Re: [Freeipa-devel] [PATCH] Stop ntpd before running ntpdate

2014-04-29 Thread Petr Spacek
Hello Gabe! On 25.4.2014 16:28, Gabe Alford wrote: Here is a patch for https://fedorahosted.org/freeipa/ticket/3735. It seemed better to try to stop ntpd before running ntpdate rather than not running ntpdate if ntpd was already running. I believe this patch only applies to the ipa-3-3

Re: [Freeipa-devel] Draft: Read permissions for user

2014-04-29 Thread Petr Viktorin
On 04/24/2014 11:35 AM, Martin Kosek wrote: On 04/23/2014 10:53 PM, Martin Kosek wrote: On 04/23/2014 08:07 PM, Simo Sorce wrote: [...] I know, we may need to provide another permission admins can use to turn on anonymous searches for those attributes too. We may also decide that on upgrade v

Re: [Freeipa-devel] Draft: Read permissions for user

2014-04-29 Thread Martin Kosek
On 04/29/2014 01:03 PM, Petr Viktorin wrote: > On 04/24/2014 11:35 AM, Martin Kosek wrote: >> On 04/23/2014 10:53 PM, Martin Kosek wrote: >>> On 04/23/2014 08:07 PM, Simo Sorce wrote: > [...] I know, we may need to provide another permission admins can use to turn on anonymous search

Re: [Freeipa-devel] Draft: Read permissions for user

2014-04-29 Thread Simo Sorce
On Tue, 2014-04-29 at 14:21 +0200, Martin Kosek wrote: > On 04/29/2014 01:03 PM, Petr Viktorin wrote: > > On 04/24/2014 11:35 AM, Martin Kosek wrote: > >> On 04/23/2014 10:53 PM, Martin Kosek wrote: > >>> On 04/23/2014 08:07 PM, Simo Sorce wrote: > > [...] > > I know, we may need to provi

Re: [Freeipa-devel] [PATCH] 14 webui: select all checkbox remains selected after operation

2014-04-29 Thread Petr Vobornik
On 24.4.2014 14:57, Misnyovszki Adam wrote: On Wed, 23 Apr 2014 16:57:35 +0200 Petr Vobornik wrote: On 18.4.2014 10:43, Misnyovszki Adam wrote: Hi, this patch fixes select_all checkbox issue, after any bulk modify or delete operation, the checkbox is deselected. https://fedorahosted.org/freei

Re: [Freeipa-devel] Draft: Read permissions for user

2014-04-29 Thread Martin Kosek
On 04/29/2014 02:48 PM, Simo Sorce wrote: > On Tue, 2014-04-29 at 14:21 +0200, Martin Kosek wrote: >> On 04/29/2014 01:03 PM, Petr Viktorin wrote: >>> On 04/24/2014 11:35 AM, Martin Kosek wrote: On 04/23/2014 10:53 PM, Martin Kosek wrote: > On 04/23/2014 08:07 PM, Simo Sorce wrote: >>> [..

Re: [Freeipa-devel] Draft: Read permissions for user

2014-04-29 Thread Simo Sorce
On Tue, 2014-04-29 at 15:10 +0200, Martin Kosek wrote: > On 04/29/2014 02:48 PM, Simo Sorce wrote: > > On Tue, 2014-04-29 at 14:21 +0200, Martin Kosek wrote: > >> On 04/29/2014 01:03 PM, Petr Viktorin wrote: > >>> On 04/24/2014 11:35 AM, Martin Kosek wrote: > On 04/23/2014 10:53 PM, Martin Kos

Re: [Freeipa-devel] [PATCH] webui: regression - enable fields on idrange type change (add)

2014-04-29 Thread Misnyovszki Adam
On Fri, 25 Apr 2014 15:01:36 +0200 Petr Vobornik wrote: > ID range adder dialog was not properly addressed in field binding > refactoring. > > The usage of reset caused some weird loops. > > https://fedorahosted.org/freeipa/ticket/4326 tests with and without trusts ran smoothly, manual tests

Re: [Freeipa-devel] [PATCH] 1106 IPA REST smart proxy

2014-04-29 Thread Rob Crittenden
Petr Viktorin wrote: On 04/23/2014 08:52 PM, Rob Crittenden wrote: Petr Viktorin wrote: On 04/09/2014 11:29 PM, Rob Crittenden wrote: Rob Crittenden wrote: Petr Viktorin wrote: On 03/14/2014 07:58 PM, Rob Crittenden wrote: Petr Viktorin wrote: On 03/12/2014 07:48 PM, Rob Crittenden wrote:

Re: [Freeipa-devel] [PATCH] 18 webui otptoken test data added

2014-04-29 Thread Misnyovszki Adam
On Fri, 25 Apr 2014 17:16:48 +0200 Misnyovszki Adam wrote: > Hi, > this patch adds some static test data for the webui otptoken part. > Adam Attached corrected DN's. Thanks Adam>From e5816ae2dca48841c7c3b3edf591257b89fcb49b Mon Sep 17 00:00:00 2001 From: Adam Misnyovszki Date: Fri, 25 Apr 2014

Re: [Freeipa-devel] [PATCH] webui: regression - enable fields on idrange type change (add)

2014-04-29 Thread Petr Vobornik
On 29.4.2014 16:25, Misnyovszki Adam wrote: On Fri, 25 Apr 2014 15:01:36 +0200 Petr Vobornik wrote: ID range adder dialog was not properly addressed in field binding refactoring. The usage of reset caused some weird loops. https://fedorahosted.org/freeipa/ticket/4326 tests with and without

Re: [Freeipa-devel] [PATCH] 1106 IPA REST smart proxy

2014-04-29 Thread Petr Viktorin
On 04/29/2014 04:27 PM, Rob Crittenden wrote: Petr Viktorin wrote: On 04/23/2014 08:52 PM, Rob Crittenden wrote: Petr Viktorin wrote: On 04/09/2014 11:29 PM, Rob Crittenden wrote: Rob Crittenden wrote: Petr Viktorin wrote: On 03/14/2014 07:58 PM, Rob Crittenden wrote: Petr Viktorin wrote:

[Freeipa-devel] [PATCH] 0543 - dns: Add idnsSecInlineSigning attribute, add --dnssec option to zone

2014-04-29 Thread Petr Viktorin
This adds the "idnsSecInlineSigning" attribute and related option. https://fedorahosted.org/freeipa/ticket/3801 Simo, is adding a MAY attribute to an existing objectClass okay? -- PetrĀ³ From 6cd0ee326598ef36583415087ab673645d3e6593 Mon Sep 17 00:00:00 2001 From: Petr Viktorin Date: Tue, 29 Apr

Re: [Freeipa-devel] [PATCH] 0543 - dns: Add idnsSecInlineSigning attribute, add --dnssec option to zone

2014-04-29 Thread Simo Sorce
On Tue, 2014-04-29 at 20:00 +0200, Petr Viktorin wrote: > This adds the "idnsSecInlineSigning" attribute and related option. > > https://fedorahosted.org/freeipa/ticket/3801 > > Simo, is adding a MAY attribute to an existing objectClass okay? > Not unheard of, however in the past we discovered

Re: [Freeipa-devel] [PATCH] 0543 - dns: Add idnsSecInlineSigning attribute, add --dnssec option to zone

2014-04-29 Thread Martin Kosek
On 04/29/2014 08:17 PM, Simo Sorce wrote: On Tue, 2014-04-29 at 20:00 +0200, Petr Viktorin wrote: This adds the "idnsSecInlineSigning" attribute and related option. https://fedorahosted.org/freeipa/ticket/3801 Simo, is adding a MAY attribute to an existing objectClass okay? Not unheard of,

[Freeipa-devel] [PATCHES] 0540-0542 Add managed read permissions to user

2014-04-29 Thread Petr Viktorin
Patch 0540 adds a bunch of managed read ACIs for user, as discussed previously [0]. Patch 0541 is some minor refactoring for the next part. Patch 0542 sets the read acces to addressbook attributes to anonymous when upgrading from pre-4.0. I first this by checking if the update is run from ipa-

[Freeipa-devel] [PATCH] 0544 Remove the global anonymous read ACI

2014-04-29 Thread Petr Viktorin
I didn't test this as much as I'd like to, but it might come in handy when testing my earlier patches. The ACI is removed in the managed permissions plugin because I want to make sure it's done after all the managed permission updates, which query it. -- PetrĀ³ From 5d1bdbf5b84cb4dc286b72274e

[Freeipa-devel] [PATCH 0251-0256] Add support for NSEC3

2014-04-29 Thread Petr Spacek
Hello, This patch set adds support for NSEC3. See commit messages for details. -- Petr^2 Spacek From 2a1bae4420a587ffbd660071a4a8af9bb1db4ec2 Mon Sep 17 00:00:00 2001 From: Petr Spacek Date: Tue, 29 Apr 2014 18:34:48 +0200 Subject: [PATCH] Fix false error message about secure zones. In-line se

Re: [Freeipa-devel] [PATCH] Stop ntpd before running ntpdate

2014-04-29 Thread Gabe Alford
Updated patch to not run ntpdate if ntpd is running. Gabe On Tue, Apr 29, 2014 at 8:16 AM, Gabe Alford wrote: > Thanks Petr! > > Will rework patch to just skip ntpdate if ntpd is already running. > > > On Tue, Apr 29, 2014 at 12:59 AM, Petr Spacek wrote: > >> Hello Gabe! >> >> >> On 25.4.2014

[Freeipa-devel] new developer; development environment

2014-04-29 Thread Fraser Tweedale
Hi all, Fraser Tweedale, brand new Red Hatter, working in the Brisbane office on FreeIPA/Dogtag, and needing the wisdom of seasoned IPA developers on how best to set things up. In particular, is it common to be developing in VMs, and if so, do the various components (DS, Dogtag, IPA etc) under (o

Re: [Freeipa-devel] new developer; development environment

2014-04-29 Thread Alexander Bokovoy
On Wed, 30 Apr 2014, Fraser Tweedale wrote: Hi all, Fraser Tweedale, brand new Red Hatter, working in the Brisbane office on FreeIPA/Dogtag, and needing the wisdom of seasoned IPA developers on how best to set things up. Welcome Fraser! In particular, is it common to be developing in VMs, an