Re: [Freeipa-users] ipa -v ping lies about the cert database

2016-05-20 Thread Harald Dunkel
On 05/13/16 14:48, Lukas Slebodnik wrote: > You might see in ticket that planned milestone is "Future Releases" > that isn't any particular release (4.4.x ...) > > It basically mean that patches are welcome. > That's how it works in open source world. > > LS > Sorry, I got confused about the co

Re: [Freeipa-users] ipa -v ping lies about the cert database

2016-05-13 Thread Lukas Slebodnik
On (12/05/16 16:16), Harald Dunkel wrote: >On 04/26/16 17:29, Timo Aaltonen wrote: >> >> I guess 4.3.1 would need to be in sid first, and it just got rejected >> because of the minified javascript (bug #787593). Don't know when >> that'll get fixed. >> > >Since 24beta is out without fixing > >

Re: [Freeipa-users] ipa -v ping lies about the cert database

2016-05-12 Thread Harald Dunkel
On 04/26/16 17:29, Timo Aaltonen wrote: > > I guess 4.3.1 would need to be in sid first, and it just got rejected > because of the minified javascript (bug #787593). Don't know when > that'll get fixed. > Since 24beta is out without fixing https://fedorahosted.org/freeipa/ticket/5639 I

Re: [Freeipa-users] ipa -v ping lies about the cert database

2016-04-26 Thread Timo Aaltonen
27.04.2016, 09:24, Harald Dunkel kirjoitti: > On 04/26/2016 05:29 PM, Timo Aaltonen wrote: >> >> I guess 4.3.1 would need to be in sid first, and it just got rejected >> because of the minified javascript (bug #787593). Don't know when >> that'll get fixed. >> > > Is this 3rd party code? yes: htt

Re: [Freeipa-users] ipa -v ping lies about the cert database

2016-04-26 Thread Harald Dunkel
On 04/26/2016 05:29 PM, Timo Aaltonen wrote: > > I guess 4.3.1 would need to be in sid first, and it just got rejected > because of the minified javascript (bug #787593). Don't know when > that'll get fixed. > Is this 3rd party code? Anyway, I was talking about a *private* backport of freeipa 4

Re: [Freeipa-users] ipa -v ping lies about the cert database

2016-04-26 Thread Timo Aaltonen
26.04.2016, 16:52, Harald Dunkel kirjoitti: > Hi Timo, > > On 04/18/2016 02:08 PM, Timo Aaltonen wrote: >> >> The old package used to create /etc/pki/nssdb on postinst, but with 644 >> permissions so I'm not sure why they have 600 here. 4.1.4 in >> experimental migrated to /etc/ipa/nssdb, and I'm

Re: [Freeipa-users] ipa -v ping lies about the cert database

2016-04-26 Thread Harald Dunkel
Hi Timo, On 04/18/2016 02:08 PM, Timo Aaltonen wrote: > > The old package used to create /etc/pki/nssdb on postinst, but with 644 > permissions so I'm not sure why they have 600 here. 4.1.4 in > experimental migrated to /etc/ipa/nssdb, and I'm about to upload 4.3.1 > to unstable this week, which

Re: [Freeipa-users] ipa -v ping lies about the cert database

2016-04-18 Thread Timo Aaltonen
18.04.2016, 10:14, David Kupka kirjoitti: > On 15/04/16 15:16, Harald Dunkel wrote: >> Hi David, >> >>> Hello Harri, >>> >>> the FreeIPA certificate database is stored in /etc/ipa/nssdb, by >>> default the permissions are set to: >>> >>> $ ls -dl /etc/ipa/nssdb/ >>> drwxr-xr-x. 2 root root 73 Apr 1

Re: [Freeipa-users] ipa -v ping lies about the cert database

2016-04-18 Thread David Kupka
On 15/04/16 15:16, Harald Dunkel wrote: Hi David, Hello Harri, the FreeIPA certificate database is stored in /etc/ipa/nssdb, by default the permissions are set to: $ ls -dl /etc/ipa/nssdb/ drwxr-xr-x. 2 root root 73 Apr 15 14:00 /etc/ipa/nssdb/ $ ls -l /etc/ipa/nssdb/ total 80 -rw-r--r--. 1

Re: [Freeipa-users] ipa -v ping lies about the cert database

2016-04-15 Thread Harald Dunkel
Hi David, > Hello Harri, > > the FreeIPA certificate database is stored in /etc/ipa/nssdb, by default the > permissions are set to: > > $ ls -dl /etc/ipa/nssdb/ > drwxr-xr-x. 2 root root 73 Apr 15 14:00 /etc/ipa/nssdb/ > > $ ls -l /etc/ipa/nssdb/ > total 80 > -rw-r--r--. 1 root root 65536 Apr

Re: [Freeipa-users] ipa -v ping lies about the cert database

2016-04-15 Thread David Kupka
On 15/04/16 11:42, Harald Dunkel wrote: Hi folks, If I run "kinit admin; ipa -v ping" as a regular user, then I get ipa: INFO: trying https://ipa2.example.com/ipa/json ipa: INFO: Connection to https://ipa2.example.com/ipa/json failed with (SEC_ERROR_LEGACY_DATABASE) The certificate/key databas

[Freeipa-users] ipa -v ping lies about the cert database

2016-04-15 Thread Harald Dunkel
Hi folks, If I run "kinit admin; ipa -v ping" as a regular user, then I get ipa: INFO: trying https://ipa2.example.com/ipa/json ipa: INFO: Connection to https://ipa2.example.com/ipa/json failed with (SEC_ERROR_LEGACY_DATABASE) The certificate/key database is in an old, unsupported format. ipa: