Re: [Freeipa-devel] Added kpasswd_server directive in client krb5.conf

2016-01-05 Thread Christian Heimes
On 2016-01-04 23:38, Nalin Dahyabhai wrote:
> On Mon, Dec 21, 2015 at 12:17:08PM +0530, Abhijeet Kasurde wrote:
>> Hi All,
>>
>> Please review patches attached.
> 
> The port number should probably be changed from 749 to 464.

Nalin is correct. kpasswd and admin server use different ports:

$ getent services kpasswd
kpasswd   464/tcp kpwd
$ getent services kerberos-adm
kerberos-adm  749/tcp

Except for the port number, the patch looks good to me.

Christian



signature.asc
Description: OpenPGP digital signature
-- 
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Re: [Freeipa-devel] Added kpasswd_server directive in client krb5.conf

2016-01-04 Thread Nalin Dahyabhai
On Mon, Dec 21, 2015 at 12:17:08PM +0530, Abhijeet Kasurde wrote:
> Hi All,
> 
> Please review patches attached.

The port number should probably be changed from 749 to 464.

HTH,

Nalin

-- 
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code


[Freeipa-devel] Added kpasswd_server directive in client krb5.conf

2015-12-20 Thread Abhijeet Kasurde

Hi All,

Please review patches attached.

Thanks,
Abhijeet Kasurde
From a03a2d9c5668dbfcdde6794af1725e546cd3ed41 Mon Sep 17 00:00:00 2001
From: Abhijeet Kasurde 
Date: Mon, 21 Dec 2015 12:11:31 +0530
Subject: [PATCH] Added kpasswd_server directive in client krb5.conf

While configuring ipa client using ipa-client-install can configure
kpasswd_server explicitly using directive in client's krb5.conf

https://fedorahosted.org/freeipa/ticket/5547

Signed-off-by: Abhijeet Kasurde 
---
 ipa-client/ipa-install/ipa-client-install | 4 
 1 file changed, 4 insertions(+)

diff --git a/ipa-client/ipa-install/ipa-client-install b/ipa-client/ipa-install/ipa-client-install
index 789ff591591673744ee3b922e5c0181233ad553c..147ea691c8e4dbf0103ae874a2fcb12f8104d0e4 100755
--- a/ipa-client/ipa-install/ipa-client-install
+++ b/ipa-client/ipa-install/ipa-client-install
@@ -1103,6 +1103,10 @@ def configure_krb5_conf(cli_realm, cli_domain, cli_server, cli_kdc, dnsok,
 kropts.append({'name':'kdc', 'type':'option', 'value':ipautil.format_netloc(server, 88)})
 kropts.append({'name':'master_kdc', 'type':'option', 'value':ipautil.format_netloc(server, 88)})
 kropts.append({'name':'admin_server', 'type':'option', 'value':ipautil.format_netloc(server, 749)})
+kropts.append({'name': 'kpasswd_server',
+   'type': 'option',
+   'value': ipautil.format_netloc(server, 749)
+  })
 kropts.append({'name':'default_domain', 'type':'option', 'value':cli_domain})
 kropts.append({'name':'pkinit_anchors', 'type':'option', 'value':'FILE:%s' % CACERT})
 ropts = [{'name':cli_realm, 'type':'subsection', 'value':kropts}]
-- 
2.4.3

From 3b43be08da0981236764f2e23f3067fe47eafe9d Mon Sep 17 00:00:00 2001
From: Abhijeet Kasurde 
Date: Mon, 21 Dec 2015 12:03:10 +0530
Subject: [PATCH] Added kpasswd_server directive in client krb5.conf

While configuring ipa client using ipa-client-install can configure
kpasswd_server explicitly using directive in client's krb5.conf

https://fedorahosted.org/freeipa/ticket/5547

Signed-off-by: Abhijeet Kasurde 
---
 ipa-client/ipa-install/ipa-client-install | 4 
 1 file changed, 4 insertions(+)

diff --git a/ipa-client/ipa-install/ipa-client-install b/ipa-client/ipa-install/ipa-client-install
index e9a7d45c3f82a58f6297db7354eb784f6416db4b..e98d52891eb5fc4a993f8b21efc44f7293c8a2a9 100755
--- a/ipa-client/ipa-install/ipa-client-install
+++ b/ipa-client/ipa-install/ipa-client-install
@@ -1106,6 +1106,10 @@ def configure_krb5_conf(cli_realm, cli_domain, cli_server, cli_kdc, dnsok,
 kropts.append({'name':'kdc', 'type':'option', 'value':ipautil.format_netloc(server, 88)})
 kropts.append({'name':'master_kdc', 'type':'option', 'value':ipautil.format_netloc(server, 88)})
 kropts.append({'name':'admin_server', 'type':'option', 'value':ipautil.format_netloc(server, 749)})
+kropts.append({'name': 'kpasswd_server',
+   'type': 'option',
+   'value': ipautil.format_netloc(server, 749)
+  })
 kropts.append({'name':'default_domain', 'type':'option', 'value':cli_domain})
 kropts.append({'name':'pkinit_anchors', 'type':'option', 'value':'FILE:%s' % CACERT})
 ropts = [{'name':cli_realm, 'type':'subsection', 'value':kropts}]
-- 
2.4.3

-- 
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code