[SSSD] [sssd PR#132][closed] Add "Wants=" to sssd unit

2020-01-02 Thread fidencio
   URL: https://github.com/SSSD/sssd/pull/132
Author: fidencio
 Title: #132: Add "Wants=" to sssd unit
Action: closed

To pull the PR as Git branch:
git remote add ghsssd https://github.com/SSSD/sssd
git fetch ghsssd pull/132/head:pr132
git checkout pr132
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/sssd-devel@lists.fedorahosted.org


[SSSD] [sssd PR#546][comment] TESTS: Re-add tests for `kdestroy -A`

2019-09-17 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/546
Title: #546: TESTS: Re-add tests for `kdestroy -A`

fidencio commented:
"""
@alexey-tikhonov,

Thanks for taking a look in the PR. At this point, being out of SSSD project 
for more than 1 year, without touching this PR for more than 1.5 years, I don't 
actually feel comfortable rebasing it and re-submitting without giving it some 
proper tests. Unfortunately, I have no time for testing it properly.

In the end, it's a 10 lines patch, feel free to just copy and paste it 
accordingly. Mentioning the original author (me) is highly desirable.

Best Regards,
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/546#issuecomment-532218355
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/sssd-devel@lists.fedorahosted.org


[SSSD] [sssd PR#546][comment] TESTS: Re-add tests for `kdestroy -A`

2019-09-17 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/546
Title: #546: TESTS: Re-add tests for `kdestroy -A`

fidencio commented:
"""
@alexey-tikhonov,

Thanks for taking a look in the PR. At this point, being out of SSSD project 
for more than 1 year, without touching this PR for more than 1.5 years, I don't 
actually feel comfortable rebasing it and re-submitting without giving it some 
proper tests. Unfortunately, I have to time for testing it properly.

In the end, it's a 10 lines patch, feel free to just copy and paste it 
accordingly. Mentioning the original author (me) is highly desirable.

Best Regards,
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/546#issuecomment-532218355
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/sssd-devel@lists.fedorahosted.org


[SSSD] [sssd PR#132][comment] Add "Wants=" to sssd unit

2018-08-24 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/132
Title: #132: Add "Wants=" to sssd unit

fidencio commented:
"""
@jhrozek, patch set has been updated.

Now it also checks the confdb in order to now what we should do.

Please, give it a try, all the issues you have seen should be resolved.

In case something is still missing, I'd like to leave these patches here and 
someone else can keep working on this as I'm not part of SSSD team anymore. Of 
course, please,  **keep my authorship on my patches** or at least mention your 
work has been based on them.

Unfortunately this PR took way too long to get the attention it needed. :-(
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/132#issuecomment-415790746
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/5APCQM5RFJGHB2CXC5ZMTOGPIKXPQ37I/


[SSSD] [sssd PR#132][comment] Add "Wants=" to sssd unit

2018-08-24 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/132
Title: #132: Add "Wants=" to sssd unit

fidencio commented:
"""
@jhrozek, patch set has been updated.

Now it also checks the confdb in order to now what we should do.

Please, give it a try, all the issues you have seen should be resolved.

In case something is still missing, I'd like to leave this patches here and 
someone else can keep working on this as I'm not part of SSSD team anymore. Of 
course, please,  **keep my authorship on my patches** or at least mention your 
work has been based on them.

Unfortunately this PR took way too long to get the attention it needed. :-(
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/132#issuecomment-415790746
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/4EGF3NXBWWU4JKMBJCSCJIW6FLBOCNT4/


[SSSD] [sssd PR#132][synchronized] Add "Wants=" to sssd unit

2018-08-22 Thread fidencio
   URL: https://github.com/SSSD/sssd/pull/132
Author: fidencio
 Title: #132: Add "Wants=" to sssd unit
Action: synchronized

To pull the PR as Git branch:
git remote add ghsssd https://github.com/SSSD/sssd
git fetch ghsssd pull/132/head:pr132
git checkout pr132
From f4f8df520184aa51cad48b718923f1c15e9eef78 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Fabiano=20Fid=C3=AAncio?= 
Date: Tue, 24 Jan 2017 09:36:34 +0100
Subject: [PATCH 1/4] sssd: add a list of dependent services to sssd.service
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit

Let's add a list of dependent services to the sssd unit file so we can
have all those services enable by default when enabling sssd unit.

As it differs from our first approach were all services were disabled by
default, the manuals have also been updated.

Signed-off-by: Fabiano Fidêncio 
---
 Makefile.am  | 14 +-
 src/man/sssd-sudo.5.xml  |  3 +--
 src/man/sssd.conf.5.xml  | 12 +---
 src/sysv/systemd/sssd.service.in |  2 +-
 4 files changed, 24 insertions(+), 7 deletions(-)

diff --git a/Makefile.am b/Makefile.am
index 1b4f0443b..8f93c63c1 100644
--- a/Makefile.am
+++ b/Makefile.am
@@ -4880,6 +4880,7 @@ endif
 init_SCRIPTS =
 systemdunit_DATA =
 systemdconf_DATA =
+sssd_dependent_services =
 if HAVE_SYSTEMD_UNIT
 systemdunit_DATA += \
 src/sysv/systemd/sssd.service \
@@ -4889,11 +4890,15 @@ if HAVE_SYSTEMD_UNIT
 src/sysv/systemd/sssd-pam-priv.socket \
 src/sysv/systemd/sssd-pam.service \
 $(NULL)
+
+sssd_dependent_services += sssd-nss.socket sssd-pam.socket
 if BUILD_AUTOFS
 systemdunit_DATA += \
 src/sysv/systemd/sssd-autofs.socket \
 src/sysv/systemd/sssd-autofs.service \
 $(NULL)
+
+sssd_dependent_services += sssd-autofs.socket
 endif
 if BUILD_IFP
 systemdunit_DATA += \
@@ -4905,6 +4910,8 @@ if BUILD_PAC_RESPONDER
 src/sysv/systemd/sssd-pac.socket \
 src/sysv/systemd/sssd-pac.service \
 $(NULL)
+
+sssd_dependent_services += sssd-pac.socket
 endif
 if BUILD_SECRETS
 systemdunit_DATA += \
@@ -4917,12 +4924,16 @@ if BUILD_SSH
 src/sysv/systemd/sssd-ssh.socket \
 src/sysv/systemd/sssd-ssh.service \
 $(NULL)
+
+sssd_dependent_services += sssd-ssh.socket
 endif
 if BUILD_SUDO
 systemdunit_DATA += \
 src/sysv/systemd/sssd-sudo.socket \
 src/sysv/systemd/sssd-sudo.service \
 $(NULL)
+
+sssd_dependent_services += sssd-sudo.socket
 endif
 if BUILD_KCM
 systemdunit_DATA += \
@@ -4969,7 +4980,8 @@ edit_cmd = $(SED) \
 -e 's|@libexecdir[@]|$(libexecdir)|g' \
 -e 's|@pipepath[@]|$(pipepath)|g' \
 -e 's|@prefix[@]|$(prefix)|g' \
--e 's|@SSSD_USER[@]|$(SSSD_USER)|g'
+-e 's|@SSSD_USER[@]|$(SSSD_USER)|g' \
+-e 's|@sssd_dependent_services[@]|${sssd_dependent_services}|g'
 
 replace_script = \
 @rm -f $@ $@.tmp; \
diff --git a/src/man/sssd-sudo.5.xml b/src/man/sssd-sudo.5.xml
index 5bc56c463..cb085419a 100644
--- a/src/man/sssd-sudo.5.xml
+++ b/src/man/sssd-sudo.5.xml
@@ -110,8 +110,7 @@ ldap_sudo_search_base = ou=sudoers,dc=example,dc=com
 
 It's important to note that on platforms where systemd is supported
 there's no need to add the "sudo" provider to the list of services,
-as it became optional. However, sssd-sudo.socket must be enabled
-instead.
+as it became optional.
 
 
 
diff --git a/src/man/sssd.conf.5.xml b/src/man/sssd.conf.5.xml
index 881ffc6ab..23f59e0e8 100644
--- a/src/man/sssd.conf.5.xml
+++ b/src/man/sssd.conf.5.xml
@@ -220,9 +220,15 @@
 
 
 
-By default, all services are disabled and the administrator
-must enable the ones allowed to be used by executing:
-"systemctl enable sssd-@service@.socket".
+By default, the following services are enabled: nss, pam
+, sudo
+, autofs
+, ssh
+, pac
+, ifp
+In case the Administrator wants to persistently disable
+one of them, it can be done by running:
+"systemctl mask sssd-@service@.socket"
 
 
 
diff --git a/src/sysv/systemd/sssd.service.in b/src/sysv/systemd/sssd.service.in
index 0c515d34c..49c09ea58 100644
--- a/src/sysv/systemd/sssd.service.in
+++ b/src/sysv/systemd/sssd.servic

[SSSD] [sssd PR#641][closed] Minor fixes related to converting of ldap attributes to bytes

2018-08-20 Thread fidencio
   URL: https://github.com/SSSD/sssd/pull/641
Author: mrniranjan
 Title: #641: Minor fixes related to converting of ldap attributes to bytes
Action: closed

To pull the PR as Git branch:
git remote add ghsssd https://github.com/SSSD/sssd
git fetch ghsssd pull/641/head:pr641
git checkout pr641
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/XOGKM4HL3PJDERAYSZBPYIXHWOZFRM3F/


[SSSD] [sssd PR#641][comment] Minor fixes related to converting of ldap attributes to bytes

2018-08-17 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/641
Title: #641: Minor fixes related to converting of ldap attributes to bytes

fidencio commented:
"""
ok to test
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/641#issuecomment-41398
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/LF6AVPDIUPWB7B5MUM6BUFAI4URNSTOT/


[SSSD] [sssd PR#640][closed] Python3 changes to multihost tests

2018-08-17 Thread fidencio
   URL: https://github.com/SSSD/sssd/pull/640
Author: mrniranjan
 Title: #640: Python3 changes to multihost tests
Action: closed

To pull the PR as Git branch:
git remote add ghsssd https://github.com/SSSD/sssd
git fetch ghsssd pull/640/head:pr640
git checkout pr640
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/EVWZYXMI2RZTI7MIZAVPQ7ZXCXRLHXAV/


[SSSD] [sssd PR#640][+Pushed] Python3 changes to multihost tests

2018-08-17 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/640
Title: #640: Python3 changes to multihost tests

Label: +Pushed
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/5IYGJOQRDBZBI3FXRCR6ME5VO7233Z4H/


[SSSD] [sssd PR#640][comment] Python3 changes to multihost tests

2018-08-17 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/640
Title: #640: Python3 changes to multihost tests

fidencio commented:
"""
master:
 c0374e1
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/640#issuecomment-413853181
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/BDQGBUC4OISBEXYWW4AXO3UX4V72UQXS/


[SSSD] [sssd PR#640][comment] Python3 changes to multihost tests

2018-08-17 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/640
Title: #640: Python3 changes to multihost tests

fidencio commented:
"""
After a second talk with @mrniranjan, he told me to go ahead and the changes 
will be submit in a second PR.
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/640#issuecomment-413852624
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/KOSDW4NTFGCXPTLJMFIAPWMVRKTTHGGD/


[SSSD] [sssd PR#640][+Accepted] Python3 changes to multihost tests

2018-08-17 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/640
Title: #640: Python3 changes to multihost tests

Label: +Accepted
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/MWSGAYWFPTZF7RMAN4XEPGGA7HVP422X/


[SSSD] [sssd PR#640][comment] Python3 changes to multihost tests

2018-08-17 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/640
Title: #640: Python3 changes to multihost tests

fidencio commented:
"""
I'm removing the "Accepted" label as @mrniranjan will send a few more patches 
in this very same PR.
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/640#issuecomment-413820660
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/QR4ACJJCCJXRBY54DVQFHTRTRA2FT2UG/


[SSSD] [sssd PR#640][-Accepted] Python3 changes to multihost tests

2018-08-17 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/640
Title: #640: Python3 changes to multihost tests

Label: -Accepted
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/CVF2BXMMKEHXH6KAXVK22NG2UPVSFTZ7/


[SSSD] [sssd PR#132][comment] Add "Wants=" to sssd unit

2018-08-17 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/132
Title: #132: Add "Wants=" to sssd unit

fidencio commented:
"""
```
[ffidenci@pessoa sssd]$ git diff
diff --git a/src/tools/sssd_check_socket_activated_responders.c 
b/src/tools/sssd_check_socket_activated_responders.c
index e83de622b..0b1a4df94 100644
--- a/src/tools/sssd_check_socket_activated_responders.c
+++ b/src/tools/sssd_check_socket_activated_responders.c
@@ -192,9 +192,9 @@ int main(int argc, const char *argv[])
 "The \"services\" line contains \"%s\", meaning that the "
 "responder's process will be started and managed by SSSD's "
 "monitor. "
-"However, SSSD automatically pulls in the \"%s\" socket(s) and 
"
-"relies on systemd to start and manage the responder's "
-"process.\n"
+"However, SSSD relies on systemd to start "
+"sssd-%s.socket and then manage the responder's process, "
+"causing then a configuration conflict.\n"
 "In order to solve this misconfiguration, please, either "
 "remove \"%s\" from the \"services\" line in \"%s\" or call "
 "`systemctl mask sssd-%s.socket`\n"
```

@pbrezina, does it look better?
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/132#issuecomment-413800580
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/URGUGGOAPEOEZC3RK2TLSHZZTJILAILW/


[SSSD] [sssd PR#640][+Accepted] Python3 changes to multihost tests

2018-08-17 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/640
Title: #640: Python3 changes to multihost tests

Label: +Accepted
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/23KNNAAKQUUBNGW3DSN2OQNH7W2EP5JN/


[SSSD] [sssd PR#640][comment] Python3 changes to multihost tests

2018-08-17 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/640
Title: #640: Python3 changes to multihost tests

fidencio commented:
"""
CI: http://vm-031.${abc}/logs/job/91/90/summary.html
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/640#issuecomment-413776902
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/N66HBGT7R5T4LQ5Z2TK3IAH6W6V4VPGO/


[SSSD] [sssd PR#640][comment] Python3 changes to multihost tests

2018-08-16 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/640
Title: #640: Python3 changes to multihost tests

fidencio commented:
"""
Patch looks good and I've fired a CI run. I'll Ack as soon as I get the results.

@mrniranjan, do you need/want a review from someone else from your team as well?
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/640#issuecomment-413667084
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/ZRDDQTWVQNH25IBBAKVUXBIUQV7RZBCZ/


[SSSD] [sssd PR#640][comment] Python3 changes to multihost tests

2018-08-16 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/640
Title: #640: Python3 changes to multihost tests

fidencio commented:
"""
ok to test
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/640#issuecomment-413663854
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/MXCENSRLCP52W4JRKHSS7JNWLZ3D4WP5/


[SSSD] [sssd PR#132][comment] Add "Wants=" to sssd unit

2018-08-16 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/132
Title: #132: Add "Wants=" to sssd unit

fidencio commented:
"""
@pbrezina: what I tried to say is that sssd.service has a 
Wants=sssd-@responder.socket, which will make the sssd-@responder.socket to be 
started as soon as sssd.service is started ... relying then on systemd.
I'm totally open for suggestions on how to rewrite this part to make ir more 
clear for our users.
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/132#issuecomment-413491333
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/TZ3SOH47OK6H5H577DRCQM4BS5Y36W7Q/


[SSSD] [sssd PR#132][synchronized] Add "Wants=" to sssd unit

2018-08-15 Thread fidencio
   URL: https://github.com/SSSD/sssd/pull/132
Author: fidencio
 Title: #132: Add "Wants=" to sssd unit
Action: synchronized

To pull the PR as Git branch:
git remote add ghsssd https://github.com/SSSD/sssd
git fetch ghsssd pull/132/head:pr132
git checkout pr132
From 3018f59a0316b548903db66fc147d5c50966dbe3 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Fabiano=20Fid=C3=AAncio?= 
Date: Tue, 24 Jan 2017 09:36:34 +0100
Subject: [PATCH 1/3] sssd: add a list of dependent services to sssd.service
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit

Let's add a list of dependent services to the sssd unit file so we can
have all those services enable by default when enabling sssd unit.

As it differs from our first approach were all services were disabled by
default, the manuals have also been updated.

Signed-off-by: Fabiano Fidêncio 
---
 Makefile.am  | 14 +-
 src/man/sssd-sudo.5.xml  |  3 +--
 src/man/sssd.conf.5.xml  | 12 +---
 src/sysv/systemd/sssd.service.in |  2 +-
 4 files changed, 24 insertions(+), 7 deletions(-)

diff --git a/Makefile.am b/Makefile.am
index d31395772..e09808b4a 100644
--- a/Makefile.am
+++ b/Makefile.am
@@ -4879,6 +4879,7 @@ endif
 init_SCRIPTS =
 systemdunit_DATA =
 systemdconf_DATA =
+sssd_dependent_services =
 if HAVE_SYSTEMD_UNIT
 systemdunit_DATA += \
 src/sysv/systemd/sssd.service \
@@ -4888,11 +4889,15 @@ if HAVE_SYSTEMD_UNIT
 src/sysv/systemd/sssd-pam-priv.socket \
 src/sysv/systemd/sssd-pam.service \
 $(NULL)
+
+sssd_dependent_services += sssd-nss.socket sssd-pam.socket
 if BUILD_AUTOFS
 systemdunit_DATA += \
 src/sysv/systemd/sssd-autofs.socket \
 src/sysv/systemd/sssd-autofs.service \
 $(NULL)
+
+sssd_dependent_services += sssd-autofs.socket
 endif
 if BUILD_IFP
 systemdunit_DATA += \
@@ -4904,6 +4909,8 @@ if BUILD_PAC_RESPONDER
 src/sysv/systemd/sssd-pac.socket \
 src/sysv/systemd/sssd-pac.service \
 $(NULL)
+
+sssd_dependent_services += sssd-pac.socket
 endif
 if BUILD_SECRETS
 systemdunit_DATA += \
@@ -4916,12 +4923,16 @@ if BUILD_SSH
 src/sysv/systemd/sssd-ssh.socket \
 src/sysv/systemd/sssd-ssh.service \
 $(NULL)
+
+sssd_dependent_services += sssd-ssh.socket
 endif
 if BUILD_SUDO
 systemdunit_DATA += \
 src/sysv/systemd/sssd-sudo.socket \
 src/sysv/systemd/sssd-sudo.service \
 $(NULL)
+
+sssd_dependent_services += sssd-sudo.socket
 endif
 if BUILD_KCM
 systemdunit_DATA += \
@@ -4968,7 +4979,8 @@ edit_cmd = $(SED) \
 -e 's|@libexecdir[@]|$(libexecdir)|g' \
 -e 's|@pipepath[@]|$(pipepath)|g' \
 -e 's|@prefix[@]|$(prefix)|g' \
--e 's|@SSSD_USER[@]|$(SSSD_USER)|g'
+-e 's|@SSSD_USER[@]|$(SSSD_USER)|g' \
+-e 's|@sssd_dependent_services[@]|${sssd_dependent_services}|g'
 
 replace_script = \
 @rm -f $@ $@.tmp; \
diff --git a/src/man/sssd-sudo.5.xml b/src/man/sssd-sudo.5.xml
index 5bc56c463..cb085419a 100644
--- a/src/man/sssd-sudo.5.xml
+++ b/src/man/sssd-sudo.5.xml
@@ -110,8 +110,7 @@ ldap_sudo_search_base = ou=sudoers,dc=example,dc=com
 
 It's important to note that on platforms where systemd is supported
 there's no need to add the "sudo" provider to the list of services,
-as it became optional. However, sssd-sudo.socket must be enabled
-instead.
+as it became optional.
 
 
 
diff --git a/src/man/sssd.conf.5.xml b/src/man/sssd.conf.5.xml
index 881ffc6ab..23f59e0e8 100644
--- a/src/man/sssd.conf.5.xml
+++ b/src/man/sssd.conf.5.xml
@@ -220,9 +220,15 @@
 
 
 
-By default, all services are disabled and the administrator
-must enable the ones allowed to be used by executing:
-"systemctl enable sssd-@service@.socket".
+By default, the following services are enabled: nss, pam
+, sudo
+, autofs
+, ssh
+, pac
+, ifp
+In case the Administrator wants to persistently disable
+one of them, it can be done by running:
+"systemctl mask sssd-@service@.socket"
 
 
 
diff --git a/src/sysv/systemd/sssd.service.in b/src/sysv/systemd/sssd.service.in
index 0c515d34c..49c09ea58 100644
--- a/src/sysv/systemd/sssd.service.in
+++ b/src/sysv/systemd/sssd.servic

[SSSD] [sssd PR#132][-postponed until sssd 2.0] Add "Wants=" to sssd unit

2018-08-15 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/132
Title: #132: Add "Wants=" to sssd unit

Label: -postponed until sssd 2.0
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/L2WDVMFKEF6ZQQMUORIX3DYNBWHTRXTS/


[SSSD] [sssd PR#132][comment] Add "Wants=" to sssd unit

2018-08-15 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/132
Title: #132: Add "Wants=" to sssd unit

fidencio commented:
"""
Patch set has been updated and is ready for review.
I'm also removing the "postponing until sssd 2.0" label.
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/132#issuecomment-413358685
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/HQT6OGEIMLPYKWOBXCNJZJJ63NSHQ7CP/


[SSSD] [sssd PR#132][synchronized] Add "Wants=" to sssd unit

2018-08-15 Thread fidencio
   URL: https://github.com/SSSD/sssd/pull/132
Author: fidencio
 Title: #132: Add "Wants=" to sssd unit
Action: synchronized

To pull the PR as Git branch:
git remote add ghsssd https://github.com/SSSD/sssd
git fetch ghsssd pull/132/head:pr132
git checkout pr132
From 074e4e424953a9d21a0be5b47d9fead348bfd774 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Fabiano=20Fid=C3=AAncio?= 
Date: Tue, 24 Jan 2017 09:36:34 +0100
Subject: [PATCH 1/3] sssd: Add a list of dependent services to sssd.service
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit

Let's add a list of dependent services to the sssd unit file so we can
have all those services enable by default when enabling sssd unit.

As it differs from our first approach were all services were disabled by
default, the manuals have also been updated.

Signed-off-by: Fabiano Fidêncio 
---
 Makefile.am  | 14 +-
 src/man/sssd-sudo.5.xml  |  3 +--
 src/man/sssd.conf.5.xml  | 12 +---
 src/sysv/systemd/sssd.service.in |  2 +-
 4 files changed, 24 insertions(+), 7 deletions(-)

diff --git a/Makefile.am b/Makefile.am
index d313957722..e09808b4aa 100644
--- a/Makefile.am
+++ b/Makefile.am
@@ -4879,6 +4879,7 @@ endif
 init_SCRIPTS =
 systemdunit_DATA =
 systemdconf_DATA =
+sssd_dependent_services =
 if HAVE_SYSTEMD_UNIT
 systemdunit_DATA += \
 src/sysv/systemd/sssd.service \
@@ -4888,11 +4889,15 @@ if HAVE_SYSTEMD_UNIT
 src/sysv/systemd/sssd-pam-priv.socket \
 src/sysv/systemd/sssd-pam.service \
 $(NULL)
+
+sssd_dependent_services += sssd-nss.socket sssd-pam.socket
 if BUILD_AUTOFS
 systemdunit_DATA += \
 src/sysv/systemd/sssd-autofs.socket \
 src/sysv/systemd/sssd-autofs.service \
 $(NULL)
+
+sssd_dependent_services += sssd-autofs.socket
 endif
 if BUILD_IFP
 systemdunit_DATA += \
@@ -4904,6 +4909,8 @@ if BUILD_PAC_RESPONDER
 src/sysv/systemd/sssd-pac.socket \
 src/sysv/systemd/sssd-pac.service \
 $(NULL)
+
+sssd_dependent_services += sssd-pac.socket
 endif
 if BUILD_SECRETS
 systemdunit_DATA += \
@@ -4916,12 +4923,16 @@ if BUILD_SSH
 src/sysv/systemd/sssd-ssh.socket \
 src/sysv/systemd/sssd-ssh.service \
 $(NULL)
+
+sssd_dependent_services += sssd-ssh.socket
 endif
 if BUILD_SUDO
 systemdunit_DATA += \
 src/sysv/systemd/sssd-sudo.socket \
 src/sysv/systemd/sssd-sudo.service \
 $(NULL)
+
+sssd_dependent_services += sssd-sudo.socket
 endif
 if BUILD_KCM
 systemdunit_DATA += \
@@ -4968,7 +4979,8 @@ edit_cmd = $(SED) \
 -e 's|@libexecdir[@]|$(libexecdir)|g' \
 -e 's|@pipepath[@]|$(pipepath)|g' \
 -e 's|@prefix[@]|$(prefix)|g' \
--e 's|@SSSD_USER[@]|$(SSSD_USER)|g'
+-e 's|@SSSD_USER[@]|$(SSSD_USER)|g' \
+-e 's|@sssd_dependent_services[@]|${sssd_dependent_services}|g'
 
 replace_script = \
 @rm -f $@ $@.tmp; \
diff --git a/src/man/sssd-sudo.5.xml b/src/man/sssd-sudo.5.xml
index 5bc56c4633..cb085419ab 100644
--- a/src/man/sssd-sudo.5.xml
+++ b/src/man/sssd-sudo.5.xml
@@ -110,8 +110,7 @@ ldap_sudo_search_base = ou=sudoers,dc=example,dc=com
 
 It's important to note that on platforms where systemd is supported
 there's no need to add the "sudo" provider to the list of services,
-as it became optional. However, sssd-sudo.socket must be enabled
-instead.
+as it became optional.
 
 
 
diff --git a/src/man/sssd.conf.5.xml b/src/man/sssd.conf.5.xml
index 881ffc6ab3..23f59e0e86 100644
--- a/src/man/sssd.conf.5.xml
+++ b/src/man/sssd.conf.5.xml
@@ -220,9 +220,15 @@
 
 
 
-By default, all services are disabled and the administrator
-must enable the ones allowed to be used by executing:
-"systemctl enable sssd-@service@.socket".
+By default, the following services are enabled: nss, pam
+, sudo
+, autofs
+, ssh
+, pac
+, ifp
+In case the Administrator wants to persistently disable
+one of them, it can be done by running:
+"systemctl mask sssd-@service@.socket"
 
 
 
diff --git a/src/sysv/systemd/sssd.service.in b/src/sysv/systemd/sssd.service.in
index 0c515d34ca..49c09ea583 100644
--- a/src/sysv/systemd/sssd.service.in
+++ b/src/sysv/systemd/sssd

[SSSD] [sssd PR#620][+superseded] Add pam_cert_pam_services option

2018-08-13 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/620
Title: #620: Add pam_cert_pam_services option

Label: +superseded
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/G4DZJCTMYIC6ICGD26INJ2BWYG3C6BBX/


[SSSD] [sssd PR#620][closed] Add pam_cert_pam_services option

2018-08-13 Thread fidencio
   URL: https://github.com/SSSD/sssd/pull/620
Author: abbra
 Title: #620: Add pam_cert_pam_services option
Action: closed

To pull the PR as Git branch:
git remote add ghsssd https://github.com/SSSD/sssd
git fetch ghsssd pull/620/head:pr620
git checkout pr620
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/HDEFDLABN4PR4C4ZTY6OD3CSC7NNV7QU/


[SSSD] [sssd PR#620][comment] Add pam_cert_pam_services option

2018-08-13 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/620
Title: #620: Add pam_cert_pam_services option

fidencio commented:
"""
@lslebodn's patch has been merged, thus I'm closing this PR.
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/620#issuecomment-412535140
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/6KMZQAIJKX4BKQYEFCWN7PI7E5UVPAO2/


[SSSD] [sssd PR#637][+Pushed] Relicense GPLv2 only files as GPLv3+

2018-08-13 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/637
Title: #637: Relicense GPLv2 only files as GPLv3+

Label: +Pushed
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/Z45RXT4MAARWTEJJJ2SDEPZMU4RN3UNF/


[SSSD] [sssd PR#637][-Accepted] Relicense GPLv2 only files as GPLv3+

2018-08-13 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/637
Title: #637: Relicense GPLv2 only files as GPLv3+

Label: -Accepted
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/SC67BR4QQTNQZVOLIFMYW626IGN4KQWT/


[SSSD] [sssd PR#637][closed] Relicense GPLv2 only files as GPLv3+

2018-08-13 Thread fidencio
   URL: https://github.com/SSSD/sssd/pull/637
Author: jhrozek
 Title: #637: Relicense GPLv2 only files as GPLv3+
Action: closed

To pull the PR as Git branch:
git remote add ghsssd https://github.com/SSSD/sssd
git fetch ghsssd pull/637/head:pr637
git checkout pr637
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/4SP3ATFZXIXN4RLXOM2N5BN4UQNU6KMH/


[SSSD] [sssd PR#637][comment] Relicense GPLv2 only files as GPLv3+

2018-08-13 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/637
Title: #637: Relicense GPLv2 only files as GPLv3+

fidencio commented:
"""
master:
 a57d9ec
 3badebc
 e4864db
 444b463
 a542217
 2527589
 e92040a
 33c668e
 7dc03ff
 3ae7458
 62a1eb3
 02008a0
 7283ee1
 23df598
 5eee13a
 85486d2
 895524e
 e7afe9f
 c2296d0
 8cc6710
 85d939d
 aa5f817
 1f244c0
 44d637d
 8a1092b
 31f3f79
 744ae1a
 b5c42f4
 b94cf69
 fa125f1
 89248d0
 bcbc2f2
 df5297f
 ce5a90b
 79f70d6
 3ee03cf
 de47b66
 02d2340
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/637#issuecomment-412513273
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/5JIFHRIDD4XP3EXLFWVANMVDNOQWS33B/


[SSSD] [sssd PR#638][closed] Explicitly add GPLv3+ license blob to several files

2018-08-13 Thread fidencio
   URL: https://github.com/SSSD/sssd/pull/638
Author: jhrozek
 Title: #638: Explicitly add GPLv3+ license blob to several files
Action: closed

To pull the PR as Git branch:
git remote add ghsssd https://github.com/SSSD/sssd
git fetch ghsssd pull/638/head:pr638
git checkout pr638
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/GVFLWLH7IMJX2PUEZPNEPIUIAVEN66F3/


[SSSD] [sssd PR#638][comment] Explicitly add GPLv3+ license blob to several files

2018-08-13 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/638
Title: #638: Explicitly add GPLv3+ license blob to several files

fidencio commented:
"""
master:
 9ba105f
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/638#issuecomment-412512867
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/ILXUIV2OUMJLD3MGT3AGDYRR7JTRLLB4/


[SSSD] [sssd PR#635][comment] sss_ssh_knownhostsproxy: fix typo pubkey -> pubkeys

2018-08-13 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/635
Title: #635: sss_ssh_knownhostsproxy: fix typo pubkey -> pubkeys

fidencio commented:
"""
master:
 2b3b41d
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/635#issuecomment-412512696
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/ZUZ3SS4UL4HXXXS2UHTX5GNNFS5ZBVK5/


[SSSD] [sssd PR#635][closed] sss_ssh_knownhostsproxy: fix typo pubkey -> pubkeys

2018-08-13 Thread fidencio
   URL: https://github.com/SSSD/sssd/pull/635
Author: fidencio
 Title: #635: sss_ssh_knownhostsproxy: fix typo pubkey -> pubkeys
Action: closed

To pull the PR as Git branch:
git remote add ghsssd https://github.com/SSSD/sssd
git fetch ghsssd pull/635/head:pr635
git checkout pr635
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/JVGQD7NFF6ORZFXCH3EXR76W6GMHAQ36/


[SSSD] [sssd PR#637][+Accepted] Relicense GPLv2 only files as GPLv3+

2018-08-13 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/637
Title: #637: Relicense GPLv2 only files as GPLv3+

Label: +Accepted
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/5OPRUSATPMOXYSDF5URDLKRV3IWBELP4/


[SSSD] [sssd PR#637][comment] Relicense GPLv2 only files as GPLv3+

2018-08-13 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/637
Title: #637: Relicense GPLv2 only files as GPLv3+

fidencio commented:
"""
Adding the "Accepted" label as per @mzidek-rh's review.
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/637#issuecomment-412495034
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/O7IZFKBIJYRUEHSO7EN3MUSW45A54QBU/


[SSSD] [sssd PR#630][+Accepted] KCM/SECRETS: Use a library to access the secrets storage instead of the secrets responder, deprecate secrets responder

2018-08-13 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/630
Title: #630: KCM/SECRETS: Use a library to access the secrets storage instead 
of the secrets responder, deprecate secrets responder

Label: +Accepted
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/OBFJ27FYX63CB5H5XRLJKRJ36SMEOH4G/


[SSSD] [sssd PR#630][comment] KCM/SECRETS: Use a library to access the secrets storage instead of the secrets responder, deprecate secrets responder

2018-08-13 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/630
Title: #630: KCM/SECRETS: Use a library to access the secrets storage instead 
of the secrets responder, deprecate secrets responder

fidencio commented:
"""
I gave it a try in the last version and it works as expected.

I've fired an internal CI build and I'll add the "Accepted" label as soon as I 
get the results.
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/630#issuecomment-412462154
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/YUWD5WJEV7FPPLV6HU7SXEXJJ2RA3SS5/


[SSSD] [sssd PR#635][comment] sss_ssh_knownhostsproxy: fix typo pubkey -> pubkeys

2018-08-13 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/635
Title: #635: sss_ssh_knownhostsproxy: fix typo pubkey -> pubkeys

fidencio commented:
"""
After a quick chat with @jhrozek, I've decided to re-submit the patch and 
treated the manual reference (pubkeys) as a typo as we should not break command 
line compatibility by changing the command line option.
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/635#issuecomment-412428922
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/MXXEH65Y7BY4PWT5BAKDTRQ6S6CLIEZ4/


[SSSD] [sssd PR#635][synchronized] sss_ssh_knownhostsproxy: fix typo pubkey -> pubkeys

2018-08-13 Thread fidencio
   URL: https://github.com/SSSD/sssd/pull/635
Author: fidencio
 Title: #635: sss_ssh_knownhostsproxy: fix typo pubkey -> pubkeys
Action: synchronized

To pull the PR as Git branch:
git remote add ghsssd https://github.com/SSSD/sssd
git fetch ghsssd pull/635/head:pr635
git checkout pr635
From e31695e4567c7a3dc2035a7660262c67d2b50c04 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Fabiano=20Fid=C3=AAncio?= 
Date: Sun, 12 Aug 2018 23:56:21 +0200
Subject: [PATCH] man/sss_ssh_knownhostsproxy: fix typo pubkeys -> pubkey
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit

In commit 36f2fe8f63 a discrepancy between the command line option and
the manpage has been introduced.

Related:
https://pagure.io/SSSD/sssd/issue/3542

Signed-off-by: Fabiano Fidêncio 
---
 src/man/sss_ssh_knownhostsproxy.1.xml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/src/man/sss_ssh_knownhostsproxy.1.xml b/src/man/sss_ssh_knownhostsproxy.1.xml
index f84732c5d..58aeb0409 100644
--- a/src/man/sss_ssh_knownhostsproxy.1.xml
+++ b/src/man/sss_ssh_knownhostsproxy.1.xml
@@ -86,7 +86,7 @@ GlobalKnownHostsFile /var/lib/sss/pubconf/known_hosts
 
 
 
--k,--pubkeys
+-k,--pubkey
 
 
 
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/GCMEC67FC673ZHBWQ7UJOTTQO67HX2X7/


[SSSD] [sssd PR#635][comment] sss_ssh_knownhostsproxy: fix typo pubkey -> pubkeys

2018-08-13 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/635
Title: #635: sss_ssh_knownhostsproxy: fix typo pubkey -> pubkeys

fidencio commented:
"""
re-test this, please
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/635#issuecomment-412424422
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/TQRXBRY64AB223RPKBZTIJFULJOSBMVY/


[SSSD] [sssd PR#635][opened] sss_ssh_knownhostsproxy: fix typo pubkey -> pubkeys

2018-08-12 Thread fidencio
   URL: https://github.com/SSSD/sssd/pull/635
Author: fidencio
 Title: #635: sss_ssh_knownhostsproxy: fix typo pubkey -> pubkeys
Action: opened

PR body:
"""
In commit 36f2fe8f63 a discrepancy between the command line option and
the manpage has been introduced.

Related:
https://pagure.io/SSSD/sssd/issue/3542

Signed-off-by: Fabiano Fidêncio 
"""

To pull the PR as Git branch:
git remote add ghsssd https://github.com/SSSD/sssd
git fetch ghsssd pull/635/head:pr635
git checkout pr635
From c8247799d3d4f18937eebe394dfcd69d482454f5 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Fabiano=20Fid=C3=AAncio?= 
Date: Sun, 12 Aug 2018 23:56:21 +0200
Subject: [PATCH] sss_ssh_knownhostsproxy: fix typo pubkey -> pubkeys
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit

In commit 36f2fe8f63 a discrepancy between the command line option and
the manpage has been introduced.

Related:
https://pagure.io/SSSD/sssd/issue/3542

Signed-off-by: Fabiano Fidêncio 
---
 src/sss_client/ssh/sss_ssh_knownhostsproxy.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/src/sss_client/ssh/sss_ssh_knownhostsproxy.c b/src/sss_client/ssh/sss_ssh_knownhostsproxy.c
index 9e574adea..973308afa 100644
--- a/src/sss_client/ssh/sss_ssh_knownhostsproxy.c
+++ b/src/sss_client/ssh/sss_ssh_knownhostsproxy.c
@@ -206,7 +206,7 @@ int main(int argc, const char **argv)
   _("The port to use to connect to the host"), NULL },
 { "domain", 'd', POPT_ARG_STRING, _domain, 0,
   _("The SSSD domain to use"), NULL },
-{ "pubkey", 'k', POPT_ARG_NONE, _pubkeys, 0,
+{ "pubkeys", 'k', POPT_ARG_NONE, _pubkeys, 0,
   _("Print the host ssh public keys"), NULL },
 POPT_TABLEEND
 };
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/3CTDD7WW46MZQFTZLT2OOYX4HJ7R67RL/


[SSSD] [sssd PR#601][-Changes requested] sbus: integrate sssd with sbus2

2018-08-10 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/601
Title: #601: sbus: integrate sssd with sbus2

Label: -Changes requested
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/NF25QXODHRV7FSDYLDMTJD4O57FQ4KMJ/


[SSSD] [sssd PR#631][+Pushed] nss: remove unused label

2018-08-10 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/631
Title: #631: nss: remove unused label

Label: +Pushed
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/QYFZDMX4SJGYBC5FJR3XIPFECZEDR4AI/


[SSSD] [sssd PR#631][closed] nss: remove unused label

2018-08-10 Thread fidencio
   URL: https://github.com/SSSD/sssd/pull/631
Author: fidencio
 Title: #631: nss: remove unused label
Action: closed

To pull the PR as Git branch:
git remote add ghsssd https://github.com/SSSD/sssd
git fetch ghsssd pull/631/head:pr631
git checkout pr631
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/TN6DYCTAKG2T4I5NFY6CDNDMU4T6FKEQ/


[SSSD] [sssd PR#631][comment] nss: remove unused label

2018-08-10 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/631
Title: #631: nss: remove unused label

fidencio commented:
"""
master:
 e8b417e
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/631#issuecomment-412120488
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/I76MPRW362XEL3RT7B4C4KSBTWDK3QWR/


[SSSD] [sssd PR#631][-Accepted] nss: remove unused label

2018-08-10 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/631
Title: #631: nss: remove unused label

Label: -Accepted
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/RMVMJVUYCXIWYMTM2UM7XWJQ5R7SRDBD/


[SSSD] [sssd PR#634][comment] P11: Don't return int failure from a bool function

2018-08-10 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/634
Title: #634: P11: Don't return int failure from a bool function

fidencio commented:
"""
master:
 7225bab
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/634#issuecomment-412120291
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/4I3Y7HLD2LIP7G7TMVEPVLULR5EHPAOW/


[SSSD] [sssd PR#634][+Pushed] P11: Don't return int failure from a bool function

2018-08-10 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/634
Title: #634: P11: Don't return int failure from a bool function

Label: +Pushed
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/RQ5XKLOUVS3L4YSMEQJR6W42ORX6FXSE/


[SSSD] [sssd PR#634][-Accepted] P11: Don't return int failure from a bool function

2018-08-10 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/634
Title: #634: P11: Don't return int failure from a bool function

Label: -Accepted
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/ZG5X6Z6CDTVZIJBIIXXIDCNAJLWHZNDB/


[SSSD] [sssd PR#632][-Accepted] tests: fix sss_nss_idmap-tests

2018-08-10 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/632
Title: #632: tests: fix sss_nss_idmap-tests

Label: -Accepted
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/CHUPRBGZMFWBBLHZLGRR7DQGD6KKCUT3/


[SSSD] [sssd PR#634][closed] P11: Don't return int failure from a bool function

2018-08-10 Thread fidencio
   URL: https://github.com/SSSD/sssd/pull/634
Author: jhrozek
 Title: #634: P11: Don't return int failure from a bool function
Action: closed

To pull the PR as Git branch:
git remote add ghsssd https://github.com/SSSD/sssd
git fetch ghsssd pull/634/head:pr634
git checkout pr634
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/AZ7BH7US3TRTP4MHKALZTREDSP7USMJU/


[SSSD] [sssd PR#632][closed] tests: fix sss_nss_idmap-tests

2018-08-10 Thread fidencio
   URL: https://github.com/SSSD/sssd/pull/632
Author: sumit-bose
 Title: #632: tests: fix sss_nss_idmap-tests
Action: closed

To pull the PR as Git branch:
git remote add ghsssd https://github.com/SSSD/sssd
git fetch ghsssd pull/632/head:pr632
git checkout pr632
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/MO2QXQ4Q6CZAVVZBL4IMQSHVE2TFCNQY/


[SSSD] [sssd PR#632][comment] tests: fix sss_nss_idmap-tests

2018-08-10 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/632
Title: #632: tests: fix sss_nss_idmap-tests

fidencio commented:
"""
master:
 da9e34e
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/632#issuecomment-412119927
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/D6YVMDFDTOFPRGTKE7RL77XG7M6MO66T/


[SSSD] [sssd PR#632][+Pushed] tests: fix sss_nss_idmap-tests

2018-08-10 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/632
Title: #632: tests: fix sss_nss_idmap-tests

Label: +Pushed
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/EWY3JDRPLOSLYWLYCEFXPGTHZUJODZNP/


[SSSD] [sssd PR#630][comment] KCM/SECRETS: Use a library to access the secrets storage instead of the secrets responder, deprecate secrets responder

2018-08-10 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/630
Title: #630: KCM/SECRETS: Use a library to access the secrets storage instead 
of the secrets responder, deprecate secrets responder

fidencio commented:
"""
@jhrozek, I found out a few more issues related to the last patch of the latest 
series, please, take a look at the following patch that could be squashed into 
yours:
```
diff --git a/Makefile.am b/Makefile.am
index 23e094a37..0f36148e8 100644
--- a/Makefile.am
+++ b/Makefile.am
@@ -4663,8 +4663,6 @@ if HAVE_SYSTEMD_UNIT
 src/sysv/systemd/sssd-pam.socket \
 src/sysv/systemd/sssd-pam-priv.socket \
 src/sysv/systemd/sssd-pam.service \
-src/sysv/systemd/sssd-secrets.socket \
-src/sysv/systemd/sssd-secrets.service \
 $(NULL)
 if BUILD_AUTOFS
 systemdunit_DATA += \
@@ -4683,6 +4681,12 @@ if BUILD_PAC_RESPONDER
 src/sysv/systemd/sssd-pac.service \
 $(NULL)
 endif
+if BUILD_SECRETS
+systemdunit_DATA += \
+src/sysv/systemd/sssd-secrets.socket \
+src/sysv/systemd/sssd-secrets.service \
+$(NULL)
+endif
 if BUILD_SSH
 systemdunit_DATA += \
 src/sysv/systemd/sssd-ssh.socket \
@@ -4820,6 +4824,7 @@ src/sysv/systemd/sssd-pam.service: 
src/sysv/systemd/sssd-pam.service.in Makefile
@$(MKDIR_P) src/sysv/systemd/
$(replace_script)
 
+if BUILD_SECRETS
 src/sysv/systemd/sssd-secrets.socket: src/sysv/systemd/sssd-secrets.socket.in 
Makefile
@$(MKDIR_P) src/sysv/systemd/
$(replace_script)
@@ -4827,6 +4832,7 @@ src/sysv/systemd/sssd-secrets.socket: 
src/sysv/systemd/sssd-secrets.socket.in Ma
 src/sysv/systemd/sssd-secrets.service: 
src/sysv/systemd/sssd-secrets.service.in Makefile
@$(MKDIR_P) src/sysv/systemd/
$(replace_script)
+endif
 
 if BUILD_AUTOFS
 src/sysv/systemd/sssd-autofs.socket: src/sysv/systemd/sssd-autofs.socket.in 
Makefile
@@ -4875,9 +4881,25 @@ src/sysv/systemd/sssd-sudo.service: 
src/sysv/systemd/sssd-sudo.service.in Makefi
 endif
 
 if BUILD_KCM
+if BUILD_SECRETS
+kcm_socket_requires = Requires=sssd-secrets.socket
+else
+kcm_socket_requires =
+endif
+
+kcm_edit_cmd = $(edit_cmd) \
+-e 's|@kcm_socket_requires[@]|$(kcm_socket_requires)|g'
+
+kcm_replace_script = \
+@rm -f $@ $@.tmp; \
+srcdir=''; \
+test -f ./$@.in || srcdir=$(srcdir)/; \
+$(kcm_edit_cmd) $${srcdir}$@.in >$@.tmp; \
+mv $@.tmp $@
+
 src/sysv/systemd/sssd-kcm.socket: src/sysv/systemd/sssd-kcm.socket.in Makefile
@$(MKDIR_P) src/sysv/systemd/
-   $(replace_script)
+   $(kcm_replace_script)
 
 src/sysv/systemd/sssd-kcm.service: src/sysv/systemd/sssd-kcm.service.in 
Makefile
@$(MKDIR_P) src/sysv/systemd/
diff --git a/contrib/sssd.spec.in b/contrib/sssd.spec.in
index a9874a10e..706254deb 100644
--- a/contrib/sssd.spec.in
+++ b/contrib/sssd.spec.in
@@ -1351,10 +1351,10 @@ done
 %{_datadir}/sssd-kcm/kcm_default_ccache
 %{_unitdir}/sssd-kcm.socket
 %{_unitdir}/sssd-kcm.service
-%{_unitdir}/sssd-secrets.socket
-%{_unitdir}/sssd-secrets.service
 %{_mandir}/man8/sssd-kcm.8*
 %if (0%{?with_secrets} == 1)
+%{_unitdir}/sssd-secrets.socket
+%{_unitdir}/sssd-secrets.service
 %{_mandir}/man5/sssd-secrets.5*
 %endif
 %endif
@@ -1372,7 +1372,6 @@ getent passwd sssd >/dev/null || useradd -r -g sssd -d / 
-s /sbin/nologin -c "Us
 %systemd_post sssd-pac.socket
 %systemd_post sssd-pam.socket
 %systemd_post sssd-pam-priv.socket
-%systemd_post sssd-secrets.socket
 %systemd_post sssd-ssh.socket
 %systemd_post sssd-sudo.socket
 
@@ -1383,7 +1382,6 @@ getent passwd sssd >/dev/null || useradd -r -g sssd -d / 
-s /sbin/nologin -c "Us
 %systemd_preun sssd-pac.socket
 %systemd_preun sssd-pam.socket
 %systemd_preun sssd-pam-priv.socket
-%systemd_preun sssd-secrets.socket
 %systemd_preun sssd-ssh.socket
 %systemd_preun sssd-sudo.socket
 
@@ -1398,8 +1396,6 @@ getent passwd sssd >/dev/null || useradd -r -g sssd -d / 
-s /sbin/nologin -c "Us
 %systemd_postun_with_restart sssd-pam.socket
 %systemd_postun_with_restart sssd-pam-priv.socket
 %systemd_postun_with_restart sssd-pam.service
-%systemd_postun_with_restart sssd-secrets.socket
-%systemd_postun_with_restart sssd-secrets.service
 %systemd_postun_with_restart sssd-ssh.socket
 %systemd_postun_with_restart sssd-ssh.service
 %systemd_postun_with_restart sssd-sudo.socket
@@ -1426,6 +1422,18 @@ getent passwd sssd >/dev/null || useradd -r -g sssd -d / 
-s /sbin/nologin -c "Us
 %systemd_postun_with_restart sssd-kcm.service
 %endif
 
+%if (0%{?with_secrets} == 1)
+%post secrets
+%systemd_postun_with_restart sssd-secrets.socket
+
+%preun secrets
+%systemd_preun_with_restart sssd-secrets.socket
+
+%postun secrets
+%systemd_postun_with_restart sssd-secrets.socket
+%systemd_postun_with_restart sssd-secrets.service
+%endif
+
 %else
 # sysv
 %post common
diff --git a/src/sysv/systemd/sssd-kcm.socket.in 
b/src/sysv/systemd/sssd-kcm.socket.in
index 8b742847d..e8a5f0aca 100644
--- a/

[SSSD] [sssd PR#620][comment] Add pam_cert_pam_services option

2018-08-09 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/620
Title: #620: Add pam_cert_pam_services option

fidencio commented:
"""
@sumit-bose, shall we go for @lslebodn's patch instead?
If so, I'd close this PR and push https://pagure.io/SSSD/sssd/pull-request/3799 
Tomorrow.
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/620#issuecomment-411871939
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/HTOVBEAKZT5CHX4NYC2QRUGQQ3L3PSQL/


[SSSD] [sssd PR#630][+Changes requested] KCM/SECRETS: Use a library to access the secrets storage instead of the secrets responder, deprecate secrets responder

2018-08-09 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/630
Title: #630: KCM/SECRETS: Use a library to access the secrets storage instead 
of the secrets responder, deprecate secrets responder

Label: +Changes requested
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/4VYQW3CAMEW6KC4XEO6FSIBVZGPZVTOH/


[SSSD] [sssd PR#632][+Accepted] tests: fix sss_nss_idmap-tests

2018-08-09 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/632
Title: #632: tests: fix sss_nss_idmap-tests

Label: +Accepted
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/XDMK2TWKODNW4LLXMZCPMR547YQKR4IP/


[SSSD] [sssd PR#632][comment] tests: fix sss_nss_idmap-tests

2018-08-09 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/632
Title: #632: tests: fix sss_nss_idmap-tests

fidencio commented:
"""
Looks good to me!
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/632#issuecomment-411861571
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/I7ULXTFWXTIAIHRRDVZLRAVD5ADMCJKS/


[SSSD] [sssd PR#631][comment] nss: remove unused label

2018-08-09 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/631
Title: #631: nss: remove unused label

fidencio commented:
"""
@sumit-bose, I've changed my mind and fully adopted your suggestion in one 
single patch.
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/631#issuecomment-411858930
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/VGHBDCXDYU37XN4YLSJZAEVZBVP43AG2/


[SSSD] [sssd PR#631][synchronized] nss: remove unused label

2018-08-09 Thread fidencio
   URL: https://github.com/SSSD/sssd/pull/631
Author: fidencio
 Title: #631: nss: remove unused label
Action: synchronized

To pull the PR as Git branch:
git remote add ghsssd https://github.com/SSSD/sssd
git fetch ghsssd pull/631/head:pr631
git checkout pr631
From 2d938f9036133d22733f8477dea2253c5f30b400 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Fabiano=20Fid=C3=AAncio?= 
Date: Thu, 9 Aug 2018 18:01:52 +0200
Subject: [PATCH] nss: remove unused label
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit

After 4937f2c6, Sumit noticed the following warning/breakage:

make[2]: Leaving directory '/home/sbose/sssd/master_build/src/man'
Making check in .
make[2]: Entering directory '/home/sbose/sssd/master_build'
  CC   src/responder/nss/nss_protocol_grent.o
../src/responder/nss/nss_protocol_grent.c: In function 'nss_protocol_fill_initgr':
../src/responder/nss/nss_protocol_grent.c:409:1: error: label 'done' defined but not used [-Werror=unused-label]
 done:
 ^~~~
cc1: all warnings being treated as errors
Makefile:17808: recipe for target 'src/responder/nss/nss_protocol_grent.o' failed
make[2]: *** [src/responder/nss/nss_protocol_grent.o] Error 1
make[2]: Leaving directory '/home/sbose/sssd/master_build'

Also, while removing the label, by moving the error treatment to the if
block just before the existing one makes the code cleaner.

Signed-off-by: Fabiano Fidêncio 
---
 src/responder/nss/nss_protocol_grent.c | 8 ++--
 1 file changed, 2 insertions(+), 6 deletions(-)

diff --git a/src/responder/nss/nss_protocol_grent.c b/src/responder/nss/nss_protocol_grent.c
index a697e86ef..59cdd800d 100644
--- a/src/responder/nss/nss_protocol_grent.c
+++ b/src/responder/nss/nss_protocol_grent.c
@@ -403,15 +403,11 @@ nss_protocol_fill_initgr(struct nss_ctx *nss_ctx,
 DEBUG(SSSDBG_MINOR_FAILURE,
   "Failed to store initgroups %s (%s) in mem-cache [%d]: %s!\n",
   rawname.str, domain->name, ret, sss_strerror(ret));
+sss_packet_set_size(packet, 0);
+return ret;
 }
 }
 
-done:
-if (ret != EOK) {
-sss_packet_set_size(packet, 0);
-return ret;
-}
-
 sss_packet_get_body(packet, , _len);
 SAFEALIGN_COPY_UINT32(body, _results, NULL);
 SAFEALIGN_SETMEM_UINT32(body + sizeof(uint32_t), 0, NULL); /* reserved */
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/JNTWTEMZXVEGL2STO3WORBVDR6VGQYKN/


[SSSD] [sssd PR#631][comment] nss: remove unused label

2018-08-09 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/631
Title: #631: nss: remove unused label

fidencio commented:
"""
I agree with your comment (but maybe I would prefer to have your suggestion as 
a separate patch of this very same PR).

Would you mind pushing this as it is in order to fix the breakage asap?

(sorry for the typos and for not doing the change now, I am commiting without 
access to my laptop).
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/631#issuecomment-411817670
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/QKTDZ2DKIDNBAAZSYDXRJHLGBSX7GPIT/


[SSSD] [sssd PR#631][opened] nss: remove unused label

2018-08-09 Thread fidencio
   URL: https://github.com/SSSD/sssd/pull/631
Author: fidencio
 Title: #631: nss: remove unused label
Action: opened

PR body:
"""
After 4937f2c6, Sumit noticed the following warning/breakage:

make[2]: Leaving directory '/home/sbose/sssd/master_build/src/man'
Making check in .
make[2]: Entering directory '/home/sbose/sssd/master_build'
  CC   src/responder/nss/nss_protocol_grent.o
../src/responder/nss/nss_protocol_grent.c: In function 
'nss_protocol_fill_initgr':
../src/responder/nss/nss_protocol_grent.c:409:1: error: label 'done' 
defined but not used [-Werror=unused-label]
 done:
 ^~~~
cc1: all warnings being treated as errors
Makefile:17808: recipe for target 'src/responder/nss/nss_protocol_grent.o' 
failed
make[2]: *** [src/responder/nss/nss_protocol_grent.o] Error 1
make[2]: Leaving directory '/home/sbose/sssd/master_build'

Signed-off-by: Fabiano Fidêncio 
"""

To pull the PR as Git branch:
git remote add ghsssd https://github.com/SSSD/sssd
git fetch ghsssd pull/631/head:pr631
git checkout pr631
From 4590d9034e9fc8ab6f173cb2bec3a69125ecc3c2 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Fabiano=20Fid=C3=AAncio?= 
Date: Thu, 9 Aug 2018 18:01:52 +0200
Subject: [PATCH] nss: remove unused label
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit

After 4937f2c6, Sumit noticed the following warning/breakage:

make[2]: Leaving directory '/home/sbose/sssd/master_build/src/man'
Making check in .
make[2]: Entering directory '/home/sbose/sssd/master_build'
  CC   src/responder/nss/nss_protocol_grent.o
../src/responder/nss/nss_protocol_grent.c: In function 'nss_protocol_fill_initgr':
../src/responder/nss/nss_protocol_grent.c:409:1: error: label 'done' defined but not used [-Werror=unused-label]
 done:
 ^~~~
cc1: all warnings being treated as errors
Makefile:17808: recipe for target 'src/responder/nss/nss_protocol_grent.o' failed
make[2]: *** [src/responder/nss/nss_protocol_grent.o] Error 1
make[2]: Leaving directory '/home/sbose/sssd/master_build'

Signed-off-by: Fabiano Fidêncio 
---
 src/responder/nss/nss_protocol_grent.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/src/responder/nss/nss_protocol_grent.c b/src/responder/nss/nss_protocol_grent.c
index a697e86ef..1b03d660b 100644
--- a/src/responder/nss/nss_protocol_grent.c
+++ b/src/responder/nss/nss_protocol_grent.c
@@ -406,7 +406,6 @@ nss_protocol_fill_initgr(struct nss_ctx *nss_ctx,
 }
 }
 
-done:
 if (ret != EOK) {
 sss_packet_set_size(packet, 0);
 return ret;
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/VEUZ6SZC3XFURBTM7GAZO62WSSOGSNKH/


[SSSD] [sssd PR#614][+Pushed] nss_protocol_fill_initgr: skip incomplete groups instead of bailing out

2018-08-09 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/614
Title: #614: nss_protocol_fill_initgr: skip incomplete groups instead of 
bailing out

Label: +Pushed
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/AVZI5TD6WE5E5QUUHDREHD66INZULFY2/


[SSSD] [sssd PR#614][comment] nss_protocol_fill_initgr: skip incomplete groups instead of bailing out

2018-08-09 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/614
Title: #614: nss_protocol_fill_initgr: skip incomplete groups instead of 
bailing out

fidencio commented:
"""
master:
 4937f2c
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/614#issuecomment-411796606
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/ZHERZWWLVPGY7BA6SQ2CSTJ7CXPRPNME/


[SSSD] [sssd PR#614][-Accepted] nss_protocol_fill_initgr: skip incomplete groups instead of bailing out

2018-08-09 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/614
Title: #614: nss_protocol_fill_initgr: skip incomplete groups instead of 
bailing out

Label: -Accepted
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/KVRJL5TY2KGOPGNMWBMGNTRXMFEBKERU/


[SSSD] [sssd PR#614][closed] nss_protocol_fill_initgr: skip incomplete groups instead of bailing out

2018-08-09 Thread fidencio
   URL: https://github.com/SSSD/sssd/pull/614
Author: asheplyakov
 Title: #614: nss_protocol_fill_initgr: skip incomplete groups instead of 
bailing out
Action: closed

To pull the PR as Git branch:
git remote add ghsssd https://github.com/SSSD/sssd
git fetch ghsssd pull/614/head:pr614
git checkout pr614
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/YNK6C257H67R6L2LU4MKYNRYOVDGPEB6/


[SSSD] [sssd PR#614][comment] nss_protocol_fill_initgr: skip incomplete groups instead of bailing out

2018-08-09 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/614
Title: #614: nss_protocol_fill_initgr: skip incomplete groups instead of 
bailing out

fidencio commented:
"""
We agreed on merging the PR during our team meeting.
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/614#issuecomment-411795873
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/EW2YI7GYU4GWVODRRB4MHHIADGTZFIZE/


[SSSD] [sssd PR#614][+Accepted] nss_protocol_fill_initgr: skip incomplete groups instead of bailing out

2018-08-09 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/614
Title: #614: nss_protocol_fill_initgr: skip incomplete groups instead of 
bailing out

Label: +Accepted
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/E4M7IY6CBPR7G4KRX3JOVYI6H7E66PL2/


[SSSD] [sssd PR#614][comment] nss_protocol_fill_initgr: skip incomplete groups instead of bailing out

2018-08-09 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/614
Title: #614: nss_protocol_fill_initgr: skip incomplete groups instead of 
bailing out

fidencio commented:
"""
I see. We'll have a phone call Today and discuss this patch within SSSD team. 
Although we don't have nor follow any "governance", I do believe that nowadays 
we would be able to have an agreement based on 
https://libvirt.org/governance.html#roughconsensus :-)

I'll update the status of the patch based on our phone call later Today.
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/614#issuecomment-411704304
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/44RNHZU6DM5OR366P66JPOOOG76R6SSA/


[SSSD] [sssd PR#614][comment] nss_protocol_fill_initgr: skip incomplete groups instead of bailing out

2018-08-09 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/614
Title: #614: nss_protocol_fill_initgr: skip incomplete groups instead of 
bailing out

fidencio commented:
"""
I see. We'll have a phone call Today and discuss this patch within SSSD team. 
Although we don't have nor follow any "governance", I do believe that nowadays 
would be able to have an agreement based on 
https://libvirt.org/governance.html#roughconsensus :-)

I'll update the status of the patch based on our phone call later Today.
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/614#issuecomment-411704304
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/7QWGDRYMCJCO5OANWOODXBAQJ3DOIWB7/


[SSSD] [sssd PR#132][comment] Add "Wants=" to sssd unit

2018-08-09 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/132
Title: #132: Add "Wants=" to sssd unit

fidencio commented:
"""
Yes, they are. Theoretically sssd and kcm responders' sockets are (or should 
be) enabled by default by the distro.
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/132#issuecomment-411701824
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/NPYTMUYVT33K2JCHOFL4Z2OI7LB6TLK2/


[SSSD] [sssd PR#132][comment] Add "Wants=" to sssd unit

2018-08-09 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/132
Title: #132: Add "Wants=" to sssd unit

fidencio commented:
"""
Yes, they are. Theoretically secrets and kcm responders' sockets are (or should 
be) enabled by default by the distro.
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/132#issuecomment-411701824
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/24HEWJZND2TF6M3AUXNLS6ESGZ4XSZF3/


[SSSD] [sssd PR#626][+Pushed] SELINUX: Also call is_selinux_enabled as a check for selinux child

2018-08-09 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/626
Title: #626: SELINUX: Also call is_selinux_enabled as a check for selinux child

Label: +Pushed
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/LXTNTWS64YSTH46MI2W35BDOSJX22U4N/


[SSSD] [sssd PR#626][comment] SELINUX: Also call is_selinux_enabled as a check for selinux child

2018-08-09 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/626
Title: #626: SELINUX: Also call is_selinux_enabled as a check for selinux child

fidencio commented:
"""
master:
 1e81d04
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/626#issuecomment-411663228
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/IMNNTQKMGTR6XWIFX3T5E6QCMYEH34S4/


[SSSD] [sssd PR#626][-Accepted] SELINUX: Also call is_selinux_enabled as a check for selinux child

2018-08-09 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/626
Title: #626: SELINUX: Also call is_selinux_enabled as a check for selinux child

Label: -Accepted
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/BQPTU5GZHYU4IBXNTQAAXTU3FNFWDMJE/


[SSSD] [sssd PR#626][closed] SELINUX: Also call is_selinux_enabled as a check for selinux child

2018-08-09 Thread fidencio
   URL: https://github.com/SSSD/sssd/pull/626
Author: jhrozek
 Title: #626: SELINUX: Also call is_selinux_enabled as a check for selinux child
Action: closed

To pull the PR as Git branch:
git remote add ghsssd https://github.com/SSSD/sssd
git fetch ghsssd pull/626/head:pr626
git checkout pr626
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/3EG5QAZGUUCNSNTLPRB2PXC4NP5FTYPM/


[SSSD] [sssd PR#624][closed] Fix "test-find-uid" and "find_uid-tests" tests

2018-08-09 Thread fidencio
   URL: https://github.com/SSSD/sssd/pull/624
Author: stanislavlevin
 Title: #624: Fix "test-find-uid" and "find_uid-tests" tests
Action: closed

To pull the PR as Git branch:
git remote add ghsssd https://github.com/SSSD/sssd
git fetch ghsssd pull/624/head:pr624
git checkout pr624
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/A5SOOMV6CDPO4YMSX4BLEKHVXWLA3YKP/


[SSSD] [sssd PR#624][-Changes requested] Fix "test-find-uid" and "find_uid-tests" tests

2018-08-09 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/624
Title: #624: Fix "test-find-uid" and "find_uid-tests" tests

Label: -Changes requested
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/Z2N5MKJNN3WAZCHEKEPWP5NKGEWICZEO/


[SSSD] [sssd PR#624][comment] Fix "test-find-uid" and "find_uid-tests" tests

2018-08-09 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/624
Title: #624: Fix "test-find-uid" and "find_uid-tests" tests

fidencio commented:
"""
master:
 a41367f
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/624#issuecomment-411662715
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/EUSXDN3NFDHFYWYSDCU2ZJTCWM6EZNOW/


[SSSD] [sssd PR#624][+Pushed] Fix "test-find-uid" and "find_uid-tests" tests

2018-08-09 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/624
Title: #624: Fix "test-find-uid" and "find_uid-tests" tests

Label: +Pushed
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/YFEZPK5QZFJWGW3O4USG6IRXRTGSZWLA/


[SSSD] [sssd PR#624][comment] Fix "test-find-uid" and "find_uid-tests" tests

2018-08-09 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/624
Title: #624: Fix "test-find-uid" and "find_uid-tests" tests

fidencio commented:
"""
After a conversation with @jhrozek, I'm doing the requested changes in this 
patch and pushing it.
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/624#issuecomment-411662203
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/J6HKBXLITOR2HQVVBC4YMVYNFA6WLAL2/


[SSSD] [sssd PR#614][-Accepted] nss_protocol_fill_initgr: skip incomplete groups instead of bailing out

2018-08-09 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/614
Title: #614: nss_protocol_fill_initgr: skip incomplete groups instead of 
bailing out

Label: -Accepted
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/45K4GYLMCSLVBBKZOHSY4KM4NM26E5PM/


[SSSD] [sssd PR#614][comment] nss_protocol_fill_initgr: skip incomplete groups instead of bailing out

2018-08-09 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/614
Title: #614: nss_protocol_fill_initgr: skip incomplete groups instead of 
bailing out

fidencio commented:
"""
Although the patch looks good, after a conversation with @jhrozek ... I have my 
mind made that we may be just papering over a more critical bug.

I'm removing the "Accepted" label but keeping the PR opened.

@asheplyakov, would you have a cache dump, logs or even a machine that you 
could give us access (via tmate) so we could nail this issue down and find out 
why we have incomplete groups in the first place?
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/614#issuecomment-411658336
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/LYH27LZVCJYOAVFBOTOUN2RUZ2KX3NVP/


[SSSD] [sssd PR#629][+postponed until sssd 2.0] ldap: remove parallel requests from rfc2307bis

2018-08-08 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/629
Title: #629: ldap: remove parallel requests from rfc2307bis

Label: +postponed until sssd 2.0
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/HHWNEN4SVLVMQG7NWDBZQ3RPJVTWVM2A/


[SSSD] [sssd PR#629][opened] ldap: remove parallel requests from rfc2307bis

2018-08-08 Thread fidencio
   URL: https://github.com/SSSD/sssd/pull/629
Author: fidencio
 Title: #629: ldap: remove parallel requests from rfc2307bis
Action: opened

PR body:
"""
As this branch of code is not well tested, we've decided to just nuke it
and, in the future, spend more time on improving the performance for the
general case instead of maintaining this old "hack".

Resolves:
https://pagure.io/SSSD/sssd/issue/3494

Signed-off-by: Fabiano Fidêncio 

NOTE: This code needs careful review as I'm not 100% sure about the parts 
deleted!
"""

To pull the PR as Git branch:
git remote add ghsssd https://github.com/SSSD/sssd
git fetch ghsssd pull/629/head:pr629
git checkout pr629
From eedbc838d95798594590116358e6d1b3ce115c42 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Fabiano=20Fid=C3=AAncio?= 
Date: Wed, 8 Aug 2018 16:43:47 +0200
Subject: [PATCH] ldap: remove parallel requests from rfc2307bis
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit

As this branch of code is not well tested, we've decided to just nuke it
and, in the future, spend more time on improving the performance for the
general case instead of maintaining this old "hack".

Resolves:
https://pagure.io/SSSD/sssd/issue/3494

Signed-off-by: Fabiano Fidêncio 
---
 src/providers/ldap/sdap_async_groups.c | 89 +-
 1 file changed, 16 insertions(+), 73 deletions(-)

diff --git a/src/providers/ldap/sdap_async_groups.c b/src/providers/ldap/sdap_async_groups.c
index 77acded7a..86a103848 100644
--- a/src/providers/ldap/sdap_async_groups.c
+++ b/src/providers/ldap/sdap_async_groups.c
@@ -1174,18 +1174,14 @@ struct sdap_process_group_state {
 struct sysdb_attrs *group;
 struct ldb_message_element* sysdb_dns;
 struct ldb_message_element* ghost_dns;
-char **queued_members;
-int queue_len;
 const char **attrs;
 const char *filter;
-size_t queue_idx;
 size_t count;
 size_t check_count;
 
 bool enumeration;
 };
 
-#define GROUPMEMBER_REQ_PARALLEL 50
 static void sdap_process_group_members(struct tevent_req *subreq);
 
 static int sdap_process_group_members_2307bis(struct tevent_req *req,
@@ -1262,9 +1258,6 @@ sdap_process_group_send(TALLOC_CTX *memctx,
 grp_state->sysdb = sysdb;
 grp_state->group =  group;
 grp_state->check_count = 0;
-grp_state->queue_idx = 0;
-grp_state->queued_members = NULL;
-grp_state->queue_len = 0;
 grp_state->filter = filter;
 grp_state->attrs = attrs;
 grp_state->enumeration = enumeration;
@@ -1359,47 +1352,23 @@ sdap_process_missing_member_2307bis(struct tevent_req *req,
 tevent_req_data(req, struct sdap_process_group_state);
 struct tevent_req *subreq;
 
-/*
- * Issue at most GROUPMEMBER_REQ_PARALLEL LDAP searches at once.
- * The rest is sent while the results are being processed.
- * We limit the number as of request here, as the Server might
- * enforce limits on the number of pending operations per
- * connection.
- */
-if (grp_state->check_count > GROUPMEMBER_REQ_PARALLEL) {
-DEBUG(SSSDBG_TRACE_LIBS, " queueing search for: %s\n", user_dn);
-if (!grp_state->queued_members) {
-DEBUG(SSSDBG_TRACE_LIBS,
-  "Allocating queue for %zu members\n",
-   num_users - grp_state->check_count);
-
-grp_state->queued_members = talloc_array(grp_state, char *,
-num_users - grp_state->check_count + 1);
-if (!grp_state->queued_members) {
-return ENOMEM;
-}
-}
-grp_state->queued_members[grp_state->queue_len] = user_dn;
-grp_state->queue_len++;
-} else {
-subreq = sdap_get_generic_send(grp_state,
-   grp_state->ev,
-   grp_state->opts,
-   grp_state->sh,
-   user_dn,
-   LDAP_SCOPE_BASE,
-   grp_state->filter,
-   grp_state->attrs,
-   grp_state->opts->user_map,
-   grp_state->opts->user_map_cnt,
-   dp_opt_get_int(grp_state->opts->basic,
-  SDAP_SEARCH_TIMEOUT),
-   false);
-if (!subreq) {
-return ENOMEM;
-}
-tevent_req_set_callback(subreq, sdap_process_group_members, req);
+subreq = sdap_get_generic_send(grp_state,
+   grp_state->ev,
+   grp_state->opts,
+   

[SSSD] [sssd PR#132][synchronized] Add "Wants=" to sssd unit

2018-08-07 Thread fidencio
   URL: https://github.com/SSSD/sssd/pull/132
Author: fidencio
 Title: #132: Add "Wants=" to sssd unit
Action: synchronized

To pull the PR as Git branch:
git remote add ghsssd https://github.com/SSSD/sssd
git fetch ghsssd pull/132/head:pr132
git checkout pr132
From e73039251d582f51ff514dca3a11d13bda303655 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Fabiano=20Fid=C3=AAncio?= 
Date: Tue, 24 Jan 2017 09:36:34 +0100
Subject: [PATCH] SSSD: Add a list of dependent services to sssd.service
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit

Let's add a list of dependent services to the sssd unit file so we can
have all those services enable by default when enabling sssd unit.

As it differs from our first approach were all services were disabled by
default, the manuals have also been updated.

Related:
https://fedorahosted.org/sssd/ticket/2243

Signed-off-by: Fabiano Fidêncio 
---
 Makefile.am  | 14 +-
 src/man/sssd-sudo.5.xml  |  3 +--
 src/man/sssd.conf.5.xml  |  7 ---
 src/sysv/systemd/sssd.service.in |  2 +-
 4 files changed, 19 insertions(+), 7 deletions(-)

diff --git a/Makefile.am b/Makefile.am
index ea7648bcd5..ff16a3f5ea 100644
--- a/Makefile.am
+++ b/Makefile.am
@@ -4618,6 +4618,7 @@ endif
 init_SCRIPTS =
 systemdunit_DATA =
 systemdconf_DATA =
+sssd_dependent_services =
 if HAVE_SYSTEMD_UNIT
 systemdunit_DATA += \
 src/sysv/systemd/sssd.service \
@@ -4629,11 +4630,15 @@ if HAVE_SYSTEMD_UNIT
 src/sysv/systemd/sssd-secrets.socket \
 src/sysv/systemd/sssd-secrets.service \
 $(NULL)
+
+sssd_dependent_services += sssd-nss.socket sssd-pam.socket
 if BUILD_AUTOFS
 systemdunit_DATA += \
 src/sysv/systemd/sssd-autofs.socket \
 src/sysv/systemd/sssd-autofs.service \
 $(NULL)
+
+sssd_dependent_services += sssd-autofs.socket
 endif
 if BUILD_IFP
 systemdunit_DATA += \
@@ -4645,18 +4650,24 @@ if BUILD_PAC_RESPONDER
 src/sysv/systemd/sssd-pac.socket \
 src/sysv/systemd/sssd-pac.service \
 $(NULL)
+
+sssd_dependent_services += sssd-pac.socket
 endif
 if BUILD_SSH
 systemdunit_DATA += \
 src/sysv/systemd/sssd-ssh.socket \
 src/sysv/systemd/sssd-ssh.service \
 $(NULL)
+
+sssd_dependent_services += sssd-ssh.socket
 endif
 if BUILD_SUDO
 systemdunit_DATA += \
 src/sysv/systemd/sssd-sudo.socket \
 src/sysv/systemd/sssd-sudo.service \
 $(NULL)
+
+sssd_dependent_services += sssd-sudo.socket
 endif
 if BUILD_KCM
 systemdunit_DATA += \
@@ -4703,7 +4714,8 @@ edit_cmd = $(SED) \
 -e 's|@libexecdir[@]|$(libexecdir)|g' \
 -e 's|@pipepath[@]|$(pipepath)|g' \
 -e 's|@prefix[@]|$(prefix)|g' \
--e 's|@SSSD_USER[@]|$(SSSD_USER)|g'
+-e 's|@SSSD_USER[@]|$(SSSD_USER)|g' \
+-e 's|@sssd_dependent_services[@]|${sssd_dependent_services}|g'
 
 replace_script = \
 @rm -f $@ $@.tmp; \
diff --git a/src/man/sssd-sudo.5.xml b/src/man/sssd-sudo.5.xml
index 5bc56c4633..cb085419ab 100644
--- a/src/man/sssd-sudo.5.xml
+++ b/src/man/sssd-sudo.5.xml
@@ -110,8 +110,7 @@ ldap_sudo_search_base = ou=sudoers,dc=example,dc=com
 
 It's important to note that on platforms where systemd is supported
 there's no need to add the "sudo" provider to the list of services,
-as it became optional. However, sssd-sudo.socket must be enabled
-instead.
+as it became optional.
 
 
 
diff --git a/src/man/sssd.conf.5.xml b/src/man/sssd.conf.5.xml
index ed3c100128..eda43bafba 100644
--- a/src/man/sssd.conf.5.xml
+++ b/src/man/sssd.conf.5.xml
@@ -220,9 +220,10 @@
 
 
 
-By default, all services are disabled and the administrator
-must enable the ones allowed to be used by executing:
-"systemctl enable sssd-@service@.socket".
+By default, all services are enabled.
+In case the Administrator wants to persistently disable
+one of them, it can be done by running:
+"systemctl mask sssd-@service@.socket"
 
 
 
diff --git a/src/sysv/systemd/sssd.service.in b/src/sysv/systemd/sssd.service.in
index 0c515d34ca..49c09ea583 100644
--- a/src/sysv/systemd/sssd.service.in
+++ b/src/sysv/systemd/sssd.service.in
@@ -2,7 +2,7 @@
 Description=System Security Services Daemon
 # SSSD must be running before we permit user sessions
 Before=systemd-user-sessions.service nss-user-lookup.target
-Wants=nss-user-lookup.target
+Wants=nss-use

[SSSD] [sssd PR#132][comment] Add "Wants=" to sssd unit

2018-08-07 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/132
Title: #132: Add "Wants=" to sssd unit

fidencio commented:
"""
Just rebased atop of git master.
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/132#issuecomment-44188
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/MCG256QKWHBJJMLTSJRHTQSKYRLL7EHX/


[SSSD] [sssd PR#601][+postponed until sssd 2.0] sbus: integrate sssd with sbus2

2018-08-07 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/601
Title: #601: sbus: integrate sssd with sbus2

Label: +postponed until sssd 2.0
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/DZEOYZZQN66VBHYFQ5COP7Y6KTMKWLQW/


[SSSD] [sssd PR#628][+postponed until sssd 2.0] providers: drop ldap_{init, }groups_use_matching_rule_in_chain support

2018-08-07 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/628
Title: #628: providers: drop ldap_{init,}groups_use_matching_rule_in_chain 
support

Label: +postponed until sssd 2.0
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/FVAF2Q7ZQ56TBRWR5BODODSV5ZYZSNSC/


[SSSD] [sssd PR#611][+postponed until sssd 2.0] Do not build the local provider by default

2018-08-07 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/611
Title: #611: Do not build the local provider by default

Label: +postponed until sssd 2.0
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/2U7ADTDVRRH2RM7KDCIXEL3JCBROFNFI/


[SSSD] [sssd PR#627][+postponed until sssd 2.0] providers: disable ldap_sudo_include_regexp by default

2018-08-07 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/627
Title: #627: providers: disable ldap_sudo_include_regexp by default

Label: +postponed until sssd 2.0
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/T43DM5SGGFVLBX3AU3UAHGOHLHMXSHCB/


[SSSD] [sssd PR#628][comment] providers: drop ldap_{init, }groups_use_matching_rule_in_chain support

2018-08-07 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/628
Title: #628: providers: drop ldap_{init,}groups_use_matching_rule_in_chain 
support

fidencio commented:
"""
@jhrozek, I **know** your preference of moving the deleted code to a file as 
the first step and then removing the file in order to make the backport easy 
for whoever is interested on keeping it downstream. Before actually moving 
those, I'd like to double-check if the patch is removing the expected piece of 
code and once we agree on that I'll re-work it and follow your 
advice/preference.
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/628#issuecomment-411025608
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/TJ2MF3IMCQ7ZF7N3VDTECWJBV3Q44DZH/


[SSSD] [sssd PR#628][opened] providers: drop ldap_{init, }groups_use_matching_rule_in_chain support

2018-08-07 Thread fidencio
   URL: https://github.com/SSSD/sssd/pull/628
Author: fidencio
 Title: #628: providers: drop ldap_{init,}groups_use_matching_rule_in_chain 
support
Action: opened

PR body:
"""
Resolves:
https://pagure.io/SSSD/sssd/issue/3492

Signed-off-by: Fabiano Fidêncio 
"""

To pull the PR as Git branch:
git remote add ghsssd https://github.com/SSSD/sssd
git fetch ghsssd pull/628/head:pr628
git checkout pr628
From d4c5e62d0d5725c666ab7fc5ac124579dc2b0a53 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Fabiano=20Fid=C3=AAncio?= 
Date: Tue, 7 Aug 2018 11:04:53 +0200
Subject: [PATCH] providers: drop ldap_{init,}groups_use_matching_rule_in_chain
 support
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit

Resolves:
https://pagure.io/SSSD/sssd/issue/3492

Signed-off-by: Fabiano Fidêncio 
---
 src/config/SSSDConfig/__init__.py.in  |   2 -
 src/config/cfg_rules.ini  |   2 -
 src/config/etc/sssd.api.d/sssd-ad.conf|   2 -
 src/config/etc/sssd.api.d/sssd-ipa.conf   |   2 -
 src/config/etc/sssd.api.d/sssd-ldap.conf  |   2 -
 src/man/sssd-ldap.5.xml   |  59 
 src/providers/ad/ad_opts.c|   2 -
 src/providers/ipa/ipa_opts.c  |   2 -
 src/providers/ldap/ldap_opts.c|   2 -
 src/providers/ldap/sdap.h |   2 -
 src/providers/ldap/sdap_async.c   |  84 +-
 src/providers/ldap/sdap_async.h   |  15 -
 src/providers/ldap/sdap_async_groups.c| 141 +
 src/providers/ldap/sdap_async_initgroups.c|  18 --
 src/providers/ldap/sdap_async_initgroups_ad.c | 277 --
 15 files changed, 7 insertions(+), 605 deletions(-)

diff --git a/src/config/SSSDConfig/__init__.py.in b/src/config/SSSDConfig/__init__.py.in
index 32b74e4c76..1210f0914e 100644
--- a/src/config/SSSDConfig/__init__.py.in
+++ b/src/config/SSSDConfig/__init__.py.in
@@ -405,8 +405,6 @@ option_strings = {
 'ldap_idmap_default_domain_sid' : _('SID of the default domain for ID-mapping'),
 'ldap_idmap_helper_table_size' : _('Number of secondary slices'),
 
-'ldap_groups_use_matching_rule_in_chain' : _('Use LDAP_MATCHING_RULE_IN_CHAIN for group lookups'),
-'ldap_initgroups_use_matching_rule_in_chain' : _('Use LDAP_MATCHING_RULE_IN_CHAIN for initgroup lookups'),
 'ldap_use_tokengroups' : _('Whether to use Token-Groups'),
 'ldap_min_id' : _('Set lower boundary for allowed IDs from the LDAP server'),
 'ldap_max_id' : _('Set upper boundary for allowed IDs from the LDAP server'),
diff --git a/src/config/cfg_rules.ini b/src/config/cfg_rules.ini
index 5513227803..7016243675 100644
--- a/src/config/cfg_rules.ini
+++ b/src/config/cfg_rules.ini
@@ -611,7 +611,6 @@ option = ldap_group_objectsid
 option = ldap_group_search_base
 option = ldap_group_search_filter
 option = ldap_group_search_scope
-option = ldap_groups_use_matching_rule_in_chain
 option = ldap_group_type
 option = ldap_group_uuid
 option = ldap_idmap_autorid_compat
@@ -623,7 +622,6 @@ option = ldap_idmap_range_max
 option = ldap_idmap_range_min
 option = ldap_idmap_range_size
 option = ldap_id_use_start_tls
-option = ldap_initgroups_use_matching_rule_in_chain
 option = ldap_krb5_init_creds
 option = ldap_krb5_keytab
 option = ldap_krb5_ticket_lifetime
diff --git a/src/config/etc/sssd.api.d/sssd-ad.conf b/src/config/etc/sssd.api.d/sssd-ad.conf
index 8d97a416c8..fad5d30941 100644
--- a/src/config/etc/sssd.api.d/sssd-ad.conf
+++ b/src/config/etc/sssd.api.d/sssd-ad.conf
@@ -129,8 +129,6 @@ ldap_idmap_autorid_compat = bool, None, false
 ldap_idmap_default_domain = str, None, false
 ldap_idmap_default_domain_sid = str, None, false
 ldap_idmap_helper_table_size = int, None, false
-ldap_groups_use_matching_rule_in_chain = bool, None, false
-ldap_initgroups_use_matching_rule_in_chain = bool, None, false
 ldap_use_tokengroups = bool, None, false
 ldap_rfc2307_fallback_to_local_users = bool, None, false
 ldap_pwdlockout_dn = str, None, false
diff --git a/src/config/etc/sssd.api.d/sssd-ipa.conf b/src/config/etc/sssd.api.d/sssd-ipa.conf
index ab9634c7a6..9c7f395450 100644
--- a/src/config/etc/sssd.api.d/sssd-ipa.conf
+++ b/src/config/etc/sssd.api.d/sssd-ipa.conf
@@ -135,8 +135,6 @@ ldap_idmap_autorid_compat = bool, None, false
 ldap_idmap_default_domain = str, None, false
 ldap_idmap_default_domain_sid = str, None, false
 ldap_idmap_helper_table_size = int, None, false
-ldap_groups_use_matching_rule_in_chain = bool, None, false
-ldap_initgroups_use_matching_rule_in_chain = bool, None, false
 ldap_use_tokengroups = bool, None, false
 ldap_rfc2307_fallback_to_local_users = bool, None, false
 ipa_server_mode = bool, None, false
diff --git a/src/config/etc/sssd.api.d/sssd-ldap.conf b/src/config/etc/sssd.api.d/sssd-ldap.conf
index 65b6407f68..655445d2ac 100644
--- a/src/config/etc/sssd.api.d/sssd-ldap.conf
+++ b/src/config/etc/sssd.api.d/sssd-ldap.conf
@@ -122,8 +122,6 @@ ld

[SSSD] [sssd PR#397][+Accepted] cleanup: Remove CONFDB_DOMAIN_LEGACY_PASS

2018-08-07 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/397
Title: #397: cleanup: Remove CONFDB_DOMAIN_LEGACY_PASS

Label: +Accepted
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/MT3EQCWY5E25CU3B6MJKSEM6557JF5Z2/


[SSSD] [sssd PR#397][comment] cleanup: Remove CONFDB_DOMAIN_LEGACY_PASS

2018-08-07 Thread fidencio
  URL: https://github.com/SSSD/sssd/pull/397
Title: #397: cleanup: Remove CONFDB_DOMAIN_LEGACY_PASS

fidencio commented:
"""
CI: http://vm-031.${abc}/logs/job/91/73/summary.html
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/397#issuecomment-411022210
___
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-devel@lists.fedorahosted.org/message/WUCRNJ5BMPRV46JGL35CAVK6PQV4GM34/


[SSSD] [sssd PR#397][synchronized] cleanup: Remove CONFDB_DOMAIN_LEGACY_PASS

2018-08-07 Thread fidencio
   URL: https://github.com/SSSD/sssd/pull/397
Author: amitkumar50
 Title: #397: cleanup: Remove CONFDB_DOMAIN_LEGACY_PASS
Action: synchronized

To pull the PR as Git branch:
git remote add ghsssd https://github.com/SSSD/sssd
git fetch ghsssd pull/397/head:pr397
git checkout pr397
From a40dea9192f0382c47d14403306bb2d53bcf870f Mon Sep 17 00:00:00 2001
From: amitkuma 
Date: Tue, 3 Oct 2017 20:49:45 +0530
Subject: [PATCH] confdb: Remove CONFDB_DOMAIN_LEGACY_PASS

As CONFDB_DOMAIN_LEGACY_PASS is legacy parameter that is rooted in
pre-1.0 SSSD, let's just nuke it now as we're already removing other
legacy code.

Resolves:
https://pagure.io/SSSD/sssd/issue/3530
---
 src/confdb/confdb.c  | 8 
 src/confdb/confdb.h  | 2 --
 src/config/SSSDConfig/__init__.py.in | 1 -
 src/config/SSSDConfigTest.py | 2 --
 src/config/cfg_rules.ini | 1 -
 src/config/etc/sssd.api.conf | 1 -
 src/db/sysdb_ops.c   | 2 +-
 7 files changed, 1 insertion(+), 16 deletions(-)

diff --git a/src/confdb/confdb.c b/src/confdb/confdb.c
index a3eb9c66d9..7017f1bcbf 100644
--- a/src/confdb/confdb.c
+++ b/src/confdb/confdb.c
@@ -,14 +,6 @@ static int confdb_get_domain_internal(struct confdb_ctx *cdb,
 goto done;
 }
 
-ret = get_entry_as_bool(res->msgs[0], >legacy_passwords,
-CONFDB_DOMAIN_LEGACY_PASS, 0);
-if(ret != EOK) {
-DEBUG(SSSDBG_FATAL_FAILURE,
-  "Invalid value for %s\n", CONFDB_DOMAIN_LEGACY_PASS);
-goto done;
-}
-
 /* Get the global entry cache timeout setting */
 ret = get_entry_as_uint32(res->msgs[0], _cache_timeout,
   CONFDB_DOMAIN_ENTRY_CACHE_TIMEOUT, 5400);
diff --git a/src/confdb/confdb.h b/src/confdb/confdb.h
index 8af625f018..4ad483689e 100644
--- a/src/confdb/confdb.h
+++ b/src/confdb/confdb.h
@@ -203,7 +203,6 @@
 #define CONFDB_DOMAIN_CACHE_CREDS_MIN_FF_LENGTH \
  "cache_credentials_minimal_first_factor_length"
 #define CONFDB_DEFAULT_CACHE_CREDS_MIN_FF_LENGTH 8
-#define CONFDB_DOMAIN_LEGACY_PASS "store_legacy_passwords"
 #define CONFDB_DOMAIN_AUTO_UPG "auto_private_groups"
 #define CONFDB_DOMAIN_FQ "use_fully_qualified_names"
 #define CONFDB_DOMAIN_ENTRY_CACHE_TIMEOUT "entry_cache_timeout"
@@ -321,7 +320,6 @@ struct sss_domain_info {
 
 bool cache_credentials;
 uint32_t cache_credentials_min_ff_length;
-bool legacy_passwords;
 bool case_sensitive;
 bool case_preserve;
 
diff --git a/src/config/SSSDConfig/__init__.py.in b/src/config/SSSDConfig/__init__.py.in
index 32b74e4c76..be2e29ce50 100644
--- a/src/config/SSSDConfig/__init__.py.in
+++ b/src/config/SSSDConfig/__init__.py.in
@@ -163,7 +163,6 @@ option_strings = {
 'max_id' : _('Maximum user ID'),
 'enumerate' : _('Enable enumerating all users/groups'),
 'cache_credentials' : _('Cache credentials for offline login'),
-'store_legacy_passwords' : _('Store password hashes'),
 'use_fully_qualified_names' : _('Display users/groups in fully-qualified form'),
 'ignore_group_members' : _('Don\'t include group members in group lookups'),
 'entry_cache_timeout' : _('Entry cache timeout length (seconds)'),
diff --git a/src/config/SSSDConfigTest.py b/src/config/SSSDConfigTest.py
index 87d1f6e641..7117d2972f 100755
--- a/src/config/SSSDConfigTest.py
+++ b/src/config/SSSDConfigTest.py
@@ -573,7 +573,6 @@ def testListOptions(self):
 'enumerate',
 'cache_credentials',
 'cache_credentials_minimal_first_factor_length',
-'store_legacy_passwords',
 'use_fully_qualified_names',
 'ignore_group_members',
 'filter_users',
@@ -944,7 +943,6 @@ def testRemoveProvider(self):
 'enumerate',
 'cache_credentials',
 'cache_credentials_minimal_first_factor_length',
-'store_legacy_passwords',
 'use_fully_qualified_names',
 'ignore_group_members',
 'filter_users',
diff --git a/src/config/cfg_rules.ini b/src/config/cfg_rules.ini
index 5513227803..28102732bc 100644
--- a/src/config/cfg_rules.ini
+++ b/src/config/cfg_rules.ini
@@ -355,7 +355,6 @@ option = subdomain_enumerate
 option = offline_timeout
 option = cache_credentials
 option = cache_credentials_minimal_first_factor_length
-option = store_legacy_passwords
 option = use_fully_qualified_names
 option = ignore_group_members
 option = entry_cache_timeout
diff --git a/src/config/etc/sssd.api.conf b/src/config/etc/sssd.api.conf
index 2be2e3e685..c25592f174 100644
--- a/src/config/etc/sssd.api.conf
+++ b/src/config/etc/sssd.api.conf
@@ -159,7 +159,6 @@ subdomain_enumerate = str, None, false
 offline_timeout = int, None, false
 cache_credentials = bool, None, false
 cache_credentials_minimal_first_factor_length = int, None, false
-store_legacy_passwords = bool, None, false
 use_fully_qualified_names = bool, None, false

  1   2   3   4   5   6   7   8   9   10   >