Re: [Freeipa-devel] [PATCH] 320 Only use service PAC type as an override

2012-10-03 Thread Martin Kosek
On 10/02/2012 10:31 PM, Rob Crittenden wrote: Martin Kosek wrote: PAC type (ipakrbauthzdata attribute) was being filled for all new service automatically. However, the PAC type attribute was designed to serve only as an override to default PAC type configured in IPA config. With PAC type set

Re: [Freeipa-devel] [PATCH 0015] Restrict admins group modifications

2012-10-03 Thread Martin Kosek
On 10/02/2012 02:33 PM, Tomas Babej wrote: On 09/26/2012 05:44 PM, Martin Kosek wrote: On 09/25/2012 02:59 PM, Tomas Babej wrote: On 09/25/2012 02:31 PM, Martin Kosek wrote: On 09/25/2012 02:22 PM, Tomas Babej wrote: Hi, Group-mod command no longer allows --rename and/or --external changes

Re: [Freeipa-devel] [PATCH 0014] Improve user addition to default group in host-add

2012-10-03 Thread Martin Kosek
On 10/01/2012 03:38 PM, Tomas Babej wrote: On 09/26/2012 04:12 PM, Martin Kosek wrote: On 09/26/2012 03:23 PM, Tomas Babej wrote: On 09/25/2012 12:37 PM, Tomas Babej wrote: Hi, On adding new user, host-add tries to make it a member of default user group. This, however, can raise

Re: [Freeipa-devel] [PATCHES] 3 enhancements for the ipa-adtrust-install page

2012-10-03 Thread Martin Kosek
On 10/02/2012 09:54 AM, Sumit Bose wrote: Hi, the following three patches should fix https://fedorahosted.org/freeipa/ticket/2967 https://fedorahosted.org/freeipa/ticket/2972 https://fedorahosted.org/freeipa/ticket/3038 respectively. bye, Sumit 3x ACK. Pushed all three to master,

[Freeipa-devel] [PATCH] 79 Add SIDs for existing users and groups at the end of ipa-adtrust-install

2012-10-03 Thread Sumit Bose
Hi, this patch adds a new option to ipa-adtrust-install to generate the SID for users and groups at the end of the run. This fixes https://fedorahosted.org/freeipa/ticket/3104 . bye, Sumit From 64f5b76c1869dbbc5e63035baa13642b43854839 Mon Sep 17 00:00:00 2001 From: Sumit Bose sb...@redhat.com

Re: [Freeipa-devel] [PATCH 0015] Restrict admins group modifications

2012-10-03 Thread Tomas Babej
On 10/03/2012 09:18 AM, Martin Kosek wrote: On 10/02/2012 02:33 PM, Tomas Babej wrote: On 09/26/2012 05:44 PM, Martin Kosek wrote: On 09/25/2012 02:59 PM, Tomas Babej wrote: On 09/25/2012 02:31 PM, Martin Kosek wrote: On 09/25/2012 02:22 PM, Tomas Babej wrote: Hi, Group-mod command no

Re: [Freeipa-devel] [PATCH 0015] Restrict admins group modifications

2012-10-03 Thread Martin Kosek
On 10/03/2012 11:49 AM, Tomas Babej wrote: On 10/03/2012 09:18 AM, Martin Kosek wrote: On 10/02/2012 02:33 PM, Tomas Babej wrote: On 09/26/2012 05:44 PM, Martin Kosek wrote: On 09/25/2012 02:59 PM, Tomas Babej wrote: On 09/25/2012 02:31 PM, Martin Kosek wrote: On 09/25/2012 02:22 PM, Tomas

Re: [Freeipa-devel] [PATCH] 1058 clear session key

2012-10-03 Thread Martin Kosek
On 10/02/2012 08:23 PM, Rob Crittenden wrote: Clear the host session key when enrolling a client. Make sure dbdir is preserved when a new connection is created. rob I tested repeatedly installing, uninstalling client and unlike previously, I did not receive any NSS initialization error.

Re: [Freeipa-devel] [PATCH] 319 Make ipakrbprincipal objectclass optional

2012-10-03 Thread Rob Crittenden
Martin Kosek wrote: On 10/02/2012 03:04 PM, Martin Kosek wrote: On 10/02/2012 12:19 PM, Petr Viktorin wrote: On 10/01/2012 05:28 PM, Martin Kosek wrote: From IPA 3.0, services have by default ipakrbprincipal objectclass which allows ipakrbprincipalalias attribute used for case-insensitive

Re: [Freeipa-devel] [PATCH] 319 Make ipakrbprincipal objectclass optional

2012-10-03 Thread Petr Viktorin
On 10/02/2012 05:46 PM, Martin Kosek wrote: On 10/02/2012 03:04 PM, Martin Kosek wrote: On 10/02/2012 12:19 PM, Petr Viktorin wrote: On 10/01/2012 05:28 PM, Martin Kosek wrote: From IPA 3.0, services have by default ipakrbprincipal objectclass which allows ipakrbprincipalalias attribute

Re: [Freeipa-devel] [PATCH 0016] Adds port to connection error message in ipa-client-install

2012-10-03 Thread Tomas Babej
On 10/02/2012 08:48 PM, Rob Crittenden wrote: Tomas Babej wrote: On 09/26/2012 09:32 PM, Rob Crittenden wrote: Tomas Babej wrote: Hi, Connection error message in ipa-client-install now warns the user about the need of opening 389 port for directory server.

Re: [Freeipa-devel] [PATCH] [WIP] Firefox extension

2012-10-03 Thread Petr Vobornik
As Alexander proposed in other channel. I will remove the removal of configure.jar and offer the old configuration method if user is using FF 4 so we don't have to make the extension compatible with this ancient version. It will be done this way: If FF 4 is detected: * in

Re: [Freeipa-devel] [PATCH 0016] Adds port to connection error message in ipa-client-install

2012-10-03 Thread Tomas Babej
On 10/03/2012 03:31 PM, Tomas Babej wrote: On 10/02/2012 08:48 PM, Rob Crittenden wrote: Tomas Babej wrote: On 09/26/2012 09:32 PM, Rob Crittenden wrote: Tomas Babej wrote: Hi, Connection error message in ipa-client-install now warns the user about the need of opening 389 port for directory

Re: [Freeipa-devel] [PATCH] [WIP] Firefox extension

2012-10-03 Thread Simo Sorce
On Wed, 2012-10-03 at 15:50 +0200, Petr Vobornik wrote: As Alexander proposed in other channel. I will remove the removal of configure.jar and offer the old configuration method if user is using FF 4 so we don't have to make the extension compatible with this ancient version. It will be

Re: [Freeipa-devel] [PATCH] [WIP] Firefox extension

2012-10-03 Thread Dmitri Pal
On 10/03/2012 10:19 AM, Simo Sorce wrote: On Wed, 2012-10-03 at 15:50 +0200, Petr Vobornik wrote: As Alexander proposed in other channel. I will remove the removal of configure.jar and offer the old configuration method if user is using FF 4 so we don't have to make the extension compatible

Re: [Freeipa-devel] [PATCH] 0084 Wait for secure Dogtag ports when starting the pki services

2012-10-03 Thread Martin Kosek
On 09/25/2012 04:38 PM, Petr Viktorin wrote: Dogtag opens not only the insecure port (8080 or 9180, for d10 or d9 respectively), but also secure ports (8443 or 94439444). Wait for them when starting. Part of the fix for https://fedorahosted.org/freeipa/ticket/3084. I found that if we

Re: [Freeipa-devel] [PATCH] 1058 clear session key

2012-10-03 Thread Rob Crittenden
Martin Kosek wrote: On 10/02/2012 08:23 PM, Rob Crittenden wrote: Clear the host session key when enrolling a client. Make sure dbdir is preserved when a new connection is created. rob I tested repeatedly installing, uninstalling client and unlike previously, I did not receive any NSS

Re: [Freeipa-devel] [PATCH] 1058 clear session key

2012-10-03 Thread Martin Kosek
- Original Message - From: Rob Crittenden rcrit...@redhat.com To: Martin Kosek mko...@redhat.com Cc: freeipa-devel freeipa-devel@redhat.com Sent: Wednesday, October 3, 2012 5:49:52 PM Subject: Re: [Freeipa-devel] [PATCH] 1058 clear session key Martin Kosek wrote: On 10/02/2012

Re: [Freeipa-devel] [PATCH 0016] Adds port to connection error message in ipa-client-install

2012-10-03 Thread Rob Crittenden
Tomas Babej wrote: On 10/03/2012 03:31 PM, Tomas Babej wrote: On 10/02/2012 08:48 PM, Rob Crittenden wrote: Tomas Babej wrote: On 09/26/2012 09:32 PM, Rob Crittenden wrote: Tomas Babej wrote: Hi, Connection error message in ipa-client-install now warns the user about the need of opening

Re: [Freeipa-devel] New Kerberos-related bugzillas

2012-10-03 Thread Steve Dickson
Hello, These issues were found at this Fall's Bake-a-ton... On 03/10/12 13:02, Chuck Lever wrote: Free IPA does not support weak crypto https://bugzilla.linux-nfs.org/show_bug.cgi?id=229 Confusing debugging output when configuring NFS over Kerberos

Re: [Freeipa-devel] New Kerberos-related bugzillas

2012-10-03 Thread Rob Crittenden
Steve Dickson wrote: Hello, These issues were found at this Fall's Bake-a-ton... On 03/10/12 13:02, Chuck Lever wrote: Free IPA does not support weak crypto https://bugzilla.linux-nfs.org/show_bug.cgi?id=229 Documented in step 6 at

Re: [Freeipa-devel] New Kerberos-related bugzillas

2012-10-03 Thread Simo Sorce
On Wed, 2012-10-03 at 13:26 -0400, Steve Dickson wrote: Hello, These issues were found at this Fall's Bake-a-ton... On 03/10/12 13:02, Chuck Lever wrote: Free IPA does not support weak crypto https://bugzilla.linux-nfs.org/show_bug.cgi?id=229 DES support is disabled on purpose,

Re: [Freeipa-devel] New Kerberos-related bugzillas

2012-10-03 Thread Simo Sorce
On Wed, 2012-10-03 at 11:03 -0700, Chuck Lever wrote: On Oct 3, 2012, at 10:49 AM, Simo Sorce wrote: On Wed, 2012-10-03 at 13:26 -0400, Steve Dickson wrote: Hello, These issues were found at this Fall's Bake-a-ton... On 03/10/12 13:02, Chuck Lever wrote: Free IPA does not

Re: [Freeipa-devel] New Kerberos-related bugzillas

2012-10-03 Thread Chuck Lever
On Oct 3, 2012, at 10:49 AM, Simo Sorce wrote: On Wed, 2012-10-03 at 13:26 -0400, Steve Dickson wrote: Hello, These issues were found at this Fall's Bake-a-ton... On 03/10/12 13:02, Chuck Lever wrote: Free IPA does not support weak crypto