On Fri, 2015-12-04 at 15:39 +0100, Jan Cholasta wrote:
> On 4.12.2015 15:16, Jan Cholasta wrote:
> > On 4.12.2015 15:12, Jan Cholasta wrote:
> >> On 4.12.2015 11:15, Petr Vobornik wrote:
> >>> On 12/03/2015 03:11 PM, Martin Basti wrote:
> >>>>
> >>>>
> >>>> On 01.12.2015 12:19, Jan Cholasta wrote:
> >>>>> On 23.11.2015 15:47, Simo Sorce wrote:
> >>>>>> On Mon, 2015-11-23 at 15:37 +0100, Jan Cholasta wrote:
> >>>>>>>
> >>>>>>> Ad alternative is to add the host to ipaservers before the checks
> >>>>>>> are
> >>>>>>> done and remove it again if any of them fail.
> >>>>>>
> >>>>>> Too error prone, I am ok with the current way in your patches
> >>>>>> until/unless I can think of a fail safe way. :-)
> >>>>>
> >>>>> Updated patches attached. Note that 520 should be applied between 509
> >>>>> and 510.
> >>>>>
> >>>>>
> >>>>>
> >>>> Functional ACK
> >>>>
> >>>
> >>> Simo, do you want to review the ACIs or other things it the patches? Or
> >>> can the patches be pushed?
> >>
> >> There were no changes in the ACIs since last time.
> >
> > Actually, memberPrincipal was removed from the "IPA server hosts can
> > manage own Custodia secrets" ACI, as per Simo's request.
> >
> >>
> >> Rebased patches attached.
> 
> Note that 520 should still be applied between 509 and 510.
> 

LGTM

-- 
Simo Sorce * Red Hat, Inc * New York

-- 
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Reply via email to