Re: NFS4 and Kerberos (next steps)

2011-01-09 Thread Andreas B. Mundt
Hi Mike, On Sat, Jan 08, 2011 at 11:41:42PM +0100, Mike Gabriel wrote: [...] > Here is what I will do next: > > 1) > > o I have a Debian server setup in the cloud for my ,,company'' > with a working > NFSv4+Kerberos server setup > o I have installed a Debian SID in the cloud today that I

LINBO and "self-healing" workstations

2011-01-08 Thread Andreas B. Mundt
Hi, as we are just discussing future development, I would like to understand the concept and the ideas behind LINBO and "self-healing" workstations better. >From a quick search I found that it is used to quickly (re-)install workstations that are spoiled. Ok, now I know from my system here at t

Re: NFS4 and Kerberos

2011-01-07 Thread Andreas B. Mundt
Hi Mike, On Sat, Jan 08, 2011 at 12:31:16AM +0100, Mike Gabriel wrote: > Hi Andi, > > On Fr 07 Jan 2011 10:41:41 CET "Andreas B. Mundt" wrote: > > >Take a look at > >http://svn.debian.org/wsvn/debian-edu/trunk/src/debian-edu-config/cf/cf.homes>, > >i.

Kerberos in a setup with several A-records to the same IP-address

2011-01-07 Thread Andreas B. Mundt
Hello all, allow me to contact the enterprise list (Cc: debian-edu), because here are probably some experts around that can help with the following issue: When working on the integration of Kerberos for debian-edu, I encountered the following problem: My DNS provides several A-records for the I

Re: NFS4 and Kerberos

2011-01-07 Thread Andreas B. Mundt
Hi, On Thu, Jan 06, 2011 at 10:13:12PM +0100, Mike Gabriel wrote: > Hi Andreas, > > On Do 06 Jan 2011 12:12:35 CET "Andreas B. Mundt" wrote: [...] > > Each client needs a Kerberos setup as well. Is this also already > coded somewhere? I am sorry that I cannot rem

Re: Gosa vs. CipUX

2011-01-06 Thread Andreas B. Mundt
Hi Klaus, On Thu, Jan 06, 2011 at 09:44:35PM +0100, Klaus Knopper wrote: > Hi, > > On Thu, Jan 06, 2011 at 03:48:12PM +0100, Andreas B. Mundt wrote: > > Hi, > > > > On Thu, Jan 06, 2011 at 01:01:57PM +0100, Mike Gabriel wrote: [...] > > Candidates were LWAT use

problems with powerdns and GOsa

2011-01-06 Thread Andreas B. Mundt
Hi, just for the record: I tried to modify the DNS entries in GOsa. This does not work anymore, because: objectClass: domainRelatedObject associateddomain: machine.intern have been added to ldap to make powerDNS work with the structure given by GOsa (prepared for bind). There is work u

Re: NFS4 and Kerberos: A-records for same IP inflate the need for service principals

2011-01-06 Thread Andreas B. Mundt
Hi, On Thu, Jan 06, 2011 at 12:24:02PM +0100, Petter Reinholdtsen wrote: > > However, to come back to the issue, the next step concerning > > kerberos would be to switch to nfs4. > > I assume you are talking about user home directories and shared > folders, and not the LTSP root mount, because LT

Re: Gosa vs. CipUX

2011-01-06 Thread Andreas B. Mundt
Hi, On Thu, Jan 06, 2011 at 01:01:57PM +0100, Mike Gabriel wrote: > Hi there, > > I want to grab one issue from the current NFS4+Krb5 thread that concerns me... > > In Germany there is quite an initiative around CipUX and Skolelinux > going on. Now I read about Gosa being (probably) used for use

Re: NFS4 and Kerberos: A-records for same IP inflate the need for service principals

2011-01-06 Thread Andreas B. Mundt
Hi Mike, On Thu, Jan 06, 2011 at 02:16:53AM +0100, Mike Gabriel wrote: > [...] > On Mi 05 Jan 2011 19:10:24 CET Petter Reinholdtsen wrote: > > >[Andreas B. Mundt] > >>I tried to find the reason for these corresponding A-records, > [...] > > Kerberos demands a

Re: NFS4 and Kerberos: A-records for same IP inflate the need for service principals

2011-01-05 Thread Andreas B. Mundt
On Wed, Jan 05, 2011 at 07:10:24PM +0100, Petter Reinholdtsen wrote: [...] > > I am not an expert regarding that stuff and I don't know if there > > are other ways to achieve the desired. However, it looks as with the > > current setup we need service principals for all host aliases. > > That isn'

NFS4 and Kerberos: A-records for same IP inflate the need for service principals

2011-01-05 Thread Andreas B. Mundt
Hi all, the last days I found a little time to have a look into the issue of using NFSv4 (and perhaps Kerberos) to mount the home directories. I first configured NFS4 to export the home directories. After that I tried kerberos authentication. However, I observed that it works only in some cases,

Re: Why not use NFS4 and Kerberos for mounting the home directories?

2010-12-29 Thread Andreas B. Mundt
On Wed, Dec 29, 2010 at 03:53:12PM +0100, Petter Reinholdtsen wrote: > It was discussed in > http://lists.debian.org/debian-edu/2010/06/msg00061.html > and > also other threads. This one might be interesting too: http://lists.debian.org/debian-edu/2010/07/msg00097.html Cheers, Andi

Why not use NFS4 and Kerberos for mounting the home directories?

2010-12-29 Thread Andreas B. Mundt
Hi all, first, let me apologize for the silence during last months and for not being able to contribute to Debian-Edu. The reasons are complicated probably and not meant to be public; you know, "real life" and the like. However, I would like to take a few minutes to discuss the following issue:

Re: Bug#588510: #588510: rename thin-client-server profile

2010-11-07 Thread Andreas B. Mundt
Hi, On Sun, Nov 07, 2010 at 01:13:38PM +0100, Philipp Hübner wrote: > On 06/11/10 13:11, Justin B Rye wrote: > >> Other, better suggestions? > > > > I've got some other, mostly worse suggestions: > [...] > > - terminal-server (from the expansion of LTSP). > > this would be my personal choice, as

Re: should we really avoid the 686 kernel image?

2010-10-31 Thread Andreas B. Mundt
Hi, On Sat, Oct 30, 2010 at 09:22:08PM +0200, Petter Reinholdtsen wrote: > [Andreas B. Mundt] > > Let's drop blender. It's about the size of a kernel and will hardly > > be used in any school. > > Blender was added (actually changed form suggests to recommend

Re: should we really avoid the 686 kernel image?

2010-10-30 Thread Andreas B. Mundt
Hi, On Sat, Oct 30, 2010 at 04:12:41PM +0200, Petter Reinholdtsen wrote: > > Well, lets begin by exploring why it the 686 kernel is on the avoid > list, then. :) > > It is on the avoid list because each kernel included in the DVD uses > around 25-30 MB on the DVD. That space can be used to incl

Re: should we really avoid the 686 kernel image?

2010-10-30 Thread Andreas B. Mundt
On Sat, Oct 30, 2010 at 03:35:11PM +0200, Holger Levsen wrote: > Hi, > > currently we avoid the 686 kernel image so that the package is not on the > CD/DVD. > > I've just talked with the kernel team about this, and they think its the > wrong > thing to do: > > 1. the 486 kernel only supports

DNS, DHCP and machines in GOsa

2010-10-29 Thread Andreas B. Mundt
Hi, here is a description how to switch DNS, DHCP and machine management over to GOsa. As we disagree on which DNS server (powerdns or bind) to use, I did not commit any changes so far. The setup shown here is using bind. To make it work with powerdns, more changes to the internals (of GOsa(?)

Re: More on the future LDAP admin gui in Debian Edu

2010-10-23 Thread Andreas B. Mundt
On Sat, Oct 23, 2010 at 01:07:27PM +0200, Jonas Smedegaard wrote: > Andreas Mundt has been _very_ active on GoSA (and thanks for that!) > but now starts as a teacher and do not expect himself to be able to > continue contributing at same pace. Regardless of my new job it's not (and probably has a

Re: More on the future LDAP admin gui in Debian Edu

2010-10-23 Thread Andreas B. Mundt
Hello, On Fri, Oct 22, 2010 at 04:38:13PM +0200, Petter Reinholdtsen wrote: > [Andreas B. Mundt] > > So in my opinion, every teacher needs to be able to change/renew the > > password of a pupil. If only admins or jadmins can do that, they > > will not be available when nee

Re: More on the future LDAP admin gui in Debian Edu

2010-10-22 Thread Andreas B. Mundt
Hi all, with regard to the replies to my mail, I conclude that we agree that for the time being it is best to focus on GOsa for squeeze. I hoped that we can get some consensus, which seems to be the case, at least when I look at the replies so far. Well, then let's start to have a look and disc

Re: More on the future LDAP admin gui in Debian Edu

2010-10-21 Thread Andreas B. Mundt
Hi, once again a mail about the LDAP administration tool we need in Debian-Edu. Since Petter's mail http://lists.debian.org/debian-edu/2010/09/msg00110.html> almost a month passed: On Mon, Sep 27, 2010 at 06:59:44PM +0200, Petter Reinholdtsen wrote: > Here is a short update on the LDAP admin stat

Re: RC1 for Debian Edu lenny 5.0.6+edu1 released

2010-10-05 Thread Andreas B. Mundt
Hi, On Tue, Oct 05, 2010 at 11:04:51AM +0200, Holger Levsen wrote: > On Montag, 4. Oktober 2010, Andreas B. Mundt wrote: > > I installed (kvm) a combined tjener/ltsp-server which worked without > > issues. > > dvd or cd? dvd image Cheers, Andi -- To UNSUBSC

Re: RC1 for Debian Edu lenny 5.0.6+edu1 released

2010-10-04 Thread Andreas B. Mundt
Hi Holger, On Mon, Oct 04, 2010 at 09:39:46AM +0200, Holger Levsen wrote: > On Mittwoch, 29. September 2010, Holger Levsen wrote: > > Please test these images as soon and as much as you can and report back > > feedback. As the packages itself are well tested I hope to be able to > > release _these

Re: More on the future LDAP admin gui in Debian Edu

2010-09-28 Thread Andreas B. Mundt
Hi, On Mon, Sep 27, 2010 at 06:59:44PM +0200, Petter Reinholdtsen wrote: > Here is a short update on the LDAP admin status for Debian Edu based > on Squeeze. The short summary is that we have no working alternative > for administrating the LDAP directory information, and basicly is in > an unrele

Re: Bug#593707: debian-edu-artwork: drop build-dep on libusplash-dev

2010-09-16 Thread Andreas B. Mundt
On Thu, Sep 16, 2010 at 09:00:49PM +0200, Holger Levsen wrote: > Hi, > > On Donnerstag, 16. September 2010, Petter Reinholdtsen wrote: > > We are still using the grub splash image and want to use it, so I hope > > you can find another way that keep the grub image. > > > > What about building the u

Re: Gosa risking passwords being logged by sudo (Was: Is LWAT completely broken in Squeeze?)

2010-09-01 Thread Andreas B. Mundt
Hi, On Tue, Aug 24, 2010 at 08:24:26AM +0200, Petter Reinholdtsen wrote: > > The fix for this is to change gosa and the hooks to pass the passwords > in the environment or using stdin, to make sure the password is not > visible in the process list nor logged by sudo. > The suggested fix is in GO

Re: Is LWAT completely broken in Squeeze?

2010-08-23 Thread Andreas B. Mundt
Hi, On Mon, Aug 23, 2010 at 06:42:58PM +0200, Finn-Arne Johansen wrote: > On 13. aug. 2010 13:12, Holger Levsen wrote: > > On Montag, 2. August 2010, Finn-Arne Johansen wrote: [...] > >> release a 0.18 which works with squeeze. > >> > >> Not sure if all patches will make it into 0.18, though. > >>

Re: ldap/gosa postcreation and kerberos password synchronization

2010-08-23 Thread Andreas B. Mundt
Hi, On Mon, Aug 23, 2010 at 06:24:45PM +0200, Finn-Arne Johansen wrote: > On 12. mai 2010 19:26, Andreas B. Mundt wrote: > > I am currently thinking about how to handle the post-creation, > > post-password-change and related stuff properly. > > > > So far, I use the

Re: Fwd: Re: Make /etc/default/slapd automatically configurable

2010-08-09 Thread Andreas B. Mundt
On Tue, Aug 10, 2010 at 12:05:33AM +0200, Petter Reinholdtsen wrote: > [Andreas B. Mundt] > > We use: > > SLAPD_OPTIONS="-4" > > here, which might be there for traditional reasons. > > Not quite sure why we add that one. It was added 2006-01-13 with thi

Re: Fwd: Re: Make /etc/default/slapd automatically configurable

2010-08-09 Thread Andreas B. Mundt
On Sun, Aug 08, 2010 at 05:59:15PM +0200, Luk Claes wrote: > Hi > > Can someone more involved with Debian Edu have a look at this, TIA? [...] > This bug is open for a long time now, what reasonable defaults are > needed for debian-edu ? > > I've attached the default file currently shipped with

How can we gain more flexibility in debian-edu?

2010-08-05 Thread Andreas B. Mundt
Hi, being here in New York at DebConf10, I have the pleasure to be exposed to many suggestions and ideas concerning Debian and free software. In a talk titled 'Managing Debian Installations using GOsa and FAI' http://penta.debconf.org/dc10_schedule/events/556.en.html>, Michael Banck illustrated h

Bug#570767: images should be available in squeeze

2010-08-02 Thread Andreas B. Mundt
Hi, [...] > the Debian Edu Lenny release currently sets up PXE booting out of the box, by > making use of a d-i-bootimages package, which is not available in Debian. > This is annoying as PXE booting is a quite a nice feature and having the d-i > bootimages on the DVD is needed as we want to fu

Re: Enforce the user of Kerberos for password checking?

2010-08-01 Thread Andreas B. Mundt
Hi, On Sun, Aug 01, 2010 at 08:13:20PM +0200, Petter Reinholdtsen wrote: > [Andreas B. Mundt] > > If I understand the mail correctly, it does not set the level needed, > > but it sort of defines/overwrites the level the connection has. > > > > To be accepted, we need

Re: Enforce the user of Kerberos for password checking?

2010-07-31 Thread Andreas B. Mundt
Hi, On Sun, Aug 01, 2010 at 01:09:26AM +0200, Petter Reinholdtsen wrote: > > At the moment the LDAP server in Squeeze is set up to allow all users > to check their password using LDAP bind, but without enforcing > encrypted connections. This can cause the password to be sent in > clear text over

Re: How should we evaluate user applications?

2010-07-30 Thread Andreas B. Mundt
Hi, just a few more thoughts from my point of view: On Wed, Jul 28, 2010 at 10:06:49PM +0200, Petter Reinholdtsen wrote: > [Andreas B. Mundt] > > The "Gymnasium" in Germany takes at least 12 years and pupils start > > school at about 6 years age. There are many pupils

GOsa in unstable

2010-07-28 Thread Andreas B. Mundt
Hi, after the GOsa packages entered unstable a couple of days ago, it is much easier now to have a look what it's gonna look like in debian-edu. Install main-server+workstation alpha0 and just add: deb http://ftp.debian.org/debian/ unstable main to your sources list and install gosa, gosa-plug

Re: How should we evaluate user applications?

2010-07-28 Thread Andreas B. Mundt
Hi, On Wed, Jul 28, 2010 at 08:22:31PM +0200, Petter Reinholdtsen wrote: > > Us developers seem to have slightly different view of what kind of > user applications we should install by default in Debian Edu, and this > make me suspect we should formulate some guidelines and put in the > release m

Re: Please suggest minimal LDAP admin GUI

2010-07-27 Thread Andreas B. Mundt
Hi Jonas, On Sat, Jul 24, 2010 at 02:40:17PM +0200, Jonas Smedegaard wrote: > > Technically, I will most likely code this in Perl as that is what I > am capable of and find trustworthy. Currently I am considering to > use either Gtk2::Ex::FormFactory or Wx::Perl::Dialog, and use an MVC > code st

Re: LDAP GUI roadmap proposal

2010-07-25 Thread Andreas B. Mundt
Hi, On Sun, Jul 25, 2010 at 02:05:19PM +0200, Philipp Huebner wrote: > > something to be considered: > > I believe gosa and cipux to be incompatible. Both bring their own ldap > schemes, and I know that CipUX breaks LWAT (at least partially). > > For these reasons I think we have to decide on ei

LDAP GUI roadmap proposal

2010-07-25 Thread Andreas B. Mundt
Hi all, there have been discussions on the list about perspectives for our LDAP GUI (CIPUX, GOsa, LWAT, in alphabetical order ;-), or even new programs). Stimulated by them, I would like to propose a way how to proceed. As usual, this is my personal view and discussing the arguments is appreciated

New ldap schema for debian-edu?

2010-07-16 Thread Andreas B. Mundt
Hi all, I have been following part of the discussions to refurbish the ldap structure in debian-edu as documented and discussed on IRC and in http://wiki.debian.org/DebianEdu/NewLDAPStructure> http://people.skolelinux.org/pere/blog/Combining_PowerDNS_and_ISC_DHCP_LDAP_objects.html>. Especially w

Re: how to proceed with edu-squeeze changes

2010-06-28 Thread Andreas B. Mundt
On Mon, Jun 28, 2010 at 04:20:52PM +0200, Holger Levsen wrote: > On Mittwoch, 23. Juni 2010, Andreas B. Mundt wrote: > > To test the gosa setup we only need the gosa package. There is one > > in Squeeze, but it does not work at all, see: > >http://bugs.debian.org/573220 [.

Re: Alternative LDAP schema for DNS database (bind9 used by freeipa)

2010-06-24 Thread Andreas B. Mundt
Hi, when trying to add machines with gosa to the dhcp and dns system, I run into related problems. Let me report below. On Thu, Jun 24, 2010 at 01:33:11PM +0200, Petter Reinholdtsen wrote: > > I asked on #freeipa on freenode, where I hang because I maintain sssd > in Debian, about their LDAP sch

Re: how to proceed with edu-squeeze changes

2010-06-23 Thread Andreas B. Mundt
Hi Holger, On Wed, Jun 23, 2010 at 11:54:32AM +0200, Holger Levsen wrote: > > Unfortunatelly the gosa packages are still missing in debian of > > today. I keep on asking the maintainer to finish them. I hope for this > > week. > > Which packages are you talking about exactly? Gosa is in Debian,

Re: how to proceed with edu-squeeze changes

2010-06-23 Thread Andreas B. Mundt
Hi, On Wed, Jun 23, 2010 at 09:53:18AM +0200, Holger Levsen wrote: > very brief comments: > > On Mittwoch, 26. Mai 2010, Andreas B. Mundt wrote: > > So that's the current status from my point of view. What needs to be > > done now? I think we have to make one decis

Re: ejabberd and ldap

2010-06-03 Thread Andreas B. Mundt
On Thu, Jun 03, 2010 at 12:01:04PM +0200, Joakim Seeberg wrote: > Hi, what do I need to change below to make ejabberd authenticate > against ldap. > > %% Authentication using LDAP > %% > {auth_method, ldap}. > %% > %% List of LDAP servers: > {ldap_servers, ["tjener.intern"]}. > %% > %% Encryption

Re: Kerberos config (Was: r64440 - in trunk/src/debian-edu-config: . debian etc)

2010-06-01 Thread Andreas B. Mundt
On Tue, Jun 01, 2010 at 12:48:04PM +0200, Petter Reinholdtsen wrote: > > Added: > >trunk/src/debian-edu-config/etc/krb5.conf > > Modified: > >trunk/src/debian-edu-config/Makefile > >trunk/src/debian-edu-config/debian/changelog > > Log: > > Add kerberos client configuration file krb5.con

Re: mail system in debian-edu: dovecot

2010-05-31 Thread Andreas B. Mundt
Hi all, On Thu, May 27, 2010 at 11:45:06PM +0200, Jürgen Leibner wrote: > On Monday 24 May 2010 16:27 Andreas B. Mundt wrote: [...] > As I noticed that dovecot is a favorite of a lot of people here, I would > say that is my favorite too. ;-) > > I use it as an IMAP Backend for m

ACL for Debian-Edu/Skolelinux

2010-05-28 Thread Andreas B. Mundt
Hi all, currently I am trying to define and preconfigure the gosa ldap tree to include ACLs for easy administration of all users in our schools out of the box. The handling of ACLs in GOsa seems to be rather flexible, so let me outline my ideas how to do it and please comment if there are better w

NFS4 ready for production / Debian-Edu?

2010-05-27 Thread Andreas B. Mundt
Hi Doug, I hope you don't mind if I contact you from the data of your web site. We currently implement kerberos authentication in Debian-Edu, ( http://www.skolelinux.orghttp://wiki.debian.org/DebianEdu ) and on the way I got pointed to your great Kerberos/LDAP/NFSv4 HOWTO: http://www-th

Re: mail system in debian-edu

2010-05-26 Thread Andreas B. Mundt
Hi Sep, On Tue, May 25, 2010 at 02:48:06PM +0200, Ronny Aasen wrote: > Andreas B. Mundt wrote: [...] > Dovecot is what i use on all non -edu machines. It's flexible and > powerful. using dovecot's delivery i implemeny sieve and you get imap re > indexed on delivery making i

how to proceed with edu-squeeze changes

2010-05-26 Thread Andreas B. Mundt
Hi all, there are a couple of changes planed for our debian-edu squeeze version, and I would like to start a discussion on how to proceed with what has been done already and what still needs more work or should be started. First, let's list some targets that come to my mind: * roaming workstatio

Re: mail system in debian-edu

2010-05-24 Thread Andreas B. Mundt
Hi all, after testing some more the various mail systems I would like to share what I figured out so far: Courier: Pros: That's what we use currently. Cons: Does not work currently out of the box with neither lwat in lenny nor gosa in squeeze. No extra GOsa integration (but mi

Re: mail system in debian-edu

2010-05-20 Thread Andreas B. Mundt
Hi, On Wed, May 19, 2010 at 09:49:26PM +0200, Petter Reinholdtsen wrote: > [Andreas B. Mundt] > > This would have one advantage: There is only on location where the > > user's data is stored and if a user is removed, all his mails will > > also be cleared. Are there

mail system in debian-edu

2010-05-19 Thread Andreas B. Mundt
Hi, when trying to get the mail system working out of the box with debian-edu and gosa, I got the following idea: What about using the home directories (~/Maildir) as mail directories instead of /var/mail/foobar? This would have one advantage: There is only on location where the user's data is s

Re: Drop usplash in Squeeze? Move to plymouth?

2010-05-19 Thread Andreas B. Mundt
On Wed, May 19, 2010 at 08:47:14PM +0200, Petter Reinholdtsen wrote: > Should we drop usplash from our package lists in Squeeze? It is as > far as I can see dead upstream, as Ubuntu moved to plymouth as their > boot progress bar, to get flicker free boot. > > It is also the cause of many problems

Re: [GOsa] last(?) missing bit to use gosa in debian-edu out of the box

2010-05-18 Thread Andreas B. Mundt
On Tue, May 18, 2010 at 09:52:08AM +0200, Ronny Aasen wrote: > Holger Levsen wrote: > > On Montag, 10. Mai 2010, Andreas B. Mundt wrote: > >>> after having thought a bit more about the password issue, I think > >>> we perhaps should add one more question during &g

access the cleartext root password during installation

2010-05-15 Thread Andreas B. Mundt
Hi, one of the goals for debian-edu/skolelinux is to provide an easy installation with as little user interaction as possible. To achieve this, we use the root password hash (from the shadow file) for authentication in several places, for example as ldap administrator. There is no need to ask the

how to make sure slapd is started before krb5-kdc

2010-05-15 Thread Andreas B. Mundt
Hi, currently, krb5-kdc fails on startup because it needs slapd running. From /etc/rc2.d: S03krb5-admin-server S03krb5-kdc S03slapd As Petter told me on IRC, you can add # Should-Start: slapd # Should-Stop: slapd to the header of /etc/init.d/krb5-kdc and probably something like: #

Re: sudoers in ldap?

2010-05-14 Thread Andreas B. Mundt
Hi, On Fri, May 14, 2010 at 08:01:07PM +0200, Petter Reinholdtsen wrote: > [Andreas B. Mundt] > > I started now to define a cf rule to edit /etc/sudoers, but hit the > > package sudo-ldap, which might be a better idea: No policy violating > > editing of config file

Re: r64170 - in trunk/src/debian-edu: debian tasks

2010-05-14 Thread Andreas B. Mundt
On Fri, May 14, 2010 at 04:43:53PM +0200, Holger Levsen wrote: > On Freitag, 14. Mai 2010, andi-gu...@alioth.debian.org wrote: > > Modified: > >trunk/src/debian-edu/debian/changelog > >trunk/src/debian-edu/tasks/common > > Log: > > Replace sudo by sudo-ldap in the common tasks. > > Doesnt

Re: sudoers in ldap?

2010-05-14 Thread Andreas B. Mundt
On Fri, May 14, 2010 at 10:50:44AM +0200, Philipp Huebner wrote: > is there a usable module in gosa to edit the sudo information later on? > > If you could set sudo rights through gosa which distinguish between > hosts, that would be really cool! > Yes, there is such a plugin, but I haven't test

sudoers in ldap?

2010-05-14 Thread Andreas B. Mundt
Hi, as you may have noticed I currently try to finish the integration of gosa and kerberos into debian-edu-config. After adding users to ldap, their home directory has to be created, a welcome mail sent and with kerberos you need to create a principal too. With gosa, you can call a script to d

ldap/gosa postcreation and kerberos password synchronization

2010-05-12 Thread Andreas B. Mundt
Hi all, [first, congrats to the gosa-guys for their latest release ;-)] I am currently thinking about how to handle the post-creation, post-password-change and related stuff properly. So far, I use the draft-script attached below which is run by the gosa postcreation hook (www-data added to sudo

Re: HowTo test gosa in debian-edu squeeze

2010-05-12 Thread Andreas B. Mundt
Hello, On Wed, May 12, 2010 at 05:47:11PM +0200, Andreas Schockenhoff wrote: > Dear Andreas, > > Am Dienstag, den 11.05.2010, 14:48 +0200 schrieb Andreas B. Mundt: > > As of today, compile debian-edu-config from svn and install it. > Does this changes popup on the DVD > c

Re: [GOsa] gosa and debian-edu/skolelinux

2010-05-12 Thread Andreas B. Mundt
Hi Benoit, On Tue, May 11, 2010 at 10:17:16PM +0200, Benoit Mortier wrote: > Le Tuesday 11 May 2010 13:45:44 Andreas B. Mundt, vous avez écrit : > > Is there news concerning that issue? > > Yes i'am the one finishing the package in Debian 3.0 format, with all the > lat

password synchronization

2010-05-12 Thread Andreas B. Mundt
Hi Veli-Matti, On Wed, May 05, 2010 at 04:41:41PM +0300, Veli-Matti Lintu wrote: > ma, 2010-05-03 kello 21:47 +0200, Andreas B. Mundt kirjoitti: > > > The critical point in using kerberos is the synchronization > > i.e. integration of all passwords: posix, samba and kerberos.

HowTo test gosa in debian-edu squeeze

2010-05-11 Thread Andreas B. Mundt
Hi, if you are curious to test gosa in debian-edu do the following: Fetch DVD, for example: rsync -avzP ftp.skolelinux.org::cd-edu-testing-nolocal-dvd/debian-edu-amd64-i386-DVD-1.iso debian-edu-DVD-1-squeeze.iso Install mainserver and workstation profile for example: kvm-image create Squeeze

gosa and debian-edu/skolelinux

2010-05-11 Thread Andreas B. Mundt
Hi Benoit, hi all, On Sat, May 08, 2010 at 11:22:22AM +0200, Benoit Mortier wrote: > Le Friday 07 May 2010 22:13:18 Cajus Pollmeier, vous avez écrit : > > Am 07.05.10 16:30, schrieb Andreas B. Mundt: [...] > > In combination with gosa-si, you can plan shutdown, wakeup, reinstall,

Re: [GOsa] last(?) missing bit to use gosa in debian-edu out of the box

2010-05-10 Thread Andreas B. Mundt
On Mon, May 10, 2010 at 02:48:48PM +0200, Andreas B. Mundt wrote: [...] > after having thought a bit more about the password issue, I think > we perhaps should add one more question during > installation/configuration of the main server: Enter the LDAP > password. This is then

Re: [GOsa] last(?) missing bit to use gosa in debian-edu out of the box

2010-05-10 Thread Andreas B. Mundt
On Mon, May 10, 2010 at 12:24:19PM +0200, Cajus Pollmeier wrote: > Am Montag 10 Mai 2010, 12:15:05 schrieb Andreas B. Mundt: [...] > > I currently have only one problem left: How to put the ldap rootdn > > password in the gosa.conf file. After the (cleartext) password has > &g

last(?) missing bit to use gosa in debian-edu out of the box

2010-05-10 Thread Andreas B. Mundt
Hi all, as you probably noticed I currently try to implement gosa in debian-edu as admin tool to manage users and groups (so far). To use gosa out of the box after installation, I already prepared the necessary configurations and the templates added to ldap during ldap-bootstrap, and things look p

Re: [GOsa] configuring gosa during system installation

2010-05-08 Thread Andreas B. Mundt
On Sat, May 08, 2010 at 05:39:57PM +0200, Cajus Pollmeier wrote: > Am Samstag 08 Mai 2010, 14:42:48 schrieb Andreas B. Mundt: [...] > The ACL entry below keeps a comma separated list of base64 encoded dn's and > the final access rights that this one gets. If the dn never changes

configuring gosa during system installation

2010-05-08 Thread Andreas B. Mundt
Hi, many thanks for all the answers and hints so far! I will reply to them soon, but first a technical question that just came up when I excitedly started to make a first draft implementation: To avoid having the user to click through the gosa builtin "configurator" after installing the system,

Re: [GOsa] Netgroups and ACL's

2010-05-07 Thread Andreas B. Mundt
Hello, (cc debian-edu to allow for comments/discussion/additions) On Fri, May 07, 2010 at 12:41:26PM +0200, Benoit Mortier wrote: > Le Friday 07 May 2010 12:03:00 Andreas B. Mundt, vous avez écrit : > > On Wed, May 05, 2010 at 02:08:00PM +0200, Cajus Pollmeier wrote: > > >

the three-headed dog at the doorstep...

2010-05-05 Thread Andreas B. Mundt
Hi all, after some successful tests I have been thinking about how to proceed with the implementation of kerberos. The changes to our sources might not be too small and the whole setup is probably influenced (in a positive way). Here are some ideas and thoughts that are puzzling me: Can we get

MIT-kerberos versus Heimdal

2010-05-03 Thread Andreas B. Mundt
Hi, the last days I spent some time on kerberos implementations namely MIT-kerberos and Heimdal. I set up a KDC on tjener using our LDAP as database. This is a short summery of my experiences, if you have additional input please comment. To connect the KDC to the LDAP database various possibili

which Kerberos implementation?

2010-05-01 Thread Andreas B. Mundt
On Sat, Apr 24, 2010 at 09:52:49PM +0200, Petter Reinholdtsen wrote: > [Petter Reinholdtsen] > Not sure which Kerberos implementation we should use. Reading > http://grep.be/blog/en/lazyweb/re_kerberos_ldap > make me > suspect Heimdal Kerberos might be a better choice than MIT Kerberos, > as it ha

Re: Kerberos for Debian Edu/Squeeze?

2010-04-28 Thread Andreas B. Mundt
On Sat, Apr 24, 2010 at 09:52:49PM +0200, Petter Reinholdtsen wrote: > [Petter Reinholdtsen] > > Posted here with his approval. Anyone with opinions on which > > Kerberos implementation we should use? > > I just commited > debian-edu-config/share/debian-edu-config/tools/kerberos-kdc-init, > which

Bug#572769: summary of work done so far

2010-04-15 Thread Andreas B. Mundt
Hi, just a short update what has been achieved so far (also concerning debian-edu-artwork in general): Done: - grub2 wallpaper has been added. - gdm and kdm have now almost identical theme definitions and use the same artwork, buttons and notifications work. - a ksplash theme has been added,

Bug#572769: progress under way

2010-04-12 Thread Andreas B. Mundt
Hi, some progress is under way to fix this issue: I commited changes to the repository resulting in a refurbished kdm greeter with working menus. I currently try to unify and clean the gdm and kdm xml-definition. Up to the items defining the entries (kdm has user-entry and pw-entry, gdm a combin

Re: new kdm/desktop wallpaper?

2010-04-07 Thread Andreas B. Mundt
On Tue, Apr 06, 2010 at 01:36:59PM +0200, Petter Reinholdtsen wrote: > [Andreas B. Mundt] > > I wanted to keep the tux-behind-his-desk picture used in lenny-edu, > > but could not find any "sources". So if you know where to obtain > > those, please let me know. >

Re: delay +edu1 by a week?

2010-03-24 Thread Andreas B. Mundt
Hi Holger, On Wed, Mar 24, 2010 at 01:52:22PM +0100, Holger Levsen wrote: > I'd like to delay +edu1 by a week or maybe even two, resulting in an RC3 as > well. For three simple reasons: > > a.) to be able to update the documentation some more > b.) to be able to fix #1450 > c.) I don't really h

Re: lwat improvements

2010-03-24 Thread Andreas B. Mundt
Hi John, On Fri, Mar 19, 2010 at 10:45:21AM +0100, John S. Skogtvedt wrote: > I haven't yet run podebconf-report-po, as I'm not 100% sure how > translation updates should be handled in lwat. I've sent an email to > Finn-Arne (the original author) to ask about it. > As for making a 0.18 release, th

Re: debian-edu-install.dat.local does not work on tjener.

2010-03-23 Thread Andreas B. Mundt
On Tue, Mar 23, 2010 at 08:30:27PM +0100, Andreas Schockenhoff wrote: > Dear Developer, > > >From the manual: > http://wiki.debian.org/DebianEdu/Documentation/Lenny/HowTo/Administration#ConfiguringthePXEmenu > > To avoid these questions the > file /etc/debian-edu/www/debian-edu-install.dat.local

Impressions from the "Chemnitzer Linux-Tage"

2010-03-19 Thread Andreas B. Mundt
Hi all, although almost a week has passed by since last weekend, I still want to share my personal impressions from presenting DebianEdu/Skolelinux at the "Chemnitzer Linux-Tage" ( http://chemnitzer.linux-tage.de ). We had a nice booth and many visitors from a broad spectrum: admins, teachers, st

Re: lwat improvements

2010-03-19 Thread Andreas B. Mundt
On Fri, Mar 19, 2010 at 10:45:21AM +0100, John S. Skogtvedt wrote: > I made one change to the text in your patch, so any new translations > based on those po files will have one fuzzy. > > I haven't yet run podebconf-report-po, as I'm not 100% sure how > translation updates should be handled in lw

Re: GUI to ldap administration

2010-03-19 Thread Andreas B. Mundt
Hi Winnie, On Thu, Mar 18, 2010 at 02:02:08PM +0100, Patrick Winnertz wrote: > Hey, > [...] > Yes, that's basically correct. My last upload was in 2008, however a new > upload to unstable is planned this month to update it to a more recent > version. > > As lwat is a nice approach for administ

Re: lwat improvements

2010-03-19 Thread Andreas B. Mundt
On Thu, Mar 18, 2010 at 12:07:31PM +0100, John S. Skogtvedt wrote: > Petter Reinholdtsen skrev: [...] > > I believe it is vital to accept a two step approach when dealing with > > translations. First one changes the original texts, next one ask for > > updated translations and integrate them when

lwat improvements

2010-03-17 Thread Andreas B. Mundt
Dear John, we currently investigate improvements and bugs in DebianEdu/skolelinux and try to get a working squeeze candidate before Debian freezes it's package-repository. I have seen from the lwat changelog that you prepared the latests modifications to the source code and would like to ask if

Re: GUI to ldap administration

2010-03-16 Thread Andreas B. Mundt
3-16 15:36:41.0 +0100 @@ -1,3 +1,12 @@ +lwat (0.17-4.1) unstable; urgency=low + + * Non-maintainer upload. + * Fix string in po/de_DE.po (Closes: #520136) + * Fix share/mailnewuser (Closes: #568407) + * Fix typo in templates/login.tpl + + -- Andreas B. Mundt Tue, 16 Mar 2010

Re: Debian Edu + Skolelinux: 2 names, 2 distros, 1 project

2010-03-15 Thread Andreas B. Mundt
On Sat, Mar 13, 2010 at 01:52:18PM +0100, Holger Levsen wrote: > Currently we struggle with both the problem of having two names for one > project and with the problem of finding the right balance between freenees > and usefulness in our release. > > So I had the idea to actually release two di

GUI to ldap administration

2010-03-08 Thread Andreas B. Mundt
Dear all, with the release of Debian Edu lenny 5.0.4+edu0 and the forthcoming release of Debian Edu lenny 5.0.4+edu1 development of Debian Edu Squeeze is brought more and more into focus. I would like to mention and stress the importance of a graphical user interface to ldap as essential and very

Bug#570773: /etc/ldap/ssl/ldap-server-pubkey.pem missing

2010-02-26 Thread Andreas B. Mundt
Hi, some observations, probably more or less known, just as a reminder for further tests (and for myself :)): After the installation of a combined squeeze tjener/terminalserver (as known automatic partitions are too small, I therefore used a single one), I explored the following: nslcd.conf h

Bug#564915: another minor fix/improvement

2010-02-16 Thread Andreas B. Mundt
Hi Holger, here is another small improvement (not worth to file a new bug but I do not want to commit it without discuss it first). It's really simple, the attached patch says it all: The Makefile contains a variable to be updated with every point release, it is currently wrong and defines the ti

Bug#564915: final patch

2010-02-14 Thread Andreas B. Mundt
Hi Holger, here is now the final patch, I it think can be comitted. I removed some redundancy and added a few comments. The "*-manual.xml" file is the same as with the older patch. I cheched the pdf, anything seems to be ok (and the extra spaces are gone :-) ). Regards, Andi PS: Do n

Bug#564915: more research

2010-02-13 Thread Andreas B. Mundt
Hi Holger, On Fri, Feb 12, 2010 at 03:39:58PM +0100, Holger Levsen wrote: > I've tried it now and noticed the following issue with the rosegarden manual: > > rosegarden-manual.xml:1328: parser error : Opening and ending tag mismatch: > article line 1 and para > > ^ > rosegarden

Bug#564915: more research

2010-02-11 Thread Andreas B. Mundt
On Thu, Feb 11, 2010 at 05:56:08PM +0100, Holger Levsen wrote: > will reply to some of your questions in the previous mail as well as attach > the patch at another time, am busy with other stuff atm... just a quick > comment: no problem :) > Great results. Just what I dont understand is the spa

<    1   2   3   >