[Freeipa-devel] Re: authconfig replacement design

2018-02-26 Thread Lukas Slebodnik via FreeIPA-devel
On (23/02/18 13:08), Martin Kosek via FreeIPA-devel wrote:
>On 02/21/2018 03:39 PM, Rob Crittenden via FreeIPA-devel wrote:
 - install client
   a) if we replace rpm dependancy on authconfig with aushselect we can
 go only this way: new installations done with authselect. if --no-sssd
 option is provided, then fail.
>>> --no-sssd option is already deprecated and should not be used, you don't
>>> have to think about that scenario. You can therefore go the a) way and
>>> remove the option as a whole so that you can be sure it won't fiddle
>>> with new installations.
>> I can't seem to find anywhere that this deprecation was announced or
>> discussed other than the ticket and commit,
>> dfc271fdf4514481c11c342fabda135feeb44de6.
>> 
>> Did anyone ask users, or anyone, if they use this option?
>> 
>> In any case it isn't even clear that the option *is* deprecated. It just
>> doesn't show as an option to ipa-client -install (hiding is not
>> deprecating).
>> 
>> IMHO to properly deprecate something it should yell loudly whenever
>> invoked with a dire warning that it will disappear in the future.
>
>This mostly seems as a review feedback that could have come in
>https://pagure.io/freeipa/issue/5860
>but did not. But it does not change anything on the fact that the option
>is deprecated.
>
>> There is also no man page mention of deprecation, in fact the option is
>> still there.
>> 
>> So even if the deprecation is fine and considered, removing the option
>> completely has had no visible discussion.
>
>Let's discuss it then. From Fedora/RHEL point of view, I do not see big
>value in spending much time in maintaining, supporting or developing
>non-SSSD scenarios. Fedora itself does not support these scenarios any
>more, after the authselect Fedora change. These very corner cases are
>left for manual administrator configuration.
>
>The non-SSSD work and code should be left to FreeIPA platform code, for
>platforms that do not use or want to use SSSD.

Which platform do you have in mind?
Because I do not know any platform/distribution which has freeipa-client
and does not have sssd.

LS
___
FreeIPA-devel mailing list -- freeipa-devel@lists.fedorahosted.org
To unsubscribe send an email to freeipa-devel-le...@lists.fedorahosted.org


[Freeipa-devel] Re: [Freeipa-users] FreeIPA wiki: troubleshooting

2017-11-14 Thread Lukas Slebodnik via FreeIPA-devel
On (13/11/17 12:45), Florence Blanc-Renaud via FreeIPA-users wrote:
>Hi all,
>
>FreeIPA wiki contains a really long page for Troubleshooting [1], and I would
>like to re-organize the content a little bit differently.
>
+1 for the effort.

BTW it might be good to have a section with links to troubleshooting of
"subcomponents" DNS(bind-dyndb-ldap), client(SSSD) ...

LS
___
FreeIPA-devel mailing list -- freeipa-devel@lists.fedorahosted.org
To unsubscribe send an email to freeipa-devel-le...@lists.fedorahosted.org


[Freeipa-devel] Re: [copr freeipa-master] sssd-1.15.3-0.beta.5.fc27 and libldb-1.2.0-1.fc27 removed

2017-07-21 Thread Lukas Slebodnik via FreeIPA-devel
On (18/07/17 20:12), Alexander Bokovoy via FreeIPA-devel wrote:
>On ti, 18 heinä 2017, Tomas Krizek via FreeIPA-devel wrote:
>> Hi,
>> 
>> builds
>> 
>> sssd-1.15.3-0.beta.5.fc27 and
>> libldb-1.2.0-1.fc27
>> 
>> caused a segfault when starting sssd service. I removed these builds
>> from copr. Instead, I added libldb-1.1.31-1.fc27, which is required by
>> samba.
>Please do not do that! Return them back.
>
>You should remove sssd-1.15.3-0.201703... from your system instead.
>We removed it from the repo because dnf thinks it is of a higher version
>than 0.beta.5.fc27. Technically, it is true in rpm comparisons but SSSD
>guys are unwilling to fix their versioning scheme for a single wrongly
>named sssd build in freeipa copr repo.
>
copr should contain just packages from fedora. And sssd-1.15.3-0.201703*
has never been in fedora and therefore it is a unsupportable build.
And should have never been there.

LS
___
FreeIPA-devel mailing list -- freeipa-devel@lists.fedorahosted.org
To unsubscribe send an email to freeipa-devel-le...@lists.fedorahosted.org