Re: authselect: what to do with systemd and nss-mdns that modify nsswith.conf

2019-01-04 Thread Pavel Březina
On 12/6/18 12:20 PM, Pavel Březina wrote: Hello, systemd and nss-mdns packages modifies nsswitch.conf in their %post scriptlets which creates conflicts with authselect on systems that are configured by authselect. This needs to be solved somehow. Originally, I wanted to create an authselect

Re: authselect: what to do with systemd and nss-mdns that modify nsswith.conf

2018-12-12 Thread Lennart Poettering
On Mi, 12.12.18 10:10, Simo Sorce (s...@redhat.com) wrote: > Acceptance is also not a problem, the point is integrating when and > where it makes sense on Fedora. Well, systemd is not a Fedora-only project. It's in fact an excercise in unification across distros, and hence interfacing with upper

Re: authselect: what to do with systemd and nss-mdns that modify nsswith.conf

2018-12-12 Thread Simo Sorce
On Thu, 2018-12-06 at 17:49 +0100, Lennart Poettering wrote: > On Do, 06.12.18 11:25, Simo Sorce (s...@redhat.com) wrote: > > > > > Summary: I'd make things simple, and enable all four unconditionally > > > > and by default without any dynamic infrastructure, without postinst > > > > scripts or

Re: authselect: what to do with systemd and nss-mdns that modify nsswith.conf

2018-12-07 Thread Zbigniew Jędrzejewski-Szmek
On Fri, Dec 07, 2018 at 06:58:31PM +0100, Dominik 'Rathann' Mierzejewski wrote: > On Friday, 07 December 2018 at 16:46, Tomasz Torcz wrote: > > On Fri, Dec 07, 2018 at 01:11:00PM +0100, Dominik 'Rathann' Mierzejewski > > wrote: > > > On Thursday, 06 December 2018 at 15:10, Florian Weimer wrote: >

Re: authselect: what to do with systemd and nss-mdns that modify nsswith.conf

2018-12-07 Thread Dominik 'Rathann' Mierzejewski
On Friday, 07 December 2018 at 16:46, Tomasz Torcz wrote: > On Fri, Dec 07, 2018 at 01:11:00PM +0100, Dominik 'Rathann' Mierzejewski > wrote: > > On Thursday, 06 December 2018 at 15:10, Florian Weimer wrote: > > [...] > > > The way myhostname is currently implemented, it is rather problematic. >

Re: authselect: what to do with systemd and nss-mdns that modify nsswith.conf

2018-12-07 Thread Tomasz Torcz
On Fri, Dec 07, 2018 at 01:11:00PM +0100, Dominik 'Rathann' Mierzejewski wrote: > On Thursday, 06 December 2018 at 15:10, Florian Weimer wrote: > [...] > > The way myhostname is currently implemented, it is rather problematic. > > I think it has largely stopped stomping over the DNS namespace

Re: authselect: what to do with systemd and nss-mdns that modify nsswith.conf

2018-12-07 Thread Zbigniew Jędrzejewski-Szmek
On Fri, Dec 07, 2018 at 01:11:00PM +0100, Dominik 'Rathann' Mierzejewski wrote: > On Thursday, 06 December 2018 at 15:10, Florian Weimer wrote: > [...] > > The way myhostname is currently implemented, it is rather problematic. > > I think it has largely stopped stomping over the DNS namespace

Re: authselect: what to do with systemd and nss-mdns that modify nsswith.conf

2018-12-07 Thread Dominik 'Rathann' Mierzejewski
On Thursday, 06 December 2018 at 15:10, Florian Weimer wrote: [...] > The way myhostname is currently implemented, it is rather problematic. > I think it has largely stopped stomping over the DNS namespace (with the > _gateway change), so it could be moved to the front, eliminating all > those

Re: authselect: what to do with systemd and nss-mdns that modify nsswith.conf

2018-12-07 Thread Pavel Březina
On 12/6/18 3:27 PM, Tom Hughes wrote: On 06/12/2018 14:11, Florian Weimer wrote: * Tom Hughes: Based on my experimentation with an F29 live image last week both nss-systemd and nss-myhostname are in the default configuration. Not in the file shipped by the glibc package. Well something

Re: authselect: what to do with systemd and nss-mdns that modify nsswith.conf

2018-12-06 Thread Lennart Poettering
On Do, 06.12.18 19:42, Florian Weimer (fwei...@redhat.com) wrote: > >> Reading https://bugzilla.redhat.com/show_bug.cgi?id=1284325 there is can > >> happen some ID overlaps with FreeIPA/Samba which is undesirable. I would > >> say > >> that this must be solves if this module is enabled by

Re: authselect: what to do with systemd and nss-mdns that modify nsswith.conf

2018-12-06 Thread Florian Weimer
* Lennart Poettering: > On Do, 06.12.18 14:58, Pavel Březina (pbrez...@redhat.com) wrote: > >> > Then there is nss-mymachines. It's primarily useful if >> > systemd-machined or systemd-nspawn is used. Given that those are now >> > part of the 'systemd-container' RPM it would be OK to also add >>

Re: authselect: what to do with systemd and nss-mdns that modify nsswith.conf

2018-12-06 Thread Lennart Poettering
On Do, 06.12.18 16:34, Zbigniew Jędrzejewski-Szmek (zbys...@in.waw.pl) wrote: > > I wonder if we should think of a tighter system integration and subsume > > the tasks of nss_machines into SSSD. > > It would allow for detection and logging of UID conflicts should they > > happen in a live system

Re: authselect: what to do with systemd and nss-mdns that modify nsswith.conf

2018-12-06 Thread Lennart Poettering
On Do, 06.12.18 11:25, Simo Sorce (s...@redhat.com) wrote: > > > Summary: I'd make things simple, and enable all four unconditionally > > > and by default without any dynamic infrastructure, without postinst > > > scripts or anything. If that's not acceptable, then at least two of the > > > four

Re: authselect: what to do with systemd and nss-mdns that modify nsswith.conf

2018-12-06 Thread Zbigniew Jędrzejewski-Szmek
On Thu, Dec 06, 2018 at 11:25:04AM -0500, Simo Sorce wrote: > On Thu, 2018-12-06 at 16:00 +, Zbigniew Jędrzejewski-Szmek wrote: > > On Thu, Dec 06, 2018 at 02:36:36PM +0100, Lennart Poettering wrote: > > > On Do, 06.12.18 12:20, Pavel Březina (pbrez...@redhat.com) wrote: > > > > > > > Hello,

Re: authselect: what to do with systemd and nss-mdns that modify nsswith.conf

2018-12-06 Thread Simo Sorce
On Thu, 2018-12-06 at 16:00 +, Zbigniew Jędrzejewski-Szmek wrote: > On Thu, Dec 06, 2018 at 02:36:36PM +0100, Lennart Poettering wrote: > > On Do, 06.12.18 12:20, Pavel Březina (pbrez...@redhat.com) wrote: > > > > > Hello, > > > > Heya! > > > > > systemd and nss-mdns packages modifies

Re: authselect: what to do with systemd and nss-mdns that modify nsswith.conf

2018-12-06 Thread Zbigniew Jędrzejewski-Szmek
On Thu, Dec 06, 2018 at 02:36:36PM +0100, Lennart Poettering wrote: > On Do, 06.12.18 12:20, Pavel Březina (pbrez...@redhat.com) wrote: > > > Hello, > > Heya! > > > systemd and nss-mdns packages modifies nsswitch.conf in their %post > > scriptlets which creates conflicts with authselect on

Re: authselect: what to do with systemd and nss-mdns that modify nsswith.conf

2018-12-06 Thread Lennart Poettering
On Do, 06.12.18 14:58, Pavel Březina (pbrez...@redhat.com) wrote: > > Then there is nss-mymachines. It's primarily useful if > > systemd-machined or systemd-nspawn is used. Given that those are now > > part of the 'systemd-container' RPM it would be OK to also add > > nss-mymachines to

Re: authselect: what to do with systemd and nss-mdns that modify nsswith.conf

2018-12-06 Thread Tom Hughes
On 06/12/2018 14:11, Florian Weimer wrote: * Tom Hughes: Based on my experimentation with an F29 live image last week both nss-systemd and nss-myhostname are in the default configuration. Not in the file shipped by the glibc package. Well something that has been installed as part of the

Re: authselect: what to do with systemd and nss-mdns that modify nsswith.conf

2018-12-06 Thread Florian Weimer
* Tom Hughes: > Based on my experimentation with an F29 live image last week both > nss-systemd and nss-myhostname are in the default configuration. Not in the file shipped by the glibc package. Florian ___ devel mailing list --

Re: authselect: what to do with systemd and nss-mdns that modify nsswith.conf

2018-12-06 Thread Florian Weimer
* Lennart Poettering: > nss-myhostname should be in nsswitch.conf by default too. It's very > minimal, and just makes sure the local hostname remains resolvable all > the time. By enabling this, installers and image generators don't have > to patch /etc/hosts anymore like they traditionally did,

Re: authselect: what to do with systemd and nss-mdns that modify nsswith.conf

2018-12-06 Thread Pavel Březina
On 12/6/18 2:36 PM, Lennart Poettering wrote: On Do, 06.12.18 12:20, Pavel Březina (pbrez...@redhat.com) wrote: Hello, Heya! systemd and nss-mdns packages modifies nsswitch.conf in their %post scriptlets which creates conflicts with authselect on systems that are configured by authselect.

Re: authselect: what to do with systemd and nss-mdns that modify nsswith.conf

2018-12-06 Thread Pavel Březina
On 12/6/18 1:31 PM, Florian Weimer wrote: * Pavel Březina: systemd and nss-mdns packages modifies nsswitch.conf in their %post scriptlets which creates conflicts with authselect on systems that are configured by authselect. This needs to be solved somehow. Other packagers (notably sssd) have

Re: authselect: what to do with systemd and nss-mdns that modify nsswith.conf

2018-12-06 Thread Tom Hughes
On 06/12/2018 13:36, Lennart Poettering wrote: nss-systemd should be in nsswitch.conf by default. It's required for systemd's DynamicUser=1 option to work correctly, and that's core service functionality. Hence, given that systemd is Fedora's PID 1, nss-systemd should also be in nsswitch.conf

Re: authselect: what to do with systemd and nss-mdns that modify nsswith.conf

2018-12-06 Thread Lennart Poettering
On Do, 06.12.18 12:20, Pavel Březina (pbrez...@redhat.com) wrote: > Hello, Heya! > systemd and nss-mdns packages modifies nsswitch.conf in their %post > scriptlets which creates conflicts with authselect on systems that are > configured by authselect. This needs to be solved somehow. > >

Re: authselect: what to do with systemd and nss-mdns that modify nsswith.conf

2018-12-06 Thread Florian Weimer
* Pavel Březina: > systemd and nss-mdns packages modifies nsswitch.conf in their %post > scriptlets which creates conflicts with authselect on systems that are > configured by authselect. This needs to be solved somehow. Other packagers (notably sssd) have made the required changes by requesting

authselect: what to do with systemd and nss-mdns that modify nsswith.conf

2018-12-06 Thread Pavel Březina
Hello, systemd and nss-mdns packages modifies nsswitch.conf in their %post scriptlets which creates conflicts with authselect on systems that are configured by authselect. This needs to be solved somehow. Originally, I wanted to create an authselect command that can be used by packages on