Re: [Freeipa-devel] [file ipa_cldap.c, line 148]: Failed to create socket

2013-05-28 Thread Alexander Bokovoy
On Tue, 28 May 2013, Nicholas MacKenzie wrote: Hello, I have seen this happen on multiple fresh installs now. Can anyone shed any light on it? I am unable to add a trust because of this, I assume. An smbclient lookup against the DC works. == # ipa trust-add --type=ad

Re: [Freeipa-devel] [file ipa_cldap.c, line 148]: Failed to create socket

2013-05-28 Thread Nicholas MacKenzie
You were spot on about that. I enabled IPv6 and now the CLDAP plugin installs fine. I am now faced with this... dcerpc: alter_resp - rpc fault: WERR_ACCESS_DENIED Failed to bind to uuid 12345778-1234-abcd-ef00-0123456789ab for 12345778-1234-abcd-ef00-0123456789ab@ncacn_ip_tcp:

Re: [Freeipa-devel] [file ipa_cldap.c, line 148]: Failed to create socket

2013-05-28 Thread Nicholas MacKenzie
Nevermind. I used the Administrator account and all is well. This is a lovely site. Added Active Directory trust for realm ad.dc.com Realm name: ad.dc.com Domain NetBIOS name: AD Domain Security Identifier:

Re: [Freeipa-devel] [file ipa_cldap.c, line 148]: Failed to create socket

2013-05-28 Thread Alexander Bokovoy
On Tue, 28 May 2013, Nicholas MacKenzie wrote: You were spot on about that. I enabled IPv6 and now the CLDAP plugin installs fine. I am now faced with this... dcerpc: alter_resp - rpc fault: WERR_ACCESS_DENIED Failed to bind to uuid 12345778-1234-abcd-ef00-0123456789ab for

Re: [Freeipa-devel] [Patchwork] command line client

2013-05-28 Thread Petr Spacek
On 27.5.2013 22:05, Simo Sorce wrote: On Mon, 2013-05-27 at 16:36 +0200, Petr Spacek wrote: On 27.5.2013 15:57, Simo Sorce wrote: On Mon, 2013-05-27 at 10:45 +0200, Petr Spacek wrote: Hello Simo, could you install/allow XMLRPC for our Patchwork, please? I found the CLI for Patchwork but it

Re: [Freeipa-devel] [PATCH 0155] Fix IPv6 handling in PTR record synchronization

2013-05-28 Thread Tomas Hozza
ACK The patch looks good and works as expected. Regards, Tomas Hozza - Original Message - Hello, Fix IPv6 handling in PTR record synchronization. https://fedorahosted.org/bind-dyndb-ldap/ticket/118 -- Petr^2 Spacek ___

Re: [Freeipa-devel] [Patchwork] command line client

2013-05-28 Thread Martin Kosek
On 05/28/2013 10:38 AM, Petr Spacek wrote: On 27.5.2013 22:05, Simo Sorce wrote: On Mon, 2013-05-27 at 16:36 +0200, Petr Spacek wrote: On 27.5.2013 15:57, Simo Sorce wrote: On Mon, 2013-05-27 at 10:45 +0200, Petr Spacek wrote: Hello Simo, could you install/allow XMLRPC for our Patchwork,

Re: [Freeipa-devel] [PATCH 0060] Do not translate trust type and direction with --raw in trust-show

2013-05-28 Thread Tomas Babej
On 05/27/2013 03:04 PM, Ana Krivokapic wrote: On 05/27/2013 02:38 PM, Tomas Babej wrote: Hi, In trust_show command, make sure that --raw flag is honoured. Attributes ipanttrusttype and ipanttrustdirection are no longer translated to strings from their raw ldap values when --raw is used.

Re: [Freeipa-devel] [Patchwork] command line client

2013-05-28 Thread Simo Sorce
On Tue, 2013-05-28 at 10:46 +0200, Martin Kosek wrote: On 05/28/2013 10:38 AM, Petr Spacek wrote: On 27.5.2013 22:05, Simo Sorce wrote: On Mon, 2013-05-27 at 16:36 +0200, Petr Spacek wrote: On 27.5.2013 15:57, Simo Sorce wrote: On Mon, 2013-05-27 at 10:45 +0200, Petr Spacek wrote: Hello

Re: [Freeipa-devel] [RFC] Serving legacy systems cliens for trusts

2013-05-28 Thread Jakub Hrozek
On Tue, May 28, 2013 at 02:50:59PM +0300, Alexander Bokovoy wrote: = Dependencies = Depends on SSSD implementing IPA server mode (sssd 1.10.x) Nitpick -- currently this is planned for 1.11 ___ Freeipa-devel mailing list Freeipa-devel@redhat.com

Re: [Freeipa-devel] [PATCH 0057] Do not allow removal of ID range of an active trust

2013-05-28 Thread Alexander Bokovoy
On Mon, 27 May 2013, Tomas Babej wrote: We got rid of openldap utilities now. While using python.ldap module, I also made the tests much more robust and added a new test case. In general patches look fine, there is one small nitpick. I'll run tests on Monday and then will provide final ACK.

Re: [Freeipa-devel] CLDAP Netlogon fixes

2013-05-28 Thread Alexander Bokovoy
On Thu, 23 May 2013, Simo Sorce wrote: As you can see, incorrect parameters still return empty dn and netlogon attributes while Windows Server 2012 returns empty response: $ ldapsearch -LL -H cldap://altai.ad.lan -b -s base '((NtVer=\00\00\00\55\00)(AAC=\00\00\00\00))' netlogon version:

Re: [Freeipa-devel] [PATCH 0057] Do not allow removal of ID range of an active trust

2013-05-28 Thread Tomas Babej
On 05/28/2013 02:35 PM, Alexander Bokovoy wrote: On Mon, 27 May 2013, Tomas Babej wrote: We got rid of openldap utilities now. While using python.ldap module, I also made the tests much more robust and added a new test case. In general patches look fine, there is one small nitpick. I'll run

Re: [Freeipa-devel] [PATCH 0057] Do not allow removal of ID range of an active trust

2013-05-28 Thread Alexander Bokovoy
On Tue, 28 May 2013, Tomas Babej wrote: On 05/28/2013 02:35 PM, Alexander Bokovoy wrote: On Mon, 27 May 2013, Tomas Babej wrote: We got rid of openldap utilities now. While using python.ldap module, I also made the tests much more robust and added a new test case. In general patches look

[Freeipa-devel] [PATCH 0159] Deprecate configuration without persistent search

2013-05-28 Thread Petr Spacek
Hello, Deprecate configuration without persistent search. https://fedorahosted.org/bind-dyndb-ldap/ticket/120 -- Petr^2 Spacek From 316918a5b8ffec4f5db97cc0c44a9445b55e5d13 Mon Sep 17 00:00:00 2001 From: Petr Spacek pspa...@redhat.com Date: Tue, 28 May 2013 15:54:24 +0200 Subject: [PATCH]

Re: [Freeipa-devel] CLDAP Netlogon fixes

2013-05-28 Thread Martin Kosek
On 05/28/2013 04:12 PM, Martin Kosek wrote: On 05/28/2013 02:35 PM, Alexander Bokovoy wrote: On Thu, 23 May 2013, Simo Sorce wrote: As you can see, incorrect parameters still return empty dn and netlogon attributes while Windows Server 2012 returns empty response: $ ldapsearch -LL -H

Re: [Freeipa-devel] CLDAP Netlogon fixes

2013-05-28 Thread Martin Kosek
On 05/28/2013 02:35 PM, Alexander Bokovoy wrote: On Thu, 23 May 2013, Simo Sorce wrote: As you can see, incorrect parameters still return empty dn and netlogon attributes while Windows Server 2012 returns empty response: $ ldapsearch -LL -H cldap://altai.ad.lan -b -s base

Re: [Freeipa-devel] [PATCH 0059] Make testcert automagically when needed by unit test

2013-05-28 Thread Petr Viktorin
On 05/27/2013 04:07 PM, Tomas Babej wrote: On 05/24/2013 02:02 PM, Petr Viktorin wrote: On 05/24/2013 09:57 AM, Tomas Babej wrote: On 05/23/2013 07:17 PM, Tomas Babej wrote: Hi, With this patch, there's no need to run make-testcert separately before running make-test. Unit test framework

[Freeipa-devel] [PATCH 0030] Require rid-base and secondary-rid-base options in idrange-add when trust exists

2013-05-28 Thread Ana Krivokapic
Hello, This patch addresses https://fedorahosted.org/freeipa/ticket/3634 -- Regards, Ana Krivokapic Associate Software Engineer FreeIPA team Red Hat Inc. From d22fe354c901e7ab47a7a53270a43ca8baf1b03f Mon Sep 17 00:00:00 2001 From: Ana Krivokapic akriv...@redhat.com Date: Tue, 28 May 2013

Re: [Freeipa-devel] CLDAP Netlogon fixes

2013-05-28 Thread Martin Kosek
On 05/28/2013 04:13 PM, Martin Kosek wrote: On 05/28/2013 04:12 PM, Martin Kosek wrote: On 05/28/2013 02:35 PM, Alexander Bokovoy wrote: On Thu, 23 May 2013, Simo Sorce wrote: As you can see, incorrect parameters still return empty dn and netlogon attributes while Windows Server 2012 returns

Re: [Freeipa-devel] [PATCH 0060] Do not translate trust type and direction with --raw in trust-show

2013-05-28 Thread Ana Krivokapic
On 05/28/2013 01:20 PM, Tomas Babej wrote: On 05/27/2013 03:04 PM, Ana Krivokapic wrote: On 05/27/2013 02:38 PM, Tomas Babej wrote: Hi, In trust_show command, make sure that --raw flag is honoured. Attributes ipanttrusttype and ipanttrustdirection are no longer translated to strings from

Re: [Freeipa-devel] [Patchwork] command line client

2013-05-28 Thread Simo Sorce
On Mon, 2013-05-27 at 09:57 -0400, Simo Sorce wrote: On Mon, 2013-05-27 at 10:45 +0200, Petr Spacek wrote: Hello Simo, could you install/allow XMLRPC for our Patchwork, please? I found the CLI for Patchwork but it requires XMLRPC. On 27.5.2013 10:41, Petr Spacek wrote: see

Re: [Freeipa-devel] [Patchwork] command line client

2013-05-28 Thread Simo Sorce
On Tue, 2013-05-28 at 12:19 -0400, Simo Sorce wrote: On Mon, 2013-05-27 at 09:57 -0400, Simo Sorce wrote: On Mon, 2013-05-27 at 10:45 +0200, Petr Spacek wrote: Hello Simo, could you install/allow XMLRPC for our Patchwork, please? I found the CLI for Patchwork but it requires

Re: [Freeipa-devel] [RFC] Serving legacy systems cliens for trusts

2013-05-28 Thread Dmitri Pal
On 05/28/2013 07:50 AM, Alexander Bokovoy wrote: Hi, http://www.freeipa.org/page/V3/Serving_legacy_clients_for_trusts = Overview = Since version 3.0 FreeIPA supports cross-realm trusts with Active Directory. In order to allow AD users to utilize services on IPA clients, up to date

Re: [Freeipa-devel] [RFC] Serving legacy systems cliens for trusts

2013-05-28 Thread Alexander Bokovoy
On Tue, 28 May 2013, Dmitri Pal wrote: On 05/28/2013 07:50 AM, Alexander Bokovoy wrote: Hi, http://www.freeipa.org/page/V3/Serving_legacy_clients_for_trusts = Overview = Since version 3.0 FreeIPA supports cross-realm trusts with Active Directory. In order to allow AD users to utilize

Re: [Freeipa-devel] [RFC] Serving legacy systems cliens for trusts

2013-05-28 Thread Dmitri Pal
On 05/28/2013 03:48 PM, Alexander Bokovoy wrote: On Tue, 28 May 2013, Dmitri Pal wrote: On 05/28/2013 07:50 AM, Alexander Bokovoy wrote: Hi, http://www.freeipa.org/page/V3/Serving_legacy_clients_for_trusts = Overview = Since version 3.0 FreeIPA supports cross-realm trusts with Active

Re: [Freeipa-devel] [RFC] Serving legacy systems cliens for trusts

2013-05-28 Thread Alexander Bokovoy
On Tue, 28 May 2013, Dmitri Pal wrote: On 05/28/2013 03:48 PM, Alexander Bokovoy wrote: On Tue, 28 May 2013, Dmitri Pal wrote: On 05/28/2013 07:50 AM, Alexander Bokovoy wrote: Hi, http://www.freeipa.org/page/V3/Serving_legacy_clients_for_trusts = Overview = Since version 3.0 FreeIPA

Re: [Freeipa-devel] [RFC] Serving legacy systems cliens for trusts

2013-05-28 Thread Dmitri Pal
On 05/28/2013 04:29 PM, Alexander Bokovoy wrote: On Tue, 28 May 2013, Dmitri Pal wrote: On 05/28/2013 03:48 PM, Alexander Bokovoy wrote: On Tue, 28 May 2013, Dmitri Pal wrote: On 05/28/2013 07:50 AM, Alexander Bokovoy wrote: Hi,

Re: [Freeipa-devel] [RFC] Serving legacy systems cliens for trusts

2013-05-28 Thread Alexander Bokovoy
On Tue, 28 May 2013, Dmitri Pal wrote: On 05/28/2013 04:29 PM, Alexander Bokovoy wrote: On Tue, 28 May 2013, Dmitri Pal wrote: On 05/28/2013 03:48 PM, Alexander Bokovoy wrote: On Tue, 28 May 2013, Dmitri Pal wrote: On 05/28/2013 07:50 AM, Alexander Bokovoy wrote: Hi,