[Freeipa-devel] Expired passwords cannot be changed via LDAP

2014-06-09 Thread Martin Kosek
On 06/09/2014 08:21 AM, Martin Kosek wrote: On 06/06/2014 05:47 PM, Nathaniel McCallum wrote: On Fri, 2014-06-06 at 11:43 -0400, Simo Sorce wrote: On Fri, 2014-06-06 at 11:06 -0400, Nathaniel McCallum wrote: On Fri, 2014-06-06 at 08:00 -0400, Simo Sorce wrote: On Fri, 2014-06-06 at 10:30

Re: [Freeipa-devel] Patch for #1539

2014-06-09 Thread Petr Viktorin
On 06/09/2014 08:21 AM, Martin Kosek wrote: On 06/06/2014 05:47 PM, Nathaniel McCallum wrote: On Fri, 2014-06-06 at 11:43 -0400, Simo Sorce wrote: On Fri, 2014-06-06 at 11:06 -0400, Nathaniel McCallum wrote: On Fri, 2014-06-06 at 08:00 -0400, Simo Sorce wrote: On Fri, 2014-06-06 at 10:30

Re: [Freeipa-devel] Expired passwords cannot be changed via LDAP

2014-06-09 Thread Martin Kosek
On 06/09/2014 10:59 AM, Martin Kosek wrote: On 06/09/2014 08:21 AM, Martin Kosek wrote: On 06/06/2014 05:47 PM, Nathaniel McCallum wrote: On Fri, 2014-06-06 at 11:43 -0400, Simo Sorce wrote: On Fri, 2014-06-06 at 11:06 -0400, Nathaniel McCallum wrote: On Fri, 2014-06-06 at 08:00 -0400, Simo

Re: [Freeipa-devel] Expired passwords cannot be changed via LDAP

2014-06-09 Thread Alon Bar-Lev
- Original Message - From: Martin Kosek mko...@redhat.com To: Nathaniel McCallum npmccal...@redhat.com, Simo Sorce s...@redhat.com Cc: freeipa-devel freeipa-devel@redhat.com Sent: Monday, June 9, 2014 1:11:17 PM Subject: Re: [Freeipa-devel] Expired passwords cannot be changed via

Re: [Freeipa-devel] [PATCHES] 0568-0570 Convert User default permissions to managed

2014-06-09 Thread Petr Viktorin
On 06/06/2014 11:38 AM, Martin Kosek wrote: On 06/04/2014 06:43 PM, Petr Viktorin wrote: Hello, I try to think about any kind of data the user might have in LDAP, but in the spirit of YAGNI, I'll deal with the various corner cases in IPA's historic default permissions as I go along. Patch 0568

Re: [Freeipa-devel] Expired passwords cannot be changed via LDAP

2014-06-09 Thread Simo Sorce
On 06/09/2014 12:15 PM, Alon Bar-Lev wrote: From: Martin Kosek mko...@redhat.com Given all sort of issues we get, I am thinking we should just revert it unless there is a quick fix available. The fix should be for the password modify to work within anonymous bind if old password is

Re: [Freeipa-devel] Patch for #1539

2014-06-09 Thread Simo Sorce
Pushed to master: bfdbd3b6ad7c437e7dd293d2488b2d53f4ea7ba6 Hello, This patch broke some of our tests. ipatests.test_ipaserver.test_changepw:test_changepw.test_invalid_auth ipatests.test_xmlrpc.test_user_plugin:test_denied_bind_with_expired_principal.test_1_bind_as_test_user

Re: [Freeipa-devel] Expired passwords cannot be changed via LDAP

2014-06-09 Thread Simo Sorce
From: Martin Kosek mko...@redhat.com Given all sort of issues we get, I am thinking we should just revert it unless there is a quick fix available. Instead of reverting I am thinking we may want to make this optional by adding a configuration parameter that defaults to False for

Re: [Freeipa-devel] Expired passwords cannot be changed via LDAP

2014-06-09 Thread Dmitri Pal
On 06/09/2014 09:01 AM, Simo Sorce wrote: From: Martin Kosek mko...@redhat.com Given all sort of issues we get, I am thinking we should just revert it unless there is a quick fix available. Instead of reverting I am thinking we may want to make this optional by adding a configuration parameter

Re: [Freeipa-devel] Expired passwords cannot be changed via LDAP

2014-06-09 Thread Martin Kosek
On 06/09/2014 03:08 PM, Dmitri Pal wrote: On 06/09/2014 09:01 AM, Simo Sorce wrote: From: Martin Kosek mko...@redhat.com Given all sort of issues we get, I am thinking we should just revert it unless there is a quick fix available. Instead of reverting I am thinking we may want to make this

Re: [Freeipa-devel] [PATCH] 592-628 Update to PatternFly

2014-06-09 Thread Petr Vobornik
On 6.6.2014 20:35, Endi Sukma Dewata wrote: On 6/6/2014 10:43 AM, Petr Vobornik wrote: On 6.6.2014 15:45, Endi Sukma Dewata wrote: On 6/5/2014 9:25 AM, Endi Sukma Dewata wrote: ACK for patches #592-#628. I'll continue reviewing the rest. ACK for patches #633-639, #642, #644, #652, and #653.

Re: [Freeipa-devel] [PATCHES 21-22] ipautil log messages and API version to env

2014-06-09 Thread Petr Viktorin
On 06/06/2014 05:02 PM, Gabe Alford wrote: Patch 21: Update per recommendation Patch 22: Added version option as well as updated the manpage. Thanks, Gabe Great! Thanks, ACK, pushed to master: 2a8c509567754877ed0188784d7c38250484be48 In the future, you can put typo fixes in a separate

Re: [Freeipa-devel] Reorganization of Web UI navigation items

2014-06-09 Thread Simo Sorce
On Mon, 2014-06-09 at 16:08 +0200, Petr Vobornik wrote: Accounts/Identity (7): - Users - Groups - Hosts - Host Groups - Netgroups - Services - Automember ^ These are all identity or identity-grouping related objects/actions +1 What are the chances that we will add some

Re: [Freeipa-devel] Expired passwords cannot be changed via LDAP

2014-06-09 Thread Dmitri Pal
On 06/09/2014 10:03 AM, Nathaniel McCallum wrote: On Mon, 2014-06-09 at 09:01 -0400, Simo Sorce wrote: From: Martin Kosek mko...@redhat.com Given all sort of issues we get, I am thinking we should just revert it unless there is a quick fix available. Instead of reverting I am thinking we may

Re: [Freeipa-devel] Reorganization of Web UI navigation items

2014-06-09 Thread Petr Vobornik
On 9.6.2014 16:42, Simo Sorce wrote: On Mon, 2014-06-09 at 16:08 +0200, Petr Vobornik wrote: Accounts/Identity (7): - Users - Groups - Hosts - Host Groups - Netgroups - Services - Automember ^ These are all identity or identity-grouping related objects/actions +1 What are the chances that

Re: [Freeipa-devel] [PATCH] #3859: Better mechanism to retrieve keytabs

2014-06-09 Thread Rob Crittenden
Simo Sorce wrote: This patch set is an initial implementation of ticket #3859 It seem to be working fine in my initial testing but I have not yet tested all cases. However I wonted to throw it on the list to get some initial feedback about the choices I made wrt access control and

Re: [Freeipa-devel] Reorganization of Web UI navigation items

2014-06-09 Thread Kyle Baker
- Original Message - On 9.6.2014 16:42, Simo Sorce wrote: On Mon, 2014-06-09 at 16:08 +0200, Petr Vobornik wrote: Accounts/Identity (7): - Users - Groups - Hosts - Host Groups - Netgroups - Services - Automember ^ These are all identity or identity-grouping related

[Freeipa-devel] [PATCH] 0576 Split long docstrings that were recently modified

2014-06-09 Thread Petr Viktorin
Hello, Some big plugin module docstrings were modified. This means translators will need to re-translate the whole string. To avoid the extra work in the future, I've split the strings we changed since the last time ipa.pot was regenerated. See:

Re: [Freeipa-devel] [PATCH] #3859: Better mechanism to retrieve keytabs

2014-06-09 Thread Nathaniel McCallum
On Mon, 2014-06-09 at 15:02 -0400, Simo Sorce wrote: On Mon, 2014-06-09 at 13:39 -0400, Rob Crittenden wrote: Simo Sorce wrote: This patch set is an initial implementation of ticket #3859 It seem to be working fine in my initial testing but I have not yet tested all cases.

Re: [Freeipa-devel] [PATCH] 592-628 Update to PatternFly

2014-06-09 Thread Endi Sukma Dewata
On 6/9/2014 8:46 AM, Petr Vobornik wrote: I've fixed issues #4, #2, #20 and #18. Commits in the branch, no rebase. With these 4 changes we are ready for the push. I'll squash them, if necessary. You mean #11 instead of #2? The fixes are confirmed. 2. If there's a login error, the logo and

Re: [Freeipa-devel] [PATCH] #3859: Better mechanism to retrieve keytabs

2014-06-09 Thread Simo Sorce
On Mon, 2014-06-09 at 17:53 -0400, Nathaniel McCallum wrote: On Mon, 2014-06-09 at 15:02 -0400, Simo Sorce wrote: On Mon, 2014-06-09 at 13:39 -0400, Rob Crittenden wrote: Simo Sorce wrote: This patch set is an initial implementation of ticket #3859 It seem to be working fine in

Re: [Freeipa-devel] [PATCH] #3859: Better mechanism to retrieve keytabs

2014-06-09 Thread Nathaniel McCallum
On Mon, 2014-06-09 at 20:58 -0400, Simo Sorce wrote: On Mon, 2014-06-09 at 17:53 -0400, Nathaniel McCallum wrote: On Mon, 2014-06-09 at 15:02 -0400, Simo Sorce wrote: On Mon, 2014-06-09 at 13:39 -0400, Rob Crittenden wrote: Simo Sorce wrote: This patch set is an initial