On Fri, 20 Jun 2014, Martin Basti wrote:
On Fri, 2014-06-20 at 10:32 +0200, Jan Cholasta wrote:
On 18.6.2014 16:49, Martin Basti wrote:
> Due to compability with older versions, only IDNA domains should be
> checked
> Patch attached.

I'm not particularly happy about the u'\xdf' special case. Isn't there a
better way to do this check?
I cant find better way. u'\xdf' is mapped to ss, and ss is not IDN string.

Or just remove this validation.

(BTW I really think this should be a warning, not an error, but that
would require larger amount of work, so I guess it's OK for now.)
(More pain than gain)
Main thing in this patch is that the check should not be done against
non-IDN strings. I want this version of the patch to go in for that
reason as currently you cannot even complete ipa-adtrust-install run due
to IDN normalisation check being applied to non-IDN domains.
--
/ Alexander Bokovoy

_______________________________________________
Freeipa-devel mailing list
Freeipa-devel@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-devel

Reply via email to