "Simo Sorce" > To: "Alexander Bokovoy" > Cc: d...@redhat.com, freeipa-devel@redhat.com > Sent: Monday, December 23, 2013 5:11:27 PM > Subject: Re: [Freeipa-devel] FreeIPA OTP End-to-End > > On Mon, 2013-12-2

Re: [Freeipa-devel] FreeIPA OTP End-to-End

2013-12-23 Thread Simo Sorce
On Mon, 2013-12-23 at 04:54 -0500, Alexander Bokovoy wrote: > > - Original Message - > > From: "Dmitri Pal" > > To: freeipa-devel@redhat.com > > Sent: Saturday, December 14, 2013 12:45:28 AM > > Subject: Re: [Freeipa-devel] FreeIPA OTP En

Re: [Freeipa-devel] FreeIPA OTP End-to-End

2013-12-23 Thread Alexander Bokovoy
- Original Message - > From: "Dmitri Pal" > To: freeipa-devel@redhat.com > Sent: Saturday, December 14, 2013 12:45:28 AM > Subject: Re: [Freeipa-devel] FreeIPA OTP End-to-End > > On 12/13/2013 03:57 PM, Nathaniel McCallum wrote: > > This is an em

Re: [Freeipa-devel] FreeIPA OTP End-to-End

2013-12-13 Thread Dmitri Pal
On 12/13/2013 03:57 PM, Nathaniel McCallum wrote: > This is an email to track the status of the OTP project as we push > toward completion. I'm also attempting to get all the pieces in play so > that they are testable. > > RPMs > Available here: http://npmccallum.fedorapeople.org/freeipa-otp/rpms/

[Freeipa-devel] FreeIPA OTP End-to-End

2013-12-13 Thread Nathaniel McCallum
This is an email to track the status of the OTP project as we push toward completion. I'm also attempting to get all the pieces in play so that they are testable. RPMs Available here: http://npmccallum.fedorapeople.org/freeipa-otp/rpms/ These currently contain the CLI and UI patches, but exclude t