Re: [Freeipa-devel] [PATCH] 0014

2016-09-05 Thread Jan Cholasta
On 5.9.2016 10:42, Tomas Krizek wrote: On 09/02/2016 09:05 AM, Florence Blanc-Renaud wrote: On 09/02/2016 08:08 AM, Jan Cholasta wrote: On 1.9.2016 19:37, Tomas Krizek wrote: On 09/01/2016 03:58 PM, Florence Blanc-Renaud wrote: Hi, please find attached a patch for ipa-certupdate in CA-less

Re: [Freeipa-devel] [PATCH] 0014

2016-09-05 Thread Tomas Krizek
On 09/02/2016 09:05 AM, Florence Blanc-Renaud wrote: On 09/02/2016 08:08 AM, Jan Cholasta wrote: On 1.9.2016 19:37, Tomas Krizek wrote: On 09/01/2016 03:58 PM, Florence Blanc-Renaud wrote: Hi, please find attached a patch for ipa-certupdate in CA-less deployment. https://fedorahosted.org/fre

Re: [Freeipa-devel] [PATCH] 0014

2016-09-02 Thread Florence Blanc-Renaud
On 09/02/2016 08:08 AM, Jan Cholasta wrote: On 1.9.2016 19:37, Tomas Krizek wrote: On 09/01/2016 03:58 PM, Florence Blanc-Renaud wrote: Hi, please find attached a patch for ipa-certupdate in CA-less deployment. https://fedorahosted.org/freeipa/ticket/6288 Flo. The patch is malformed, but

Re: [Freeipa-devel] [PATCH] 0014

2016-09-01 Thread Jan Cholasta
On 1.9.2016 19:37, Tomas Krizek wrote: On 09/01/2016 03:58 PM, Florence Blanc-Renaud wrote: Hi, please find attached a patch for ipa-certupdate in CA-less deployment. https://fedorahosted.org/freeipa/ticket/6288 Flo. The patch is malformed, but you can simply delete the very first characte

Re: [Freeipa-devel] [PATCH] 0014

2016-09-01 Thread Petr Spacek
On 2.9.2016 05:22, Fraser Tweedale wrote: > On Thu, Sep 01, 2016 at 07:37:53PM +0200, Tomas Krizek wrote: >> On 09/01/2016 03:58 PM, Florence Blanc-Renaud wrote: >>> Hi, >>> >>> please find attached a patch for ipa-certupdate in CA-less deployment. >>> https://fedorahosted.org/freeipa/ticket/6288 >

Re: [Freeipa-devel] [PATCH] 0014

2016-09-01 Thread Fraser Tweedale
On Thu, Sep 01, 2016 at 07:37:53PM +0200, Tomas Krizek wrote: > On 09/01/2016 03:58 PM, Florence Blanc-Renaud wrote: > > Hi, > > > > please find attached a patch for ipa-certupdate in CA-less deployment. > > https://fedorahosted.org/freeipa/ticket/6288 > > > > Flo. > > > > > > > The patch is m

Re: [Freeipa-devel] [PATCH] 0014

2016-09-01 Thread Tomas Krizek
On 09/01/2016 03:58 PM, Florence Blanc-Renaud wrote: Hi, please find attached a patch for ipa-certupdate in CA-less deployment. https://fedorahosted.org/freeipa/ticket/6288 Flo. The patch is malformed, but you can simply delete the very first character to fix it. Other than that, patch wo

Re: [Freeipa-devel] [PATCH 0014-0016][Tests] Authentication indicators

2016-07-15 Thread Petr Vobornik
On 07/14/2016 03:11 PM, Milan Kubík wrote: > On 07/14/2016 11:43 AM, Lenka Doudova wrote: >> >>> >>> >> Resending the complete patch set. >> L. >> >> > > Thanks, ACK. > > -- > Milan Kubik > master: * 0f9a5ce6b4c533647b8894f516e34bea8184f1b8 Tests: Tracker class for services * dcdbbb975927a24e

Re: [Freeipa-devel] [PATCH 0014-0016][Tests] Authentication indicators

2016-07-14 Thread Milan Kubík
On 07/14/2016 11:43 AM, Lenka Doudova wrote: On 07/14/2016 11:25 AM, Lenka Doudova wrote: On 07/14/2016 09:20 AM, Lenka Doudova wrote: On 07/13/2016 04:48 PM, Milan Kubík wrote: On 07/11/2016 01:34 PM, Lenka Doudova wrote: On 07/08/2016 02:24 PM, Milan Kubík wrote: On 07/01/2016

Re: [Freeipa-devel] [PATCH 0014-0016][Tests] Authentication indicators

2016-07-14 Thread Lenka Doudova
On 07/14/2016 11:25 AM, Lenka Doudova wrote: On 07/14/2016 09:20 AM, Lenka Doudova wrote: On 07/13/2016 04:48 PM, Milan Kubík wrote: On 07/11/2016 01:34 PM, Lenka Doudova wrote: On 07/08/2016 02:24 PM, Milan Kubík wrote: On 07/01/2016 05:13 PM, Lenka Doudova wrote: On 07/01/201

Re: [Freeipa-devel] [PATCH 0014-0016][Tests] Authentication indicators

2016-07-14 Thread Lenka Doudova
On 07/14/2016 09:20 AM, Lenka Doudova wrote: On 07/13/2016 04:48 PM, Milan Kubík wrote: On 07/11/2016 01:34 PM, Lenka Doudova wrote: On 07/08/2016 02:24 PM, Milan Kubík wrote: On 07/01/2016 05:13 PM, Lenka Doudova wrote: On 07/01/2016 02:42 PM, Milan Kubík wrote: On 06/16/2016 03:

Re: [Freeipa-devel] [PATCH 0014-0016][Tests] Authentication indicators

2016-07-14 Thread Lenka Doudova
On 07/13/2016 04:48 PM, Milan Kubík wrote: On 07/11/2016 01:34 PM, Lenka Doudova wrote: On 07/08/2016 02:24 PM, Milan Kubík wrote: On 07/01/2016 05:13 PM, Lenka Doudova wrote: On 07/01/2016 02:42 PM, Milan Kubík wrote: On 06/16/2016 03:23 PM, Lenka Doudova wrote: Hi, attached are te

Re: [Freeipa-devel] [PATCH 0014-0016][Tests] Authentication indicators

2016-07-13 Thread Milan Kubík
On 07/11/2016 01:34 PM, Lenka Doudova wrote: On 07/08/2016 02:24 PM, Milan Kubík wrote: On 07/01/2016 05:13 PM, Lenka Doudova wrote: On 07/01/2016 02:42 PM, Milan Kubík wrote: On 06/16/2016 03:23 PM, Lenka Doudova wrote: Hi, attached are tests for authentication indicators. Please note

Re: [Freeipa-devel] [PATCH 0014-0016][Tests] Authentication indicators

2016-07-11 Thread Lenka Doudova
On 07/08/2016 02:24 PM, Milan Kubík wrote: On 07/01/2016 05:13 PM, Lenka Doudova wrote: On 07/01/2016 02:42 PM, Milan Kubík wrote: On 06/16/2016 03:23 PM, Lenka Doudova wrote: Hi, attached are tests for authentication indicators. Please note: 1. newly created service tracker is not exac

Re: [Freeipa-devel] [PATCH 0014-0016][Tests] Authentication indicators

2016-07-08 Thread Milan Kubík
On 07/01/2016 05:13 PM, Lenka Doudova wrote: On 07/01/2016 02:42 PM, Milan Kubík wrote: On 06/16/2016 03:23 PM, Lenka Doudova wrote: Hi, attached are tests for authentication indicators. Please note: 1. newly created service tracker is not exactly complete, list of unimplemented methods i

Re: [Freeipa-devel] [PATCH 0014-0016][Tests] Authentication indicators

2016-07-01 Thread Lenka Doudova
On 07/01/2016 02:42 PM, Milan Kubík wrote: On 06/16/2016 03:23 PM, Lenka Doudova wrote: Hi, attached are tests for authentication indicators. Please note: 1. newly created service tracker is not exactly complete, list of unimplemented methods is in doc. These methods can be filled in when

Re: [Freeipa-devel] [PATCH 0014-0016][Tests] Authentication indicators

2016-07-01 Thread Milan Kubík
On 06/16/2016 03:23 PM, Lenka Doudova wrote: Hi, attached are tests for authentication indicators. Please note: 1. newly created service tracker is not exactly complete, list of unimplemented methods is in doc. These methods can be filled in when existing declarative tests are refactored. 2

Re: [Freeipa-devel] [PATCH 0014-0016][Tests] Authentication indicators

2016-06-22 Thread Lenka Doudova
Bump for review. Thanks. On 06/16/2016 03:23 PM, Lenka Doudova wrote: Hi, attached are tests for authentication indicators. Please note: 1. newly created service tracker is not exactly complete, list of unimplemented methods is in doc. These methods can be filled in when existing declarativ

Re: [Freeipa-devel] [PATCH] 0014 webui: Update delete dialog on active user details page

2016-06-02 Thread Petr Vobornik
On 04/14/2016 09:39 AM, Pavel Vomacka wrote: > Hi, > > The attached patch fixes this ticket: > https://fedorahosted.org/freeipa/ticket/5370 . > > It adds radio button to choose whether you want to preserve or delete > user when performing delete action from details page. > > -- > Pavel^3 Vomack

Re: [Freeipa-devel] [PATCH 0014] Removed custom implementation of CalledProcessError

2016-05-10 Thread Martin Basti
On 09.05.2016 10:02, Petr Spacek wrote: On 7.5.2016 08:44, Abhijeet Kasurde wrote: Hi All, Please review this patch. ACK, I've verified that CalledProcessError signature in Python 2.7 and in the duplicate code is the same. Pushed to master: 51db9380cfc862993e1909602d2726e851f463b4 -- Mana

Re: [Freeipa-devel] [PATCH 0014] Removed custom implementation of CalledProcessError

2016-05-09 Thread Petr Spacek
On 7.5.2016 08:44, Abhijeet Kasurde wrote: > Hi All, > > Please review this patch. ACK, I've verified that CalledProcessError signature in Python 2.7 and in the duplicate code is the same. -- Petr^2 Spacek -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/

Re: [Freeipa-devel] [PATCH 0014] [py3] Replace M2Crypto RC4 with python-cryptography ARC4

2015-07-31 Thread Jan Cholasta
Dne 23.7.2015 v 11:06 Christian Heimes napsal(a): On 2015-07-23 10:54, Jan Cholasta wrote: Hi, Dne 23.7.2015 v 10:43 Christian Heimes napsal(a): This patch removes the dependency on M2Crypto in favor for cryptography. Cryptography is more strict about the key size and doesn't support non-stand

Re: [Freeipa-devel] [PATCH 0014] [py3] Replace M2Crypto RC4 with python-cryptography ARC4

2015-07-23 Thread Alexander Bokovoy
On Thu, 23 Jul 2015, Christian Heimes wrote: On 2015-07-23 11:06, Alexander Bokovoy wrote: On Thu, 23 Jul 2015, Christian Heimes wrote: This patch removes the dependency on M2Crypto in favor for cryptography. Cryptography is more strict about the key size and doesn't support non-standard key si

Re: [Freeipa-devel] [PATCH 0014] [py3] Replace M2Crypto RC4 with python-cryptography ARC4

2015-07-23 Thread Christian Heimes
On 2015-07-23 11:06, Alexander Bokovoy wrote: > On Thu, 23 Jul 2015, Christian Heimes wrote: >> This patch removes the dependency on M2Crypto in favor for cryptography. >> Cryptography is more strict about the key size and doesn't support >> non-standard key sizes: >> > from M2Crypto import RC4

Re: [Freeipa-devel] [PATCH 0014] [py3] Replace M2Crypto RC4 with python-cryptography ARC4

2015-07-23 Thread Alexander Bokovoy
On Thu, 23 Jul 2015, Christian Heimes wrote: This patch removes the dependency on M2Crypto in favor for cryptography. Cryptography is more strict about the key size and doesn't support non-standard key sizes: from M2Crypto import RC4 from ipaserver.dcerpc import arcfour_encrypt RC4.RC4(b'key').

Re: [Freeipa-devel] [PATCH 0014] [py3] Replace M2Crypto RC4 with python-cryptography ARC4

2015-07-23 Thread Christian Heimes
On 2015-07-23 10:54, Jan Cholasta wrote: > Hi, > > Dne 23.7.2015 v 10:43 Christian Heimes napsal(a): >> This patch removes the dependency on M2Crypto in favor for cryptography. >> Cryptography is more strict about the key size and doesn't support >> non-standard key sizes: >> > from M2Crypto i

Re: [Freeipa-devel] [PATCH 0014] [py3] Replace M2Crypto RC4 with python-cryptography ARC4

2015-07-23 Thread Alexander Bokovoy
On Thu, 23 Jul 2015, Christian Heimes wrote: This patch removes the dependency on M2Crypto in favor for cryptography. Cryptography is more strict about the key size and doesn't support non-standard key sizes: from M2Crypto import RC4 from ipaserver.dcerpc import arcfour_encrypt RC4.RC4(b'key').

Re: [Freeipa-devel] [PATCH 0014] [py3] Replace M2Crypto RC4 with python-cryptography ARC4

2015-07-23 Thread Jan Cholasta
Hi, Dne 23.7.2015 v 10:43 Christian Heimes napsal(a): This patch removes the dependency on M2Crypto in favor for cryptography. Cryptography is more strict about the key size and doesn't support non-standard key sizes: from M2Crypto import RC4 from ipaserver.dcerpc import arcfour_encrypt RC4.RC

Re: [Freeipa-devel] [PATCH 0014] correct handling of one directional segments

2015-06-29 Thread Tomas Babej
On 06/29/2015 01:50 PM, thierry bordaz wrote: > On 06/29/2015 12:47 PM, Martin Basti wrote: >> On 17/06/15 11:05, Ludwig Krispenz wrote: >>> >>> On 06/17/2015 10:35 AM, thierry bordaz wrote: On 06/17/2015 09:25 AM, Ludwig Krispenz wrote: > Hi, > thanks for review, see answers inline.

Re: [Freeipa-devel] [PATCH 0014] correct handling of one directional segments

2015-06-29 Thread thierry bordaz
On 06/29/2015 12:47 PM, Martin Basti wrote: On 17/06/15 11:05, Ludwig Krispenz wrote: On 06/17/2015 10:35 AM, thierry bordaz wrote: On 06/17/2015 09:25 AM, Ludwig Krispenz wrote: Hi, thanks for review, see answers inline. On 06/16/2015 05:17 PM, thierry bordaz wrote: On 06/16/2015 11:41 AM,

Re: [Freeipa-devel] [PATCH 0014] correct handling of one directional segments

2015-06-29 Thread Martin Basti
On 17/06/15 11:05, Ludwig Krispenz wrote: On 06/17/2015 10:35 AM, thierry bordaz wrote: On 06/17/2015 09:25 AM, Ludwig Krispenz wrote: Hi, thanks for review, see answers inline. On 06/16/2015 05:17 PM, thierry bordaz wrote: On 06/16/2015 11:41 AM, Ludwig Krispenz wrote: this patch adresses i

Re: [Freeipa-devel] [PATCH 0014] correct handling of one directional segments

2015-06-17 Thread Ludwig Krispenz
On 06/17/2015 10:35 AM, thierry bordaz wrote: On 06/17/2015 09:25 AM, Ludwig Krispenz wrote: Hi, thanks for review, see answers inline. On 06/16/2015 05:17 PM, thierry bordaz wrote: On 06/16/2015 11:41 AM, Ludwig Krispenz wrote: this patch adresses issues in checking existing segments for one

Re: [Freeipa-devel] [PATCH 0014] correct handling of one directional segments

2015-06-17 Thread thierry bordaz
On 06/17/2015 09:25 AM, Ludwig Krispenz wrote: Hi, thanks for review, see answers inline. On 06/16/2015 05:17 PM, thierry bordaz wrote: On 06/16/2015 11:41 AM, Ludwig Krispenz wrote: this patch adresses issues in checking existing segments for one directional segments and correctly handles the

Re: [Freeipa-devel] [PATCH 0014] correct handling of one directional segments

2015-06-17 Thread Ludwig Krispenz
Hi, thanks for review, see answers inline. On 06/16/2015 05:17 PM, thierry bordaz wrote: On 06/16/2015 11:41 AM, Ludwig Krispenz wrote: this patch adresses issues in checking existing segments for one directional segments and correctly handles the merging of segments, so that all agreements wi

Re: [Freeipa-devel] [PATCH 0014] correct handling of one directional segments

2015-06-16 Thread thierry bordaz
On 06/16/2015 11:41 AM, Ludwig Krispenz wrote: this patch adresses issues in checking existing segments for one directional segments and correctly handles the merging of segments, so that all agreements will be removed when the merged segment is deleted This is looking good to me with few c

Re: [Freeipa-devel] [PATCH 0014 v3] Support multiple user and host certificates

2015-06-03 Thread Jan Cholasta
Dne 3.6.2015 v 17:44 Martin Basti napsal(a): On 03/06/15 15:21, Fraser Tweedale wrote: On Wed, Jun 03, 2015 at 01:55:47PM +0200, Milan Kubik wrote: On 06/03/2015 01:17 PM, Martin Basti wrote: On 02/06/15 16:03, Jan Cholasta wrote: Dne 2.6.2015 v 12:36 Martin Basti napsal(a): On 02/06/15 11:4

Re: [Freeipa-devel] [PATCH 0014] Support multiple user and host certificates

2015-06-03 Thread Martin Basti
On 02/06/15 16:56, Petr Vobornik wrote: On 05/27/2015 03:53 PM, Fraser Tweedale wrote: This patch adds supports for multiple user / host certificates. No schema change is needed ('usercertificate' attribute is already multi-value). The revoke-previous-cert behaviour of host-mod and user-mod ha

Re: [Freeipa-devel] [PATCH 0014 v3] Support multiple user and host certificates

2015-06-03 Thread Martin Basti
On 03/06/15 15:21, Fraser Tweedale wrote: On Wed, Jun 03, 2015 at 01:55:47PM +0200, Milan Kubik wrote: On 06/03/2015 01:17 PM, Martin Basti wrote: On 02/06/15 16:03, Jan Cholasta wrote: Dne 2.6.2015 v 12:36 Martin Basti napsal(a): On 02/06/15 11:42, Fraser Tweedale wrote: On Mon, Jun 01, 201

Re: [Freeipa-devel] [PATCH 0014 v3] Support multiple user and host certificates

2015-06-03 Thread Fraser Tweedale
On Wed, Jun 03, 2015 at 01:55:47PM +0200, Milan Kubik wrote: > On 06/03/2015 01:17 PM, Martin Basti wrote: > >On 02/06/15 16:03, Jan Cholasta wrote: > >>Dne 2.6.2015 v 12:36 Martin Basti napsal(a): > >>>On 02/06/15 11:42, Fraser Tweedale wrote: > On Mon, Jun 01, 2015 at 02:50:45PM +0200, Martin

Re: [Freeipa-devel] [PATCH 0014 v3] Support multiple user and host certificates

2015-06-03 Thread Milan Kubik
On 06/03/2015 01:17 PM, Martin Basti wrote: On 02/06/15 16:03, Jan Cholasta wrote: Dne 2.6.2015 v 12:36 Martin Basti napsal(a): On 02/06/15 11:42, Fraser Tweedale wrote: On Mon, Jun 01, 2015 at 02:50:45PM +0200, Martin Basti wrote: On 01/06/15 06:40, Fraser Tweedale wrote: New version of pat

Re: [Freeipa-devel] [PATCH 0014 v3] Support multiple user and host certificates

2015-06-03 Thread Martin Basti
On 02/06/15 16:03, Jan Cholasta wrote: Dne 2.6.2015 v 12:36 Martin Basti napsal(a): On 02/06/15 11:42, Fraser Tweedale wrote: On Mon, Jun 01, 2015 at 02:50:45PM +0200, Martin Basti wrote: On 01/06/15 06:40, Fraser Tweedale wrote: New version of patch; ``{host,service}-show --out=FILE`` now wr

Re: [Freeipa-devel] [PATCH 0014] Support multiple user and host certificates

2015-06-02 Thread Petr Vobornik
On 05/27/2015 03:53 PM, Fraser Tweedale wrote: This patch adds supports for multiple user / host certificates. No schema change is needed ('usercertificate' attribute is already multi-value). The revoke-previous-cert behaviour of host-mod and user-mod has been removed but revocation behaviour o

Re: [Freeipa-devel] [PATCH 0014 v3] Support multiple user and host certificates

2015-06-02 Thread Jan Cholasta
Dne 2.6.2015 v 12:36 Martin Basti napsal(a): On 02/06/15 11:42, Fraser Tweedale wrote: On Mon, Jun 01, 2015 at 02:50:45PM +0200, Martin Basti wrote: On 01/06/15 06:40, Fraser Tweedale wrote: New version of patch; ``{host,service}-show --out=FILE`` now writes all certs to FILE. Rebased on late

Re: [Freeipa-devel] [PATCH 0014 v3] Support multiple user and host certificates

2015-06-02 Thread Martin Basti
On 02/06/15 11:42, Fraser Tweedale wrote: On Mon, Jun 01, 2015 at 02:50:45PM +0200, Martin Basti wrote: On 01/06/15 06:40, Fraser Tweedale wrote: New version of patch; ``{host,service}-show --out=FILE`` now writes all certs to FILE. Rebased on latest master. Thanks, Fraser On Thu, May 28, 20

Re: [Freeipa-devel] [PATCH 0014 v3] Support multiple user and host certificates

2015-06-02 Thread Fraser Tweedale
On Mon, Jun 01, 2015 at 02:50:45PM +0200, Martin Basti wrote: > On 01/06/15 06:40, Fraser Tweedale wrote: > >New version of patch; ``{host,service}-show --out=FILE`` now writes > >all certs to FILE. Rebased on latest master. > > > >Thanks, > >Fraser > > > >On Thu, May 28, 2015 at 09:18:04PM +1000,

Re: [Freeipa-devel] [PATCH 0014 v3] Support multiple user and host certificates

2015-06-01 Thread Martin Basti
On 01/06/15 06:40, Fraser Tweedale wrote: New version of patch; ``{host,service}-show --out=FILE`` now writes all certs to FILE. Rebased on latest master. Thanks, Fraser On Thu, May 28, 2015 at 09:18:04PM +1000, Fraser Tweedale wrote: Updated patch attached. Notably restores/adds revocation

Re: [Freeipa-devel] [PATCH 0014 v3] Support multiple user and host certificates

2015-05-31 Thread Fraser Tweedale
New version of patch; ``{host,service}-show --out=FILE`` now writes all certs to FILE. Rebased on latest master. Thanks, Fraser On Thu, May 28, 2015 at 09:18:04PM +1000, Fraser Tweedale wrote: > Updated patch attached. Notably restores/adds revocation behaviour > to host-mod and service-mod. >

Re: [Freeipa-devel] [PATCH 0014] Support multiple user and host certificates

2015-05-28 Thread Petr Spacek
On 28.5.2015 15:43, Martin Kosek wrote: > On 05/28/2015 02:29 PM, Petr Spacek wrote: >> On 28.5.2015 12:06, Fraser Tweedale wrote: >>> On Thu, May 28, 2015 at 11:52:25AM +0200, Martin Kosek wrote: On 05/28/2015 11:17 AM, Martin Basti wrote: > On 28/05/15 10:46, Martin Kosek wrote: >> O

Re: [Freeipa-devel] [PATCH 0014] Support multiple user and host certificates

2015-05-28 Thread Simo Sorce
On Thu, 2015-05-28 at 15:43 +0200, Martin Kosek wrote: > On 05/28/2015 02:29 PM, Petr Spacek wrote: > > On 28.5.2015 12:06, Fraser Tweedale wrote: > >> On Thu, May 28, 2015 at 11:52:25AM +0200, Martin Kosek wrote: > >>> On 05/28/2015 11:17 AM, Martin Basti wrote: > On 28/05/15 10:46, Martin Ko

Re: [Freeipa-devel] [PATCH 0014] Support multiple user and host certificates

2015-05-28 Thread Martin Kosek
On 05/28/2015 02:29 PM, Petr Spacek wrote: > On 28.5.2015 12:06, Fraser Tweedale wrote: >> On Thu, May 28, 2015 at 11:52:25AM +0200, Martin Kosek wrote: >>> On 05/28/2015 11:17 AM, Martin Basti wrote: On 28/05/15 10:46, Martin Kosek wrote: > On 05/27/2015 06:12 PM, Martin Basti wrote:

Re: [Freeipa-devel] [PATCH 0014] Support multiple user and host certificates

2015-05-28 Thread Martin Basti
On 28/05/15 14:29, Petr Spacek wrote: On 28.5.2015 12:06, Fraser Tweedale wrote: On Thu, May 28, 2015 at 11:52:25AM +0200, Martin Kosek wrote: On 05/28/2015 11:17 AM, Martin Basti wrote: On 28/05/15 10:46, Martin Kosek wrote: On 05/27/2015 06:12 PM, Martin Basti wrote: On 27/05/15 15:53, Fra

Re: [Freeipa-devel] [PATCH 0014] Support multiple user and host certificates

2015-05-28 Thread Petr Spacek
On 28.5.2015 12:06, Fraser Tweedale wrote: > On Thu, May 28, 2015 at 11:52:25AM +0200, Martin Kosek wrote: >> On 05/28/2015 11:17 AM, Martin Basti wrote: >>> On 28/05/15 10:46, Martin Kosek wrote: On 05/27/2015 06:12 PM, Martin Basti wrote: > On 27/05/15 15:53, Fraser Tweedale wrote: >

Re: [Freeipa-devel] [PATCH 0014] Support multiple user and host certificates

2015-05-28 Thread Fraser Tweedale
Updated patch attached. Notably restores/adds revocation behaviour to host-mod and service-mod. Thanks, Fraser On Wed, May 27, 2015 at 06:12:50PM +0200, Martin Basti wrote: > On 27/05/15 15:53, Fraser Tweedale wrote: > >This patch adds supports for multiple user / host certificates. No > >schem

Re: [Freeipa-devel] [PATCH 0014] Support multiple user and host certificates

2015-05-28 Thread Fraser Tweedale
On Thu, May 28, 2015 at 11:52:25AM +0200, Martin Kosek wrote: > On 05/28/2015 11:17 AM, Martin Basti wrote: > > On 28/05/15 10:46, Martin Kosek wrote: > >> On 05/27/2015 06:12 PM, Martin Basti wrote: > >>> On 27/05/15 15:53, Fraser Tweedale wrote: > This patch adds supports for multiple user /

Re: [Freeipa-devel] [PATCH 0014] Support multiple user and host certificates

2015-05-28 Thread Martin Basti
On 28/05/15 11:17, Fraser Tweedale wrote: On Thu, May 28, 2015 at 10:40:22AM +0200, Martin Basti wrote: On 28/05/15 10:13, Fraser Tweedale wrote: On Wed, May 27, 2015 at 06:12:50PM +0200, Martin Basti wrote: On 27/05/15 15:53, Fraser Tweedale wrote: This patch adds supports for multiple user

Re: [Freeipa-devel] [PATCH 0014] Support multiple user and host certificates

2015-05-28 Thread Martin Kosek
On 05/28/2015 11:17 AM, Martin Basti wrote: > On 28/05/15 10:46, Martin Kosek wrote: >> On 05/27/2015 06:12 PM, Martin Basti wrote: >>> On 27/05/15 15:53, Fraser Tweedale wrote: This patch adds supports for multiple user / host certificates. No schema change is needed ('usercertificate'

Re: [Freeipa-devel] [PATCH 0014] Support multiple user and host certificates

2015-05-28 Thread Fraser Tweedale
On Thu, May 28, 2015 at 10:40:22AM +0200, Martin Basti wrote: > On 28/05/15 10:13, Fraser Tweedale wrote: > >On Wed, May 27, 2015 at 06:12:50PM +0200, Martin Basti wrote: > >>On 27/05/15 15:53, Fraser Tweedale wrote: > >>>This patch adds supports for multiple user / host certificates. No > >>>sche

Re: [Freeipa-devel] [PATCH 0014] Support multiple user and host certificates

2015-05-28 Thread Martin Basti
On 28/05/15 10:46, Martin Kosek wrote: On 05/27/2015 06:12 PM, Martin Basti wrote: On 27/05/15 15:53, Fraser Tweedale wrote: This patch adds supports for multiple user / host certificates. No schema change is needed ('usercertificate' attribute is already multi-value). The revoke-previous-cer

Re: [Freeipa-devel] [PATCH 0014] Support multiple user and host certificates

2015-05-28 Thread Martin Kosek
On 05/27/2015 06:12 PM, Martin Basti wrote: > On 27/05/15 15:53, Fraser Tweedale wrote: >> This patch adds supports for multiple user / host certificates. No >> schema change is needed ('usercertificate' attribute is already >> multi-value). The revoke-previous-cert behaviour of host-mod and >> u

Re: [Freeipa-devel] [PATCH 0014] Support multiple user and host certificates

2015-05-28 Thread Martin Basti
On 28/05/15 10:13, Fraser Tweedale wrote: On Wed, May 27, 2015 at 06:12:50PM +0200, Martin Basti wrote: On 27/05/15 15:53, Fraser Tweedale wrote: This patch adds supports for multiple user / host certificates. No schema change is needed ('usercertificate' attribute is already multi-value). Th

Re: [Freeipa-devel] [PATCH 0014] Support multiple user and host certificates

2015-05-28 Thread Fraser Tweedale
On Wed, May 27, 2015 at 06:12:50PM +0200, Martin Basti wrote: > On 27/05/15 15:53, Fraser Tweedale wrote: > >This patch adds supports for multiple user / host certificates. No > >schema change is needed ('usercertificate' attribute is already > >multi-value). The revoke-previous-cert behaviour of

Re: [Freeipa-devel] [PATCH 0014] Support multiple user and host certificates

2015-05-27 Thread Sumit Bose
On Wed, May 27, 2015 at 06:12:50PM +0200, Martin Basti wrote: > On 27/05/15 15:53, Fraser Tweedale wrote: > >This patch adds supports for multiple user / host certificates. No > >schema change is needed ('usercertificate' attribute is already > >multi-value). The revoke-previous-cert behaviour of

Re: [Freeipa-devel] [PATCH 0014] Support multiple user and host certificates

2015-05-27 Thread Martin Basti
On 27/05/15 15:53, Fraser Tweedale wrote: This patch adds supports for multiple user / host certificates. No schema change is needed ('usercertificate' attribute is already multi-value). The revoke-previous-cert behaviour of host-mod and user-mod has been removed but revocation behaviour of -de

Re: [Freeipa-devel] [PATCH 0014] emit a more helpful error messages when CA configuration fails

2015-04-28 Thread Jan Cholasta
Dne 28.4.2015 v 15:03 Martin Basti napsal(a): On 27/04/15 10:54, Martin Babinsky wrote: On 04/24/2015 04:15 PM, Martin Basti wrote: On 20/04/15 12:59, Martin Babinsky wrote: On 04/17/2015 03:56 PM, Martin Babinsky wrote: On 03/05/2015 01:11 PM, Martin Babinsky wrote: https://fedorahosted.org

Re: [Freeipa-devel] [PATCH 0014] emit a more helpful error messages when CA configuration fails

2015-04-28 Thread Martin Basti
On 27/04/15 10:54, Martin Babinsky wrote: On 04/24/2015 04:15 PM, Martin Basti wrote: On 20/04/15 12:59, Martin Babinsky wrote: On 04/17/2015 03:56 PM, Martin Babinsky wrote: On 03/05/2015 01:11 PM, Martin Babinsky wrote: https://fedorahosted.org/freeipa/ticket/4900 ___

Re: [Freeipa-devel] [PATCH 0014] emit a more helpful error messages when CA configuration fails

2015-04-27 Thread Martin Babinsky
On 04/24/2015 04:15 PM, Martin Basti wrote: On 20/04/15 12:59, Martin Babinsky wrote: On 04/17/2015 03:56 PM, Martin Babinsky wrote: On 03/05/2015 01:11 PM, Martin Babinsky wrote: https://fedorahosted.org/freeipa/ticket/4900 ___ Freeipa-devel mail

Re: [Freeipa-devel] [PATCH 0014] emit a more helpful error messages when CA configuration fails

2015-04-24 Thread Martin Basti
On 20/04/15 12:59, Martin Babinsky wrote: On 04/17/2015 03:56 PM, Martin Babinsky wrote: On 03/05/2015 01:11 PM, Martin Babinsky wrote: https://fedorahosted.org/freeipa/ticket/4900 ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www

Re: [Freeipa-devel] [PATCH 0014] emit a more helpful error messages when CA configuration fails

2015-04-20 Thread Martin Babinsky
On 04/17/2015 03:56 PM, Martin Babinsky wrote: On 03/05/2015 01:11 PM, Martin Babinsky wrote: https://fedorahosted.org/freeipa/ticket/4900 ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel

Re: [Freeipa-devel] [PATCH 0014] emit a more helpful error messages when CA configuration fails

2015-04-17 Thread Martin Babinsky
On 03/05/2015 01:11 PM, Martin Babinsky wrote: https://fedorahosted.org/freeipa/ticket/4900 ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel Nobody to review this? -- Martin^3 Babinsky

Re: [Freeipa-devel] [PATCH] 0014 Fix typo causing ipa-upgradeconfig to fail

2014-09-11 Thread Martin Kosek
On 09/10/2014 03:18 PM, Jan Cholasta wrote: > Dne 10.9.2014 v 13:15 David Kupka napsal(a): >> https://fedorahosted.org/freeipa/ticket/4529 > > ACK. > Pushed to master, ipa-4-1, ipa-4-0. Martin ___ Freeipa-devel mailing list Freeipa-devel@redhat.com h

Re: [Freeipa-devel] [PATCH] 0014 Fix typo causing ipa-upgradeconfig to fail

2014-09-10 Thread Jan Cholasta
Dne 10.9.2014 v 13:15 David Kupka napsal(a): https://fedorahosted.org/freeipa/ticket/4529 ACK. -- Jan Cholasta ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel

Re: [Freeipa-devel] [PATCH] 0014 [RFE] ipa migrate-ds should have an argument to specify cert to use for DS connection

2013-10-21 Thread Martin Kosek
On 10/18/2013 05:00 PM, Martin Basti wrote: > Patch attached. > > Ticket: > https://fedorahosted.org/freeipa/ticket/3243 > I did not test the patch, just looked at the code and I have few comments: 1) Please put the ipalib/cli.py change to a sepparate change, we may want to backport it separate

Re: [Freeipa-devel] [PATCH 0014] Improve user addition to default group in host-add

2012-10-03 Thread Martin Kosek
On 10/01/2012 03:38 PM, Tomas Babej wrote: > On 09/26/2012 04:12 PM, Martin Kosek wrote: >> On 09/26/2012 03:23 PM, Tomas Babej wrote: >>> On 09/25/2012 12:37 PM, Tomas Babej wrote: Hi, On adding new user, host-add tries to make it a member of default user group. This, however,

Re: [Freeipa-devel] [PATCH 0014] Improve user addition to default group in host-add

2012-10-01 Thread Tomas Babej
On 09/26/2012 04:12 PM, Martin Kosek wrote: On 09/26/2012 03:23 PM, Tomas Babej wrote: On 09/25/2012 12:37 PM, Tomas Babej wrote: Hi, On adding new user, host-add tries to make it a member of default user group. This, however, can raise AlreadyGroupMember when the user is already member of thi

Re: [Freeipa-devel] [PATCH 0014] Improve user addition to default group in host-add

2012-09-26 Thread Martin Kosek
On 09/26/2012 03:23 PM, Tomas Babej wrote: > On 09/25/2012 12:37 PM, Tomas Babej wrote: >> Hi, >> >> On adding new user, host-add tries to make it a member of default >> user group. This, however, can raise AlreadyGroupMember when the >> user is already member of this group due to automember rule o

Re: [Freeipa-devel] [PATCH 0014] Improve user addition to default group in host-add

2012-09-26 Thread Tomas Babej
On 09/25/2012 12:37 PM, Tomas Babej wrote: Hi, On adding new user, host-add tries to make it a member of default user group. This, however, can raise AlreadyGroupMember when the user is already member of this group due to automember rule or default group configured. This patch makes sure Already

Re: [Freeipa-devel] [PATCH 0014] Improve user addition to default group in host-add

2012-09-26 Thread Petr Viktorin
On 09/25/2012 12:37 PM, Tomas Babej wrote: Hi, On adding new user, host-add tries to make it a member of default user group. This, however, can raise AlreadyGroupMember when the user is already member of this group due to automember rule or default group configured. This patch makes sure Already

Re: [Freeipa-devel] [PATCH] 0014 Add final debug message in installers

2012-04-19 Thread Petr Viktorin
On 04/18/2012 12:38 AM, Dmitri Pal wrote: On 04/17/2012 01:13 PM, Petr Viktorin wrote: On 04/17/2012 06:46 PM, John Dennis wrote: Thank you for the explanation Petr, it's very much appreciated. I do have a problem with this patch and I'm inclined to NAK it, but I'm open to discussion. Here's m

Re: [Freeipa-devel] [PATCH] 0014 Add final debug message in installers

2012-04-17 Thread Dmitri Pal
On 04/17/2012 01:13 PM, Petr Viktorin wrote: > On 04/17/2012 06:46 PM, John Dennis wrote: >> Thank you for the explanation Petr, it's very much appreciated. >> >> I do have a problem with this patch and I'm inclined to NAK it, but I'm >> open to discussion. Here's my thoughts, if I've made mistakes

Re: [Freeipa-devel] [PATCH] 0014 Add final debug message in installers

2012-04-17 Thread Petr Viktorin
On 04/17/2012 06:46 PM, John Dennis wrote: Thank you for the explanation Petr, it's very much appreciated. I do have a problem with this patch and I'm inclined to NAK it, but I'm open to discussion. Here's my thoughts, if I've made mistakes in my reasoning please point them out. The fundamental

Re: [Freeipa-devel] [PATCH] 0014 Add final debug message in installers

2012-04-17 Thread John Dennis
Thank you for the explanation Petr, it's very much appreciated. I do have a problem with this patch and I'm inclined to NAK it, but I'm open to discussion. Here's my thoughts, if I've made mistakes in my reasoning please point them out. The fundamental problem is many of our command line util

Re: [Freeipa-devel] [PATCH] 0014 Add final debug message in installers

2012-04-17 Thread Petr Viktorin
On 04/17/2012 04:12 PM, John Dennis wrote: There have been so many versions of the patch and various comments attached to it I'm afraid I'm still trying to wrap my head around what the actual problem is we're trying to solve, until I have that understanding I can't evaluate the proposed solution.

Re: [Freeipa-devel] [PATCH] 0014 Add final debug message in installers

2012-04-17 Thread John Dennis
There have been so many versions of the patch and various comments attached to it I'm afraid I'm still trying to wrap my head around what the actual problem is we're trying to solve, until I have that understanding I can't evaluate the proposed solution. Could you please state simply what the

Re: [Freeipa-devel] [PATCH] 0014 Add final debug message in installers

2012-04-17 Thread Petr Viktorin
On 04/17/2012 12:12 AM, Rob Crittenden wrote: John Dennis wrote: On 04/16/2012 04:15 PM, Rob Crittenden wrote: John Dennis wrote: On 04/16/2012 01:31 PM, Rob Crittenden wrote: John Dennis wrote: On 04/13/2012 06:25 AM, Petr Viktorin wrote: When the utility sets logging to console, the extra

Re: [Freeipa-devel] [PATCH] 0014 Add final debug message in installers

2012-04-16 Thread Rob Crittenden
John Dennis wrote: On 04/16/2012 04:15 PM, Rob Crittenden wrote: John Dennis wrote: On 04/16/2012 01:31 PM, Rob Crittenden wrote: John Dennis wrote: On 04/13/2012 06:25 AM, Petr Viktorin wrote: When the utility sets logging to console, the extra log message gets printed out there. I agree th

Re: [Freeipa-devel] [PATCH] 0014 Add final debug message in installers

2012-04-16 Thread John Dennis
On 04/16/2012 04:15 PM, Rob Crittenden wrote: John Dennis wrote: On 04/16/2012 01:31 PM, Rob Crittenden wrote: John Dennis wrote: On 04/13/2012 06:25 AM, Petr Viktorin wrote: When the utility sets logging to console, the extra log message gets printed out there. I agree this isn't optimal. At

Re: [Freeipa-devel] [PATCH] 0014 Add final debug message in installers

2012-04-16 Thread Rob Crittenden
John Dennis wrote: On 04/16/2012 01:31 PM, Rob Crittenden wrote: John Dennis wrote: On 04/13/2012 06:25 AM, Petr Viktorin wrote: When the utility sets logging to console, the extra log message gets printed out there. I agree this isn't optimal. Attached patch removes the console log handler be

Re: [Freeipa-devel] [PATCH] 0014 Add final debug message in installers

2012-04-16 Thread John Dennis
On 04/16/2012 01:31 PM, Rob Crittenden wrote: John Dennis wrote: On 04/13/2012 06:25 AM, Petr Viktorin wrote: When the utility sets logging to console, the extra log message gets printed out there. I agree this isn't optimal. Attached patch removes the console log handler before logging the res

Re: [Freeipa-devel] [PATCH] 0014 Add final debug message in installers

2012-04-16 Thread Rob Crittenden
John Dennis wrote: On 04/13/2012 06:25 AM, Petr Viktorin wrote: When the utility sets logging to console, the extra log message gets printed out there. I agree this isn't optimal. Attached patch removes the console log handler before logging the result. I read through log_manager, and found t

Re: [Freeipa-devel] [PATCH] 0014 Add final debug message in installers

2012-04-16 Thread John Dennis
On 04/13/2012 06:25 AM, Petr Viktorin wrote: When the utility sets logging to console, the extra log message gets printed out there. I agree this isn't optimal. Attached patch removes the console log handler before logging the result. I read through log_manager, and found that I can do this mo

Re: [Freeipa-devel] [PATCH] 0014 Add final debug message in installers

2012-04-13 Thread Petr Viktorin
On 04/12/2012 01:30 PM, Petr Viktorin wrote: On 04/10/2012 10:41 PM, Rob Crittenden wrote: Petr Viktorin wrote: On 03/30/2012 11:00 PM, Rob Crittenden wrote: Petr Viktorin wrote: On 03/26/2012 05:35 PM, Petr Viktorin wrote: On 03/26/2012 04:54 PM, Rob Crittenden wrote: Some minor compliant

Re: [Freeipa-devel] [PATCH] 0014 Add final debug message in installers

2012-04-12 Thread John Dennis
On 03/30/2012 06:21 AM, Petr Viktorin wrote: Updated patch: only log if logging has been configured (detected by looking at the root logger's handlers), and changed the message to “The ipa-server-install command has succeeded/failed”. Actually the log_manager has an attribute called configure_s

Re: [Freeipa-devel] [PATCH] 0014 Add final debug message in installers

2012-04-12 Thread Petr Viktorin
On 04/10/2012 10:41 PM, Rob Crittenden wrote: Petr Viktorin wrote: On 03/30/2012 11:00 PM, Rob Crittenden wrote: Petr Viktorin wrote: On 03/26/2012 05:35 PM, Petr Viktorin wrote: On 03/26/2012 04:54 PM, Rob Crittenden wrote: Some minor compliants. Ideally, there would be a routine that s

Re: [Freeipa-devel] [PATCH] 0014 Add final debug message in installers

2012-04-10 Thread Rob Crittenden
Petr Viktorin wrote: On 03/30/2012 11:00 PM, Rob Crittenden wrote: Petr Viktorin wrote: On 03/26/2012 05:35 PM, Petr Viktorin wrote: On 03/26/2012 04:54 PM, Rob Crittenden wrote: Some minor compliants. Ideally, there would be a routine that sets up the logging and handles command-line arg

Re: [Freeipa-devel] [PATCH] 0014 Add final debug message in installers

2012-04-04 Thread Petr Viktorin
On 03/30/2012 11:00 PM, Rob Crittenden wrote: Petr Viktorin wrote: On 03/26/2012 05:35 PM, Petr Viktorin wrote: On 03/26/2012 04:54 PM, Rob Crittenden wrote: Some minor compliants. Ideally, there would be a routine that sets up the logging and handles command-line arguments in some uniform

Re: [Freeipa-devel] [PATCH] 0014 Add final debug message in installers

2012-03-30 Thread Rob Crittenden
Petr Viktorin wrote: On 03/26/2012 05:35 PM, Petr Viktorin wrote: On 03/26/2012 04:54 PM, Rob Crittenden wrote: Some minor compliants. Ideally, there would be a routine that sets up the logging and handles command-line arguments in some uniform way (which is also needed before logging setup

Re: [Freeipa-devel] [PATCH] 0014 Add final debug message in installers

2012-03-30 Thread Petr Viktorin
On 03/26/2012 05:35 PM, Petr Viktorin wrote: On 03/26/2012 04:54 PM, Rob Crittenden wrote: Some minor compliants. Ideally, there would be a routine that sets up the logging and handles command-line arguments in some uniform way (which is also needed before logging setup to detect ipa-server-

Re: [Freeipa-devel] [PATCH] 0014 Add final debug message in installers

2012-03-26 Thread Petr Viktorin
On 03/26/2012 04:54 PM, Rob Crittenden wrote: Some minor compliants. Ideally, there would be a routine that sets up the logging and handles command-line arguments in some uniform way (which is also needed before logging setup to detect ipa-server-install --uninstall). The original patch did

Re: [Freeipa-devel] [PATCH] 0014 Add final debug message in installers

2012-03-26 Thread Rob Crittenden
Petr Viktorin wrote: On 03/15/2012 11:30 AM, Petr Viktorin wrote: On 03/01/2012 11:45 AM, Petr Viktorin wrote: On 02/29/2012 07:46 PM, Rob Crittenden wrote: Martin Kosek wrote: On Mon, 2012-02-27 at 17:51 +0100, Petr Viktorin wrote: On 02/22/2012 10:41 AM, Petr Viktorin wrote: This fixes ht

Re: [Freeipa-devel] [PATCH] 0014 Add final debug message in installers

2012-03-23 Thread Petr Viktorin
On 03/15/2012 11:30 AM, Petr Viktorin wrote: On 03/01/2012 11:45 AM, Petr Viktorin wrote: On 02/29/2012 07:46 PM, Rob Crittenden wrote: Martin Kosek wrote: On Mon, 2012-02-27 at 17:51 +0100, Petr Viktorin wrote: On 02/22/2012 10:41 AM, Petr Viktorin wrote: This fixes https://fedorahosted.org

  1   2   >