Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-07-12 Thread Lukas Slebodnik
On (23/06/14 14:35), Simo Sorce wrote: - Original Message - - Original Message - Can you check if ipaProtectedOperation is in the aci attribute in the base tree object ? It should be there as excluded, and that should cause admin to not be able to retrieve keytabs.

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-27 Thread Alexander Bokovoy
On Thu, 26 Jun 2014, Simo Sorce wrote: On Thu, 2014-06-26 at 10:20 -0400, Simo Sorce wrote: On Thu, 2014-06-26 at 15:33 +0300, Alexander Bokovoy wrote: On Thu, 26 Jun 2014, Martin Kosek wrote: On 06/26/2014 04:29 AM, Nathaniel McCallum wrote: On Mon, 2014-06-23 at 17:24 -0400, Nathaniel

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-27 Thread Martin Kosek
On 06/27/2014 10:00 AM, Alexander Bokovoy wrote: On Thu, 26 Jun 2014, Simo Sorce wrote: On Thu, 2014-06-26 at 10:20 -0400, Simo Sorce wrote: On Thu, 2014-06-26 at 15:33 +0300, Alexander Bokovoy wrote: On Thu, 26 Jun 2014, Martin Kosek wrote: On 06/26/2014 04:29 AM, Nathaniel McCallum wrote:

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-26 Thread Martin Kosek
On 06/26/2014 04:29 AM, Nathaniel McCallum wrote: On Mon, 2014-06-23 at 17:24 -0400, Nathaniel McCallum wrote: On Mon, 2014-06-23 at 14:35 -0400, Simo Sorce wrote: - Original Message - - Original Message - Can you check if ipaProtectedOperation is in the aci attribute in the

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-26 Thread Alexander Bokovoy
On Thu, 26 Jun 2014, Martin Kosek wrote: On 06/26/2014 04:29 AM, Nathaniel McCallum wrote: On Mon, 2014-06-23 at 17:24 -0400, Nathaniel McCallum wrote: On Mon, 2014-06-23 at 14:35 -0400, Simo Sorce wrote: - Original Message - - Original Message - Can you check if

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-26 Thread Tomas Babej
On 06/26/2014 02:33 PM, Alexander Bokovoy wrote: On Thu, 26 Jun 2014, Martin Kosek wrote: On 06/26/2014 04:29 AM, Nathaniel McCallum wrote: On Mon, 2014-06-23 at 17:24 -0400, Nathaniel McCallum wrote: On Mon, 2014-06-23 at 14:35 -0400, Simo Sorce wrote: - Original Message - -

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-26 Thread Simo Sorce
On Thu, 2014-06-26 at 15:33 +0300, Alexander Bokovoy wrote: On Thu, 26 Jun 2014, Martin Kosek wrote: On 06/26/2014 04:29 AM, Nathaniel McCallum wrote: On Mon, 2014-06-23 at 17:24 -0400, Nathaniel McCallum wrote: On Mon, 2014-06-23 at 14:35 -0400, Simo Sorce wrote: - Original Message

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-26 Thread Simo Sorce
On Thu, 2014-06-26 at 10:20 -0400, Simo Sorce wrote: On Thu, 2014-06-26 at 15:33 +0300, Alexander Bokovoy wrote: On Thu, 26 Jun 2014, Martin Kosek wrote: On 06/26/2014 04:29 AM, Nathaniel McCallum wrote: On Mon, 2014-06-23 at 17:24 -0400, Nathaniel McCallum wrote: On Mon, 2014-06-23 at

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-26 Thread Simo Sorce
On Thu, 2014-06-26 at 10:37 +0200, Martin Kosek wrote: On 06/26/2014 04:29 AM, Nathaniel McCallum wrote: On Mon, 2014-06-23 at 17:24 -0400, Nathaniel McCallum wrote: On Mon, 2014-06-23 at 14:35 -0400, Simo Sorce wrote: - Original Message - - Original Message - Can you

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-25 Thread Nathaniel McCallum
On Mon, 2014-06-23 at 17:24 -0400, Nathaniel McCallum wrote: On Mon, 2014-06-23 at 14:35 -0400, Simo Sorce wrote: - Original Message - - Original Message - Can you check if ipaProtectedOperation is in the aci attribute in the base tree object ? It should be

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-24 Thread Simo Sorce
- Original Message - On Fri, 2014-06-20 at 16:05 -0400, Simo Sorce wrote: On Fri, 2014-06-20 at 14:47 -0400, Nathaniel McCallum wrote: This change would have very small impact on your patch set, but would be much clearer for the future consumers of this protocol. Code can be

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-23 Thread Nathaniel McCallum
On Fri, 2014-06-20 at 19:55 -0400, Simo Sorce wrote: On Fri, 2014-06-20 at 16:50 -0400, Nathaniel McCallum wrote: On Fri, 2014-06-20 at 16:05 -0400, Simo Sorce wrote: On Fri, 2014-06-20 at 14:47 -0400, Nathaniel McCallum wrote: This change would have very small impact on your patch set,

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-23 Thread Nathaniel McCallum
On Fri, 2014-06-20 at 19:55 -0400, Simo Sorce wrote: On Fri, 2014-06-20 at 16:50 -0400, Nathaniel McCallum wrote: On Fri, 2014-06-20 at 16:05 -0400, Simo Sorce wrote: On Fri, 2014-06-20 at 14:47 -0400, Nathaniel McCallum wrote: This change would have very small impact on your patch set,

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-23 Thread Simo Sorce
- Original Message - Can you check if ipaProtectedOperation is in the aci attribute in the base tree object ? It should be there as excluded, and that should cause admin to not be able to retrieve keytabs. It was not. While running ipa-ldap-updater I got the following:

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-23 Thread Nathaniel McCallum
On Mon, 2014-06-23 at 14:35 -0400, Simo Sorce wrote: - Original Message - - Original Message - Can you check if ipaProtectedOperation is in the aci attribute in the base tree object ? It should be there as excluded, and that should cause admin to not be able to

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-20 Thread Nathaniel McCallum
On Mon, 2014-06-16 at 11:34 -0400, Simo Sorce wrote: Although the code is all done it would be nice to have a review of the feature, to see if it has all been captured: http://www.freeipa.org/page/V4/Keytab_Retrieval I'm a bit confused about the behavior of enctypes in the Request. A list of

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-20 Thread Simo Sorce
On Fri, 2014-06-20 at 14:05 -0400, Nathaniel McCallum wrote: On Mon, 2014-06-16 at 11:34 -0400, Simo Sorce wrote: Although the code is all done it would be nice to have a review of the feature, to see if it has all been captured: http://www.freeipa.org/page/V4/Keytab_Retrieval I'm a bit

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-20 Thread Nathaniel McCallum
On Fri, 2014-06-20 at 14:10 -0400, Simo Sorce wrote: On Fri, 2014-06-20 at 14:05 -0400, Nathaniel McCallum wrote: On Mon, 2014-06-16 at 11:34 -0400, Simo Sorce wrote: Although the code is all done it would be nice to have a review of the feature, to see if it has all been captured:

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-20 Thread Simo Sorce
On Fri, 2014-06-20 at 14:30 -0400, Nathaniel McCallum wrote: On Fri, 2014-06-20 at 14:10 -0400, Simo Sorce wrote: On Fri, 2014-06-20 at 14:05 -0400, Nathaniel McCallum wrote: On Mon, 2014-06-16 at 11:34 -0400, Simo Sorce wrote: Although the code is all done it would be nice to have a

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-20 Thread Nathaniel McCallum
On Fri, 2014-06-20 at 14:38 -0400, Simo Sorce wrote: On Fri, 2014-06-20 at 14:30 -0400, Nathaniel McCallum wrote: On Fri, 2014-06-20 at 14:10 -0400, Simo Sorce wrote: On Fri, 2014-06-20 at 14:05 -0400, Nathaniel McCallum wrote: On Mon, 2014-06-16 at 11:34 -0400, Simo Sorce wrote:

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-20 Thread Nathaniel McCallum
On Mon, 2014-06-16 at 11:34 -0400, Simo Sorce wrote: Although the code is all done it would be nice to have a review of the feature, to see if it has all been captured: http://www.freeipa.org/page/V4/Keytab_Retrieval Is there any need to create different permissions for password generation vs

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-20 Thread Nathaniel McCallum
On Fri, 2014-06-20 at 15:50 -0400, Nathaniel McCallum wrote: On Mon, 2014-06-16 at 11:34 -0400, Simo Sorce wrote: Although the code is all done it would be nice to have a review of the feature, to see if it has all been captured: http://www.freeipa.org/page/V4/Keytab_Retrieval Is there

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-20 Thread Simo Sorce
On Fri, 2014-06-20 at 15:50 -0400, Nathaniel McCallum wrote: On Mon, 2014-06-16 at 11:34 -0400, Simo Sorce wrote: Although the code is all done it would be nice to have a review of the feature, to see if it has all been captured: http://www.freeipa.org/page/V4/Keytab_Retrieval Is there

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-20 Thread Simo Sorce
On Fri, 2014-06-20 at 15:55 -0400, Nathaniel McCallum wrote: On Fri, 2014-06-20 at 15:50 -0400, Nathaniel McCallum wrote: On Mon, 2014-06-16 at 11:34 -0400, Simo Sorce wrote: Although the code is all done it would be nice to have a review of the feature, to see if it has all been

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-20 Thread Nathaniel McCallum
On Fri, 2014-06-20 at 16:05 -0400, Simo Sorce wrote: On Fri, 2014-06-20 at 14:47 -0400, Nathaniel McCallum wrote: This change would have very small impact on your patch set, but would be much clearer for the future consumers of this protocol. Code can be changed; protocols can't. Ok

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-20 Thread Simo Sorce
On Fri, 2014-06-20 at 16:50 -0400, Nathaniel McCallum wrote: On Fri, 2014-06-20 at 16:05 -0400, Simo Sorce wrote: On Fri, 2014-06-20 at 14:47 -0400, Nathaniel McCallum wrote: This change would have very small impact on your patch set, but would be much clearer for the future consumers

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-17 Thread Martin Kosek
On 06/16/2014 05:34 PM, Simo Sorce wrote: Although the code is all done it would be nice to have a review of the feature, to see if it has all been captured: http://www.freeipa.org/page/V4/Keytab_Retrieval Simo. Thanks! I was not deeply involved in the review, but from the high level it

Re: [Freeipa-devel] Design Review Keytab Retrieval

2014-06-17 Thread Simo Sorce
On Tue, 2014-06-17 at 09:18 +0200, Martin Kosek wrote: On 06/16/2014 05:34 PM, Simo Sorce wrote: Although the code is all done it would be nice to have a review of the feature, to see if it has all been captured: http://www.freeipa.org/page/V4/Keytab_Retrieval Simo. Thanks! I was