Re: [Freeipa-devel] User life cycle: question regarding the design

2014-06-02 Thread Martin Kosek
On 06/02/2014 12:19 PM, thierry bordaz wrote: > On 05/30/2014 03:32 PM, Jan Cholasta wrote: >> On 30.5.2014 15:24, Petr Viktorin wrote: >>> On 05/30/2014 08:37 AM, Martin Kosek wrote: On 05/29/2014 08:14 PM, Dmitri Pal wrote: > On 05/29/2014 08:39 AM, Simo Sorce wrote: >> On Thu, 2014-

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-06-02 Thread thierry bordaz
On 05/30/2014 03:32 PM, Jan Cholasta wrote: On 30.5.2014 15:24, Petr Viktorin wrote: On 05/30/2014 08:37 AM, Martin Kosek wrote: On 05/29/2014 08:14 PM, Dmitri Pal wrote: On 05/29/2014 08:39 AM, Simo Sorce wrote: On Thu, 2014-05-29 at 09:43 +0200, Martin Kosek wrote: On 05/29/2014 05:31 AM,

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-30 Thread Rob Crittenden
Petr Viktorin wrote: > On 05/30/2014 08:37 AM, Martin Kosek wrote: >> On 05/29/2014 08:14 PM, Dmitri Pal wrote: >>> On 05/29/2014 08:39 AM, Simo Sorce wrote: On Thu, 2014-05-29 at 09:43 +0200, Martin Kosek wrote: > On 05/29/2014 05:31 AM, Dmitri Pal wrote: >> On 05/26/2014 01:49 AM, Ma

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-30 Thread Jan Cholasta
On 30.5.2014 15:24, Petr Viktorin wrote: On 05/30/2014 08:37 AM, Martin Kosek wrote: On 05/29/2014 08:14 PM, Dmitri Pal wrote: On 05/29/2014 08:39 AM, Simo Sorce wrote: On Thu, 2014-05-29 at 09:43 +0200, Martin Kosek wrote: On 05/29/2014 05:31 AM, Dmitri Pal wrote: On 05/26/2014 01:49 AM, Ma

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-30 Thread Dmitri Pal
On 05/30/2014 09:24 AM, Petr Viktorin wrote: On 05/30/2014 08:37 AM, Martin Kosek wrote: On 05/29/2014 08:14 PM, Dmitri Pal wrote: On 05/29/2014 08:39 AM, Simo Sorce wrote: On Thu, 2014-05-29 at 09:43 +0200, Martin Kosek wrote: On 05/29/2014 05:31 AM, Dmitri Pal wrote: On 05/26/2014 01:49 AM

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-30 Thread Petr Viktorin
On 05/30/2014 08:37 AM, Martin Kosek wrote: On 05/29/2014 08:14 PM, Dmitri Pal wrote: On 05/29/2014 08:39 AM, Simo Sorce wrote: On Thu, 2014-05-29 at 09:43 +0200, Martin Kosek wrote: On 05/29/2014 05:31 AM, Dmitri Pal wrote: On 05/26/2014 01:49 AM, Martin Kosek wrote: On 05/23/2014 04:55 PM,

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-30 Thread Dmitri Pal
On 05/30/2014 02:37 AM, Martin Kosek wrote: On 05/29/2014 08:14 PM, Dmitri Pal wrote: On 05/29/2014 08:39 AM, Simo Sorce wrote: On Thu, 2014-05-29 at 09:43 +0200, Martin Kosek wrote: On 05/29/2014 05:31 AM, Dmitri Pal wrote: On 05/26/2014 01:49 AM, Martin Kosek wrote: On 05/23/2014 04:55 PM,

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-29 Thread Martin Kosek
On 05/29/2014 08:14 PM, Dmitri Pal wrote: > On 05/29/2014 08:39 AM, Simo Sorce wrote: >> On Thu, 2014-05-29 at 09:43 +0200, Martin Kosek wrote: >>> On 05/29/2014 05:31 AM, Dmitri Pal wrote: On 05/26/2014 01:49 AM, Martin Kosek wrote: > On 05/23/2014 04:55 PM, Simo Sorce wrote: >> On Fr

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-29 Thread Dmitri Pal
On 05/29/2014 08:39 AM, Simo Sorce wrote: On Thu, 2014-05-29 at 09:43 +0200, Martin Kosek wrote: On 05/29/2014 05:31 AM, Dmitri Pal wrote: On 05/26/2014 01:49 AM, Martin Kosek wrote: On 05/23/2014 04:55 PM, Simo Sorce wrote: On Fri, 2014-05-23 at 10:13 -0400, Rob Crittenden wrote: This, I be

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-29 Thread Simo Sorce
On Thu, 2014-05-29 at 10:06 +0200, Petr Viktorin wrote: > > Let me try to consolidate again the proposals and changes for the > > workflow&API > > we have so far: > > > > 1) Manipulating staged users > > - staged users must have UID RDN > > - UID uniqueness plugin should not be enforcing in stagin

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-29 Thread Simo Sorce
On Thu, 2014-05-29 at 09:43 +0200, Martin Kosek wrote: > On 05/29/2014 05:31 AM, Dmitri Pal wrote: > > On 05/26/2014 01:49 AM, Martin Kosek wrote: > >> On 05/23/2014 04:55 PM, Simo Sorce wrote: > >>> On Fri, 2014-05-23 at 10:13 -0400, Rob Crittenden wrote: > This, I believe, has already been c

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-29 Thread Martin Kosek
On 05/29/2014 10:06 AM, Petr Viktorin wrote: > On 05/29/2014 09:43 AM, Martin Kosek wrote: ... >> 1) Manipulating staged users >> - staged users must have UID RDN >> - UID uniqueness plugin should not be enforcing in staging area >> - we do not want it in user plugin as it requires different parame

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-29 Thread Jan Cholasta
On 29.5.2014 09:43, Martin Kosek wrote: On 05/29/2014 05:31 AM, Dmitri Pal wrote: On 05/26/2014 01:49 AM, Martin Kosek wrote: On 05/23/2014 04:55 PM, Simo Sorce wrote: On Fri, 2014-05-23 at 10:13 -0400, Rob Crittenden wrote: This, I believe, has already been covered, but I'm concerned with th

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-29 Thread Petr Viktorin
On 05/29/2014 09:43 AM, Martin Kosek wrote: On 05/29/2014 05:31 AM, Dmitri Pal wrote: On 05/26/2014 01:49 AM, Martin Kosek wrote: On 05/23/2014 04:55 PM, Simo Sorce wrote: On Fri, 2014-05-23 at 10:13 -0400, Rob Crittenden wrote: This, I believe, has already been covered, but I'm concerned wit

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-29 Thread Martin Kosek
On 05/29/2014 05:31 AM, Dmitri Pal wrote: > On 05/26/2014 01:49 AM, Martin Kosek wrote: >> On 05/23/2014 04:55 PM, Simo Sorce wrote: >>> On Fri, 2014-05-23 at 10:13 -0400, Rob Crittenden wrote: This, I believe, has already been covered, but I'm concerned with the (over)use of active/inact

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-28 Thread Dmitri Pal
On 05/26/2014 01:49 AM, Martin Kosek wrote: On 05/23/2014 04:55 PM, Simo Sorce wrote: On Fri, 2014-05-23 at 10:13 -0400, Rob Crittenden wrote: This, I believe, has already been covered, but I'm concerned with the (over)use of active/inactive in this discussion. I think use of "inactive" and "a

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-28 Thread Dmitri Pal
On 05/23/2014 01:01 PM, Simo Sorce wrote: On Fri, 2014-05-23 at 17:47 +0200, thierry bordaz wrote: About membership. I think it could be risky to keep membership in 'delete' or 'stage'. Those entries are not valid user and should not belong to any active group. Should we keep membership attribut

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-27 Thread Jan Cholasta
On 26.5.2014 10:18, Martin Kosek wrote: On 05/26/2014 09:33 AM, Jan Cholasta wrote: On 26.5.2014 07:49, Martin Kosek wrote: ... > 5) modifying > (in active) ipa user-mod tuser ... Ok. > (in stage)ipa user-mod tuser --staged ... Simo did not like this command, I would personally

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-26 Thread Alexander Bokovoy
On Mon, 26 May 2014, Martin Kosek wrote: On 05/26/2014 09:33 AM, Jan Cholasta wrote: On 26.5.2014 07:49, Martin Kosek wrote: ... > 5) modifying > (in active) ipa user-mod tuser ... Ok. > (in stage)ipa user-mod tuser --staged ... Simo did not like this command, I would personally ad

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-26 Thread thierry bordaz
On 05/26/2014 10:18 AM, Martin Kosek wrote: On 05/26/2014 09:33 AM, Jan Cholasta wrote: On 26.5.2014 07:49, Martin Kosek wrote: ... > 5) modifying > (in active) ipa user-mod tuser ... Ok. > (in stage)ipa user-mod tuser --staged ... Simo did not like this command, I would persona

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-26 Thread Martin Kosek
On 05/26/2014 09:33 AM, Jan Cholasta wrote: > On 26.5.2014 07:49, Martin Kosek wrote: ... >> > 5) modifying >> > (in active) ipa user-mod tuser ... >> >> Ok. >> >> > (in stage)ipa user-mod tuser --staged ... >> >> Simo did not like this command, I would personally add it. As long as we >>

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-26 Thread thierry bordaz
On 05/26/2014 07:49 AM, Martin Kosek wrote: On 05/23/2014 04:55 PM, Simo Sorce wrote: On Fri, 2014-05-23 at 10:13 -0400, Rob Crittenden wrote: This, I believe, has already been covered, but I'm concerned with the (over)use of active/inactive in this discussion. I think use of "inactive" and "a

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-26 Thread Jan Cholasta
On 26.5.2014 07:49, Martin Kosek wrote: On 05/23/2014 04:55 PM, Simo Sorce wrote: On Fri, 2014-05-23 at 10:13 -0400, Rob Crittenden wrote: This, I believe, has already been covered, but I'm concerned with the (over)use of active/inactive in this discussion. I think use of "inactive" and "activ

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-25 Thread Martin Kosek
On 05/23/2014 04:55 PM, Simo Sorce wrote: On Fri, 2014-05-23 at 10:13 -0400, Rob Crittenden wrote: This, I believe, has already been covered, but I'm concerned with the (over)use of active/inactive in this discussion. I think use of "inactive" and "active" to describe users might be confusing s

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-23 Thread Simo Sorce
On Fri, 2014-05-23 at 17:47 +0200, thierry bordaz wrote: > About membership. I think it could be risky to keep membership in > 'delete' or 'stage'. Those entries are not valid user and should not > belong to any active group. Should we keep membership attributes in > those state or let the plugi

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-23 Thread thierry bordaz
On 05/23/2014 10:13 AM, Petr Viktorin wrote: On 05/23/2014 08:33 AM, Martin Kosek wrote: On 05/23/2014 07:48 AM, Jan Cholasta wrote: On 22.5.2014 19:27, Simo Sorce wrote: On Thu, 2014-05-22 at 15:35 +0200, Martin Kosek wrote: On 05/21/2014 10:11 PM, Dmitri Pal wrote: On 05/21/2014 03:06 PM,

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-23 Thread Simo Sorce
On Fri, 2014-05-23 at 10:13 -0400, Rob Crittenden wrote: > This, I believe, has already been covered, but I'm concerned with the > (over)use of active/inactive in this discussion. > > I think use of "inactive" and "active" to describe users might be > confusing since there is already an account en

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-23 Thread Simo Sorce
On Fri, 2014-05-23 at 08:33 +0200, Martin Kosek wrote: > On 05/23/2014 07:48 AM, Jan Cholasta wrote: > > On 22.5.2014 19:27, Simo Sorce wrote: > >> On Thu, 2014-05-22 at 15:35 +0200, Martin Kosek wrote: > >>> On 05/21/2014 10:11 PM, Dmitri Pal wrote: > On 05/21/2014 03:06 PM, Martin Kosek wrot

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-23 Thread Rob Crittenden
Martin Kosek wrote: > On 05/23/2014 07:48 AM, Jan Cholasta wrote: >> On 22.5.2014 19:27, Simo Sorce wrote: >>> On Thu, 2014-05-22 at 15:35 +0200, Martin Kosek wrote: On 05/21/2014 10:11 PM, Dmitri Pal wrote: > On 05/21/2014 03:06 PM, Martin Kosek wrote: >> On 05/21/2014 08:14 PM, Simo

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-23 Thread Jan Cholasta
On 23.5.2014 10:13, Petr Viktorin wrote: On 05/23/2014 08:33 AM, Martin Kosek wrote: On 05/23/2014 07:48 AM, Jan Cholasta wrote: On 22.5.2014 19:27, Simo Sorce wrote: On Thu, 2014-05-22 at 15:35 +0200, Martin Kosek wrote: On 05/21/2014 10:11 PM, Dmitri Pal wrote: On 05/21/2014 03:06 PM, Mart

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-23 Thread Petr Viktorin
On 05/23/2014 08:33 AM, Martin Kosek wrote: On 05/23/2014 07:48 AM, Jan Cholasta wrote: On 22.5.2014 19:27, Simo Sorce wrote: On Thu, 2014-05-22 at 15:35 +0200, Martin Kosek wrote: On 05/21/2014 10:11 PM, Dmitri Pal wrote: On 05/21/2014 03:06 PM, Martin Kosek wrote: On 05/21/2014 08:14 PM, S

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-22 Thread Martin Kosek
On 05/23/2014 07:48 AM, Jan Cholasta wrote: > On 22.5.2014 19:27, Simo Sorce wrote: >> On Thu, 2014-05-22 at 15:35 +0200, Martin Kosek wrote: >>> On 05/21/2014 10:11 PM, Dmitri Pal wrote: On 05/21/2014 03:06 PM, Martin Kosek wrote: > On 05/21/2014 08:14 PM, Simo Sorce wrote: >> On Wed,

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-22 Thread Jan Cholasta
On 22.5.2014 19:27, Simo Sorce wrote: On Thu, 2014-05-22 at 15:35 +0200, Martin Kosek wrote: On 05/21/2014 10:11 PM, Dmitri Pal wrote: On 05/21/2014 03:06 PM, Martin Kosek wrote: On 05/21/2014 08:14 PM, Simo Sorce wrote: On Wed, 2014-05-21 at 16:01 +0200, thierry bordaz wrote: Hello,

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-22 Thread Simo Sorce
On Thu, 2014-05-22 at 15:35 +0200, Martin Kosek wrote: > On 05/21/2014 10:11 PM, Dmitri Pal wrote: > > On 05/21/2014 03:06 PM, Martin Kosek wrote: > >> On 05/21/2014 08:14 PM, Simo Sorce wrote: > >>> On Wed, 2014-05-21 at 16:01 +0200, thierry bordaz wrote: > Hello, > > Thanks fo

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-22 Thread Martin Kosek
On 05/21/2014 10:11 PM, Dmitri Pal wrote: > On 05/21/2014 03:06 PM, Martin Kosek wrote: >> On 05/21/2014 08:14 PM, Simo Sorce wrote: >>> On Wed, 2014-05-21 at 16:01 +0200, thierry bordaz wrote: Hello, Thanks for all these detailed descriptions. Just to be sure to be on

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-22 Thread thierry bordaz
On 05/21/2014 09:06 PM, Martin Kosek wrote: On 05/21/2014 08:14 PM, Simo Sorce wrote: On Wed, 2014-05-21 at 16:01 +0200, thierry bordaz wrote: Hello, Thanks for all these detailed descriptions. Just to be sure to be on the same page, here is my understanding of the provisionin

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-21 Thread Dmitri Pal
On 05/21/2014 03:06 PM, Martin Kosek wrote: On 05/21/2014 08:14 PM, Simo Sorce wrote: On Wed, 2014-05-21 at 16:01 +0200, thierry bordaz wrote: Hello, Thanks for all these detailed descriptions. Just to be sure to be on the same page, here is my understanding of the provisionin

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-21 Thread Martin Kosek
On 05/21/2014 08:14 PM, Simo Sorce wrote: On Wed, 2014-05-21 at 16:01 +0200, thierry bordaz wrote: Hello, Thanks for all these detailed descriptions. Just to be sure to be on the same page, here is my understanding of the provisioning templates and placeholder definitions. An

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-21 Thread Simo Sorce
On Wed, 2014-05-21 at 16:01 +0200, thierry bordaz wrote: > Hello, > > Thanks for all these detailed descriptions. > Just to be sure to be on the same page, here is my understanding of > the provisioning templates and placeholder definitions. An > administrator can provide a provisi

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-21 Thread thierry bordaz
On 05/20/2014 10:30 PM, Martin Kosek wrote: I am sharing the question below with the list as I think the information is useful and relevant for everyone interested in this feature. See answers in the text. On 05/20/2014 06:26 PM, thierry bordaz wrote: Hello Martin, Petr, I implemented 'u

Re: [Freeipa-devel] User life cycle: question regarding the design

2014-05-20 Thread Martin Kosek
I am sharing the question below with the list as I think the information is useful and relevant for everyone interested in this feature. See answers in the text. On 05/20/2014 06:26 PM, thierry bordaz wrote: Hello Martin, Petr, I implemented 'user-add --to-stage' in a very simple way. Bas