Re: What does 141 mean?

2018-09-20 Thread Jakub Hrozek
> On 20 Sep 2018, at 06:47, Alexander Bokovoy wrote: > > On ke, 19 syys 2018, Björn Persson wrote: >> Alexander Bokovoy wrote: >>> Can you provide output from >>> >>> export KRB5_TRACE=/dev/stderr >>> klist -A >>> kinit >>> fedpkg build >>> >>> ? >> >> The log is attached. I tried it twice a

Re: systemd 238 and sysusers

2018-03-07 Thread Jakub Hrozek
> On 7 Mar 2018, at 15:53, Stephen Gallagher wrote: > > > > On Wed, Mar 7, 2018 at 9:50 AM Simo Sorce wrote: > On Wed, 2018-03-07 at 14:24 +, Zbigniew Jędrzejewski-Szmek wrote: > > On Wed, Mar 07, 2018 at 02:00:03PM +0100, Florian Weimer wrote: > > > On 03/07/2018 01:55 PM, Stephen Galla

Re: F27 Self Contained Change: Authselect: new tool to replace authconfig

2017-07-18 Thread Jakub Hrozek
On Tue, Jul 18, 2017 at 08:30:57PM +0100, Tom Hughes wrote: > On 18/07/17 15:26, Stephen Gallagher wrote: > > > On Tue, Jul 18, 2017 at 10:17 AM Tom Hughes > > wrote: > > > > Well none of my newly upgraded F26 machines appear to be running it ;-) > > > > I said "defa

Re: F27 System Wide Change: Kerberos KCM credential cache by default

2017-06-21 Thread Jakub Hrozek
On Wed, Jun 21, 2017 at 09:01:04AM +0200, Pavel Cahyna wrote: > On Tue, Jun 20, 2017 at 08:45:48PM +0200, Jakub Hrozek wrote: > > Well, UID of the peer accessing the socket is the access control key right > > now. Unlike Heimdal's KCM, root doesn't have any special power

Re: F27 System Wide Change: Kerberos KCM credential cache by default

2017-06-20 Thread Jakub Hrozek
On Wed, Jun 21, 2017 at 08:23:10AM +0200, Jakub Hrozek wrote: > On Tue, Jun 20, 2017 at 04:23:30PM -0400, Daniel Walsh wrote: > > On 06/20/2017 02:45 PM, Jakub Hrozek wrote: > > > On Tue, Jun 20, 2017 at 08:55:49AM -0400, Daniel Walsh wrote: > > > > On 06/20/201

Re: F27 System Wide Change: Kerberos KCM credential cache by default

2017-06-20 Thread Jakub Hrozek
On Tue, Jun 20, 2017 at 04:23:30PM -0400, Daniel Walsh wrote: > On 06/20/2017 02:45 PM, Jakub Hrozek wrote: > > On Tue, Jun 20, 2017 at 08:55:49AM -0400, Daniel Walsh wrote: > > > On 06/20/2017 04:21 AM, Jakub Hrozek wrote: > > > > On Tue, Jun 20, 2017 at 09:25:

Re: F27 System Wide Change: Kerberos KCM credential cache by default

2017-06-20 Thread Jakub Hrozek
On Tue, Jun 20, 2017 at 08:55:49AM -0400, Daniel Walsh wrote: > On 06/20/2017 04:21 AM, Jakub Hrozek wrote: > > On Tue, Jun 20, 2017 at 09:25:49AM +0200, Pavel Cahyna wrote: > > > Hi, > > > > > > On Tue, Jun 20, 2017 at 07:42:27AM +0200, Jan Kurik wrote: > &

Re: F27 System Wide Change: Kerberos KCM credential cache by default

2017-06-20 Thread Jakub Hrozek
links when I re-submitted the feature..) The correct link is: https://docs.pagure.org/SSSD.sssd/design_pages/kcm.html > > > Change owner(s): > > * Jakub Hrozek > > > > Default to a new Kerberos credential cache type called KCM which is > > better suited for cont

Re: Wild changes in nsswitch.conf

2017-05-18 Thread Jakub Hrozek
On Tue, May 16, 2017 at 08:20:49AM -0400, Stephen Gallagher wrote: > On 05/16/2017 07:04 AM, Nico Kadel-Garcia wrote: > > On Mon, May 15, 2017 at 11:37 AM, Stephen Gallagher > > wrote: > >> > >> > >> On 05/15/2017 11:30 AM, Jakub Hrozek wrote: >

Re: Wild changes in nsswitch.conf

2017-05-15 Thread Jakub Hrozek
On Mon, May 15, 2017 at 05:57:50PM +0200, Tomasz Kłoczko wrote: > On 15 May 2017 at 17:35, Stephen Gallagher wrote: > > Tomasz, your tone is needlessly hostile. If you have a question, ask it. If > > you want to make a suggestion, make it. But casting aspersions on people > > doing work is unacc

Re: Wild changes in nsswitch.conf

2017-05-15 Thread Jakub Hrozek
On Mon, May 15, 2017 at 05:22:14PM +0200, Tomas Mraz wrote: > On Mon, 2017-05-15 at 17:15 +0200, Jakub Hrozek wrote: > > On Mon, May 15, 2017 at 04:35:56PM +0200, Tomas Mraz wrote: > > > My current Fedora 26 default nsswitch.conf contains these lines: > > > > >

Re: Wild changes in nsswitch.conf

2017-05-15 Thread Jakub Hrozek
On Mon, May 15, 2017 at 04:35:56PM +0200, Tomas Mraz wrote: > My current Fedora 26 default nsswitch.conf contains these lines: > > passwd:  sss files systemd > shadow: files sss > group:   sss files systemd > > Not sure which package created this configuration, but: > > * Where is t

Re: F26 System Wide Change: Kerberos KCM credential cache by default

2017-01-31 Thread Jakub Hrozek
On Tue, Jan 31, 2017 at 09:47:05AM -0600, Rex Dieter wrote: > Jakub Hrozek wrote: > > > On Tue, Jan 31, 2017 at 07:04:33AM -0600, Rex Dieter wrote: > >> Jan Kurik wrote: > >> > >> > F26 System Wide Change: Kerberos KCM credential cache by default >

Re: F26 System Wide Change: Kerberos KCM credential cache by default

2017-01-31 Thread Jakub Hrozek
On Tue, Jan 31, 2017 at 02:49:41PM +0100, Florian Weimer wrote: > On 01/31/2017 02:38 PM, Jakub Hrozek wrote: > > On Tue, Jan 31, 2017 at 02:36:12PM +0100, Florian Weimer wrote: > > > On 01/31/2017 10:36 AM, David Woodhouse wrote: > > > > Please ensure this wor

Re: F26 System Wide Change: Kerberos KCM credential cache by default

2017-01-31 Thread Jakub Hrozek
On Tue, Jan 31, 2017 at 02:36:12PM +0100, Florian Weimer wrote: > On 01/31/2017 10:36 AM, David Woodhouse wrote: > > Please ensure this works with winbind. The switch to KEYRING: by > > default didn't — pam_winbind was putting creds in /tmp/krb5cc_$UID > > still, and then they weren't consistently

Re: F26 System Wide Change: Kerberos KCM credential cache by default

2017-01-31 Thread Jakub Hrozek
On Tue, Jan 31, 2017 at 07:04:33AM -0600, Rex Dieter wrote: > Jan Kurik wrote: > > > F26 System Wide Change: Kerberos KCM credential cache by default > > Hi, can you please consider changing the name of this change/feature to not > use "KCM". That's an acronym commonly used in kde/plasma for KD

Re: F26 System Wide Change: Kerberos KCM credential cache by default

2017-01-31 Thread Jakub Hrozek
On Tue, Jan 31, 2017 at 09:36:59AM +, David Woodhouse wrote: > On Tue, 2017-01-31 at 10:24 +0100, Jan Kurik wrote: > > = System Wide Change: Kerberos KCM credential cache by default = > > https://fedoraproject.org/wiki/Changes/KerberosKCMCache > > > > Change o

Re: F26 System Wide Change: Kerberos KCM credential cache by default

2017-01-31 Thread Jakub Hrozek
On Tue, Jan 31, 2017 at 10:57:33AM +0100, Mike Bonnet wrote: > > == Scope == > > * Proposal owners: > > SSSD developers will implement a KCM server. The krb5-libs package > > will then switch its default from KEYRING to KCM. The libkrb5 package > > will require the sssd-kcm subpackage and enable it

Re: F26 System Wide Change: Kerberos KCM credential cache by default

2017-01-31 Thread Jakub Hrozek
On Tue, Jan 31, 2017 at 09:55:41AM +, Tom Hughes wrote: > On 31/01/17 09:24, Jan Kurik wrote: > > > With KCM, the Kerberos caches are not stored in a "passive" store, but > > managed by a daemon. In this setup, the Kerberos library (typically > > used through an application, like for example,

Re: upcoming build and release developer flag day December 12 2016

2016-11-21 Thread Jakub Hrozek
t. > > > > > BTW it would be nice, if it works with SSSD somehow and I don't need to > > use kinit at all. > > > > > > That is being worked on. I've asked Jakub Hrozek to come talk about the > upcoming > SSSD KCM work (targeted for F26). > If you acqu

Re: New Fedora 22 Change proposal: systemd-sysusers

2014-07-10 Thread Jakub Hrozek
On Thu, Jul 10, 2014 at 12:44:29PM -0400, Simo Sorce wrote: > On Thu, 2014-07-10 at 17:18 +0200, Jakub Hrozek wrote: > > We /do/ plan on the syncing anyway, because some admins are > > still used to vipw their passwd databases and there are legacy scripts > > around, but sti

Re: New Fedora 22 Change proposal: systemd-sysusers

2014-07-10 Thread Jakub Hrozek
On Wed, Jul 09, 2014 at 10:30:27AM -0400, Miloslav Trmač wrote: > - Original Message - > > Hi, for Atomic I'd like to investigate the new systemd-sysusers, so I > > wrote up a Change: > > > > https://fedoraproject.org/wiki/Changes/SystemdSysusers > > A move to something more declarative m

Active Directory Integration test day coming up on Thursday, 2012-10-18

2012-10-16 Thread Jakub Hrozek
Hi, The Fedora Test day scheduled for Thursday, October 18th is focused on Active Directory integration, in particular the realmd project and to some extent the Active Directory provider of the SSSD. This test day should be of particular interest to admins who manage Linux boxes enrolled in an Ac

Intent to retire: nss_ldap

2012-06-07 Thread Jakub Hrozek
Hi, I would like to retire PADL's nss_ldap and pam_ldap from current Rawhide. SSSD has been the default in Fedora for quite a few releases with nss-pam-ldapd as another option for deployments that, for some reason, do not want to migrate to the SSSD. nss_ldap also seems to be abandoned upstream.

Re: Heads up: bumping libnl to v3 in rawhide/F17 soon

2011-12-08 Thread Jakub Hrozek
On Tue, Nov 08, 2011 at 02:13:09PM -0500, Stephen Gallagher wrote: > On Tue, 2011-11-08 at 12:52 -0600, Dan Williams wrote: > > It certainly has a different soname, so yeah, we can have a -compat > > package. But that would still mean a ton of stuff busted for rebuilds > > while packages get fixed