Re: [Freeipa-devel] #4534: SSSD deref processing fail when entryusn can be read and objectclass doesn't

2014-09-12 Thread Petr Viktorin
On 09/11/2014 10:24 PM, Martin Kosek wrote: On 09/11/2014 08:49 PM, Simo Sorce wrote: On Thu, 2014-09-11 at 20:28 +0200, Martin Kosek wrote: On 09/11/2014 05:37 PM, Simo Sorce wrote: On Thu, 2014-09-11 at 17:03 +0200, Martin Kosek wrote: Hello, We have another important issue to resolve. Cur

Re: [Freeipa-devel] FreeIPA 4.0.3?

2014-09-12 Thread Martin Kosek
On 09/12/2014 03:21 AM, Nathaniel McCallum wrote: On Thu, 2014-09-11 at 16:48 +0200, Petr Viktorin wrote: On 09/11/2014 04:43 PM, Nathaniel McCallum wrote: On Thu, 2014-09-11 at 16:39 +0200, Petr Viktorin wrote: On 09/11/2014 04:38 PM, Ludwig Krispenz wrote: On 09/11/2014 04:31 PM, Petr Vikt

Re: [Freeipa-devel] #4534: SSSD deref processing fail when entryusn can be read and objectclass doesn't

2014-09-12 Thread Martin Kosek
On 09/12/2014 09:35 AM, Petr Viktorin wrote: On 09/11/2014 10:24 PM, Martin Kosek wrote: On 09/11/2014 08:49 PM, Simo Sorce wrote: On Thu, 2014-09-11 at 20:28 +0200, Martin Kosek wrote: On 09/11/2014 05:37 PM, Simo Sorce wrote: On Thu, 2014-09-11 at 17:03 +0200, Martin Kosek wrote: Hello, W

Re: [Freeipa-devel] #4534: SSSD deref processing fail when entryusn can be read and objectclass doesn't

2014-09-12 Thread Alexander Bokovoy
On Fri, 12 Sep 2014, Martin Kosek wrote: Operational Attributes) Removing a default ACI is difficult (read: new code that could go wrong) if we want to handle 4.0.2 properly, since installing/upgrading to 4.0.2 will always add it back. Perhaps we should just say in the release notes that people

Re: [Freeipa-devel] #4534: SSSD deref processing fail when entryusn can be read and objectclass doesn't

2014-09-12 Thread Petr Viktorin
On 09/12/2014 09:48 AM, Alexander Bokovoy wrote: On Fri, 12 Sep 2014, Martin Kosek wrote: Operational Attributes) Removing a default ACI is difficult (read: new code that could go wrong) if we want to handle 4.0.2 properly, since installing/upgrading to 4.0.2 will always add it back. Perhaps w

Re: [Freeipa-devel] FreeIPA 4.0.3?

2014-09-12 Thread Ludwig Krispenz
On 09/12/2014 09:37 AM, Martin Kosek wrote: On 09/12/2014 03:21 AM, Nathaniel McCallum wrote: On Thu, 2014-09-11 at 16:48 +0200, Petr Viktorin wrote: On 09/11/2014 04:43 PM, Nathaniel McCallum wrote: On Thu, 2014-09-11 at 16:39 +0200, Petr Viktorin wrote: On 09/11/2014 04:38 PM, Ludwig Krisp

Re: [Freeipa-devel] FreeIPA 4.0.3?

2014-09-12 Thread Martin Kosek
On 09/12/2014 10:13 AM, Ludwig Krispenz wrote: On 09/12/2014 09:37 AM, Martin Kosek wrote: On 09/12/2014 03:21 AM, Nathaniel McCallum wrote: On Thu, 2014-09-11 at 16:48 +0200, Petr Viktorin wrote: On 09/11/2014 04:43 PM, Nathaniel McCallum wrote: On Thu, 2014-09-11 at 16:39 +0200, Petr Vikto

Re: [Freeipa-devel] #4534: SSSD deref processing fail when entryusn can be read and objectclass doesn't

2014-09-12 Thread thierry bordaz
On 09/11/2014 10:24 PM, Martin Kosek wrote: On 09/11/2014 08:49 PM, Simo Sorce wrote: On Thu, 2014-09-11 at 20:28 +0200, Martin Kosek wrote: On 09/11/2014 05:37 PM, Simo Sorce wrote: On Thu, 2014-09-11 at 17:03 +0200, Martin Kosek wrote: Hello, We have another important issue to resolve. Cur

Re: [Freeipa-devel] #4534: SSSD deref processing fail when entryusn can be read and objectclass doesn't

2014-09-12 Thread Martin Kosek
On 09/12/2014 10:27 AM, thierry bordaz wrote: On 09/11/2014 10:24 PM, Martin Kosek wrote: On 09/11/2014 08:49 PM, Simo Sorce wrote: On Thu, 2014-09-11 at 20:28 +0200, Martin Kosek wrote: On 09/11/2014 05:37 PM, Simo Sorce wrote: On Thu, 2014-09-11 at 17:03 +0200, Martin Kosek wrote: Hello,

Re: [Freeipa-devel] [PATCH] 0009 Detect and configure all usable IP addresses.

2014-09-12 Thread David Kupka
On 09/08/2014 05:56 PM, Martin Basti wrote: On 02/09/14 16:55, David Kupka wrote: The patch now depends on freeipa-dkupka-0012 as both modifies the same part of code. freeipa-dkupka-0012 is now accepted and merged upstream so there is no need to take this dependency into account. On 09/02

Re: [Freeipa-devel] FreeIPA 4.0.3?

2014-09-12 Thread Martin Kosek
On 09/12/2014 10:25 AM, Martin Kosek wrote: On 09/12/2014 10:13 AM, Ludwig Krispenz wrote: On 09/12/2014 09:37 AM, Martin Kosek wrote: On 09/12/2014 03:21 AM, Nathaniel McCallum wrote: On Thu, 2014-09-11 at 16:48 +0200, Petr Viktorin wrote: On 09/11/2014 04:43 PM, Nathaniel McCallum wrote:

[Freeipa-devel] [PATCH] 0001 Update-SSL-ciphers-configured-in-389-ds-base

2014-09-12 Thread Ludwig Krispenz
please review attached patch for ticket: https://fedorahosted.org/freeipa/ticket/4395 use new options in 389-ds to configure enabled ciphers >From e3ab55b01c7d800ffe9f4a43f328087d97e328db Mon Sep 17 00:00:00 2001 From: Ludwig Krispenz Date: Fri, 12 Sep 2014 12:43:31 +0200 Subject: [PATCH] Updat

[Freeipa-devel] [PATCHES] 0642-0643 Move granting read access to entryusn & timestamp entries to individual permissions

2014-09-12 Thread Petr Viktorin
https://fedorahosted.org/freeipa/ticket/4534 The entryusn and timestamp operational attributes are now automatically added to every read permission that targets objectclass, whether managed or user-created. The 'System: Read Timestamp and USN Operational Attributes', which was added for 4.0.

Re: [Freeipa-devel] [PATCH 0291-0294] Fix locking to prevent crashes and deadlocks

2014-09-12 Thread Martin Basti
On 11/09/14 21:58, Petr Spacek wrote: On 11.9.2014 18:34, Martin Basti wrote: On 11/09/14 15:57, Martin Basti wrote: On 11/09/14 11:59, Petr Spacek wrote: Hello, I was fighting with random crashes for couple of days ... and discovered that run_exclusive_enter()/isc_task_beginexclusive() usag

Re: [Freeipa-devel] [PATCH 0291-0294] Fix locking to prevent crashes and deadlocks

2014-09-12 Thread Petr Spacek
On 12.9.2014 14:45, Martin Basti wrote: On 11/09/14 21:58, Petr Spacek wrote: On 11.9.2014 18:34, Martin Basti wrote: On 11/09/14 15:57, Martin Basti wrote: On 11/09/14 11:59, Petr Spacek wrote: Hello, I was fighting with random crashes for couple of days ... and discovered that run_exclusiv

[Freeipa-devel] [PATCH 0295-0296] Release 5.3

2014-09-12 Thread Petr Spacek
Hello, Update NEWS for upcoming 5.3 release. Pushed to master: b1a176d0b71127b428db3a901f736d1ca2ed6a65 Bump NVR to 5.3. Pushed to master: 9886db5772a6635bdc33f718685b7df0ea1a3ea1 -- Petr^2 Spacek From b1a176d0b71127b428db3a901f736d1ca2ed6a65 Mon Sep 17 00:00:00 2001 From: Petr Spacek Date: Fr

Re: [Freeipa-devel] [PATCHES 0114-0115, 0120-0121] DNS: allow to add root zone '.'

2014-09-12 Thread Martin Basti
On 03/09/14 12:45, Martin Basti wrote: On 03/09/14 12:27, Martin Kosek wrote: On 09/02/2014 05:46 PM, Petr Spacek wrote: On 25.8.2014 14:52, Martin Basti wrote: Patches attached. Ticket: https://fedorahosted.org/freeipa/ticket/4149 There is a bug in bind-dyndb-ldap (or worse in dirsrv), whic

[Freeipa-devel] [PATCH 0122] Add dogtag 10.2 to specfile

2014-09-12 Thread Martin Basti
I always forgot to install dogtag 10.2, so here is updated specfile. COPR: http://copr.fedoraproject.org/coprs/vakwetu/dogtag/ Patch atached. ipa-4-1 -- Martin Basti From 36de55fd8edc63c50cb6494a1a432eb1eb21fb44 Mon Sep 17 00:00:00 2001 From: Martin Basti Date: Fri, 12 Sep 2014 13:19:40 +020

Re: [Freeipa-devel] [PATCH 0122] Add dogtag 10.2 to specfile

2014-09-12 Thread Alexander Bokovoy
On Fri, 12 Sep 2014, Martin Basti wrote: I always forgot to install dogtag 10.2, so here is updated specfile. COPR: http://copr.fedoraproject.org/coprs/vakwetu/dogtag/ ACK if you fix the commit message (see below), NACK for the link, as dogtag 10.2 is going to Rawhide and F21. https://admin.fed

Re: [Freeipa-devel] FreeIPA 4.0.3?

2014-09-12 Thread Nathaniel McCallum
On Fri, 2014-09-12 at 13:17 +0200, Martin Kosek wrote: > On 09/12/2014 10:25 AM, Martin Kosek wrote: > > On 09/12/2014 10:13 AM, Ludwig Krispenz wrote: > >> > >> On 09/12/2014 09:37 AM, Martin Kosek wrote: > >>> On 09/12/2014 03:21 AM, Nathaniel McCallum wrote: > On Thu, 2014-09-11 at 16:48 +0

Re: [Freeipa-devel] FreeIPA 4.0.3?

2014-09-12 Thread Ludwig Krispenz
Hi, I alread had sent a patch for review, It is exactly like yours with one exception: 65c61 < +default:allowWeakCipher: off --- > +addifnew:allowWeakCipher: off I tested with default, but it was ignored - is default only used for new entries ? On 09/12/2014 04:08 PM, Nathaniel McCallum wro

Re: [Freeipa-devel] [PATCH 0122] Add dogtag 10.2 to specfile

2014-09-12 Thread Martin Basti
On 12/09/14 16:02, Martin Basti wrote: I always forgot to install dogtag 10.2, so here is updated specfile. COPR: http://copr.fedoraproject.org/coprs/vakwetu/dogtag/ Patch atached. ipa-4-1 I'm not sure if dogtag 10.2 is required in 4.1 -- Martin Basti

Re: [Freeipa-devel] FreeIPA 4.0.3?

2014-09-12 Thread Nathaniel McCallum
Sorry, I missed that. Let's take your patch. On Fri, 2014-09-12 at 16:16 +0200, Ludwig Krispenz wrote: > Hi, > > I alread had sent a patch for review, It is exactly like yours with one > exception: > 65c61 > < +default:allowWeakCipher: off > --- > > +addifnew:allowWeakCipher: off > > I tested

Re: [Freeipa-devel] [PATCH] 0001 Update-SSL-ciphers-configured-in-389-ds-base

2014-09-12 Thread Nathaniel McCallum
On Fri, 2014-09-12 at 13:21 +0200, Ludwig Krispenz wrote: > please review attached patch for ticket: > https://fedorahosted.org/freeipa/ticket/4395 > > use new options in 389-ds to configure enabled ciphers ACK. Let's get 4.0.3 out the door! :) ___ Fr

Re: [Freeipa-devel] [PATCHES] 0642-0643 Move granting read access to entryusn & timestamp entries to individual permissions

2014-09-12 Thread Martin Kosek
On 09/12/2014 01:53 PM, Petr Viktorin wrote: https://fedorahosted.org/freeipa/ticket/4534 The entryusn and timestamp operational attributes are now automatically added to every read permission that targets objectclass, whether managed or user-created. The 'System: Read Timestamp and USN Operati

[Freeipa-devel] [Freeipa-interest] Announcing bind-dyndb-ldap version 5.3

2014-09-12 Thread Petr Spacek
The FreeIPA team is proud to announce bind-dyndb-ldap version 5.3. It can be downloaded from https://fedorahosted.org/released/bind-dyndb-ldap/ The new version has also been built for Fedora 21+ and and is on its way to updates-testing: https://admin.fedoraproject.org/updates/bind-dyndb-ldap-5

Re: [Freeipa-devel] #4534: SSSD deref processing fail when entryusn can be read and objectclass doesn't

2014-09-12 Thread Simo Sorce
On Fri, 2014-09-12 at 09:42 +0200, Martin Kosek wrote: > > Well, I am not convinced that everyone reads the release notes, so I > would rather delete this permission in 4.0.3. Hopefully, there won't > be many 4.0.2 users. It seems as a lesser evil to me than having SSSD > clients broken. +1 such

Re: [Freeipa-devel] #4534: SSSD deref processing fail when entryusn can be read and objectclass doesn't

2014-09-12 Thread Simo Sorce
On Fri, 2014-09-12 at 10:27 +0200, thierry bordaz wrote: > On 09/11/2014 10:24 PM, Martin Kosek wrote: > > On 09/11/2014 08:49 PM, Simo Sorce wrote: > >> On Thu, 2014-09-11 at 20:28 +0200, Martin Kosek wrote: > >>> On 09/11/2014 05:37 PM, Simo Sorce wrote: > On Thu, 2014-09-11 at 17:03 +0200,

Re: [Freeipa-devel] [PATCH 0122] Add dogtag 10.2 to specfile

2014-09-12 Thread Martin Kosek
On 09/12/2014 04:14 PM, Martin Basti wrote: On 12/09/14 16:02, Martin Basti wrote: I always forgot to install dogtag 10.2, so here is updated specfile. COPR: http://copr.fedoraproject.org/coprs/vakwetu/dogtag/ Patch atached. ipa-4-1 I'm not sure if dogtag 10.2 is required in 4.1 It is

Re: [Freeipa-devel] [PATCHES] 0642-0643 Move granting read access to entryusn & timestamp entries to individual permissions

2014-09-12 Thread Simo Sorce
On Fri, 2014-09-12 at 13:53 +0200, Petr Viktorin wrote: > https://fedorahosted.org/freeipa/ticket/4534 > > The entryusn and timestamp operational attributes are now automatically > added to every read permission that targets objectclass, whether managed > or user-created. > > The 'System: Read

Re: [Freeipa-devel] FreeIPA 4.0.3?

2014-09-12 Thread Rob Crittenden
Ludwig Krispenz wrote: > Hi, > > I alread had sent a patch for review, It is exactly like yours with one > exception: > 65c61 > < +default:allowWeakCipher: off > --- >> +addifnew:allowWeakCipher: off > > I tested with default, but it was ignored - is default only used for new > entries ? Correct

Re: [Freeipa-devel] [PATCH 0122] Add dogtag 10.2 to specfile

2014-09-12 Thread Martin Basti
On 12/09/14 16:38, Martin Kosek wrote: On 09/12/2014 04:14 PM, Martin Basti wrote: On 12/09/14 16:02, Martin Basti wrote: I always forgot to install dogtag 10.2, so here is updated specfile. COPR: http://copr.fedoraproject.org/coprs/vakwetu/dogtag/ Patch atached. ipa-4-1 I'm not sure if

Re: [Freeipa-devel] [PATCHES] 0642-0643 Move granting read access to entryusn & timestamp entries to individual permissions

2014-09-12 Thread Petr Viktorin
On 09/12/2014 04:25 PM, Martin Kosek wrote: On 09/12/2014 01:53 PM, Petr Viktorin wrote: https://fedorahosted.org/freeipa/ticket/4534 The entryusn and timestamp operational attributes are now automatically added to every read permission that targets objectclass, whether managed or user-created.

Re: [Freeipa-devel] [PATCH] 0001 Update-SSL-ciphers-configured-in-389-ds-base

2014-09-12 Thread Martin Kosek
On 09/12/2014 04:18 PM, Nathaniel McCallum wrote: On Fri, 2014-09-12 at 13:21 +0200, Ludwig Krispenz wrote: please review attached patch for ticket: https://fedorahosted.org/freeipa/ticket/4395 use new options in 389-ds to configure enabled ciphers ACK. Let's get 4.0.3 out the door! :) Than

Re: [Freeipa-devel] [PATCHES] 0642-0643 Move granting read access to entryusn & timestamp entries to individual permissions

2014-09-12 Thread Martin Kosek
On 09/12/2014 04:46 PM, Petr Viktorin wrote: On 09/12/2014 04:25 PM, Martin Kosek wrote: On 09/12/2014 01:53 PM, Petr Viktorin wrote: https://fedorahosted.org/freeipa/ticket/4534 The entryusn and timestamp operational attributes are now automatically added to every read permission that targets

Re: [Freeipa-devel] [PATCH] 0001 Update-SSL-ciphers-configured-in-389-ds-base

2014-09-12 Thread Martin Kosek
On 09/12/2014 04:47 PM, Martin Kosek wrote: On 09/12/2014 04:18 PM, Nathaniel McCallum wrote: On Fri, 2014-09-12 at 13:21 +0200, Ludwig Krispenz wrote: please review attached patch for ticket: https://fedorahosted.org/freeipa/ticket/4395 use new options in 389-ds to configure enabled ciphers

[Freeipa-devel] [PATCH] 0644 Update referential integrity config for DS 1.3.3

2014-09-12 Thread Petr Viktorin
https://fedorahosted.org/freeipa/ticket/4537 See commit message for the story behind this one. -- PetrĀ³ From e36ecfee32a331bfd031a48df2abe7e0ce8ec987 Mon Sep 17 00:00:00 2001 From: Petr Viktorin Date: Fri, 12 Sep 2014 17:14:14 +0200 Subject: [PATCH] Update referential integrity config for DS 1.

Re: [Freeipa-devel] [PATCH] 0644 Update referential integrity config for DS 1.3.3

2014-09-12 Thread Martin Kosek
On 09/12/2014 05:35 PM, Petr Viktorin wrote: https://fedorahosted.org/freeipa/ticket/4537 See commit message for the story behind this one. Thanks. Works as a charm, so ACK. Pushed to: master: d61fb40542abb0aa66c49d987813099fda356adf ipa-4-1: f8771db202bcca4419be847c00f167362311e28e ipa-4-0:

Re: [Freeipa-devel] [PATCH] 0644 Update referential integrity config for DS 1.3.3

2014-09-12 Thread Ludwig Krispenz
On 09/12/2014 05:43 PM, Martin Kosek wrote: On 09/12/2014 05:35 PM, Petr Viktorin wrote: https://fedorahosted.org/freeipa/ticket/4537 See commit message for the story behind this one. Thanks. Works as a charm, so ACK. just for my understanding. what was install/share/referint-conf.ldif goo

Re: [Freeipa-devel] [PATCH] 0644 Update referential integrity config for DS 1.3.3

2014-09-12 Thread Petr Viktorin
On 09/12/2014 05:47 PM, Ludwig Krispenz wrote: On 09/12/2014 05:43 PM, Martin Kosek wrote: On 09/12/2014 05:35 PM, Petr Viktorin wrote: https://fedorahosted.org/freeipa/ticket/4537 See commit message for the story behind this one. Thanks. Works as a charm, so ACK. just for my understandin

Re: [Freeipa-devel] [PATCHES] 0642-0643 Move granting read access to entryusn & timestamp entries to individual permissions

2014-09-12 Thread Petr Viktorin
On 09/12/2014 05:02 PM, Martin Kosek wrote: On 09/12/2014 04:46 PM, Petr Viktorin wrote: On 09/12/2014 04:25 PM, Martin Kosek wrote: On 09/12/2014 01:53 PM, Petr Viktorin wrote: https://fedorahosted.org/freeipa/ticket/4534 The entryusn and timestamp operational attributes are now automaticall

[Freeipa-devel] FreeIPA 4.0.3 ?

2014-09-12 Thread Petr Viktorin
There were some critical issues in 4.0.2, mainly with integration: https://fedorahosted.org/freeipa/ticket/4529 - broken upgrades https://fedorahosted.org/freeipa/ticket/4430 - python-qrcode packaging fix https://fedorahosted.org/freeipa/ticket/4395 - update of SSL ciphers https://fedorahosted.or

Re: [Freeipa-devel] FreeIPA 4.0.3 ?

2014-09-12 Thread Martin Kosek
On 09/12/2014 06:36 PM, Petr Viktorin wrote: There were some critical issues in 4.0.2, mainly with integration: https://fedorahosted.org/freeipa/ticket/4529 - broken upgrades https://fedorahosted.org/freeipa/ticket/4430 - python-qrcode packaging fix https://fedorahosted.org/freeipa/ticket/4395 -

Re: [Freeipa-devel] [PATCH] 0009 Detect and configure all usable IP addresses.

2014-09-12 Thread Martin Basti
Be careful, reviewed on friday! :-) 1) whitespace error + pep8 error patch:76: trailing whitespace. # there is reverse zone for every ip address warning: 1 line adds whitespace errors. ./ipaserver/install/bindinstance.py:640:9: E265 block comment should start with '# ' 2) (server insta

[Freeipa-devel] Announcing FreeIPA 4.0.3

2014-09-12 Thread Petr Viktorin
The FreeIPA team would like to announce FreeIPA v4.0.3 bugfix release! It can be downloaded from http://www.freeipa.org/page/Downloads. The builds will be available for Fedora 21 Beta. Builds for Fedora 20 are available in the official [https://copr.fedoraproject.org/coprs/mkosek/freeipa/ COPR