Re: [Freeipa-devel] [PATCH] 0009 Detect and configure all usable IP addresses.

2014-09-26 Thread David Kupka
On 09/25/2014 04:17 PM, David Kupka wrote: On 09/24/2014 08:54 PM, Martin Basti wrote: On 24/09/14 15:44, David Kupka wrote: On 09/23/2014 08:25 PM, Martin Basti wrote: On 23/09/14 13:23, David Kupka wrote: On 09/18/2014 06:34 PM, Martin Basti wrote: ... 1) +if options.unattended: +

Re: [Freeipa-devel] [PATCH] 0009 Detect and configure all usable IP addresses.

2014-09-26 Thread Jan Cholasta
Dne 26.9.2014 v 08:28 David Kupka napsal(a): On 09/25/2014 04:17 PM, David Kupka wrote: On 09/24/2014 08:54 PM, Martin Basti wrote: On 24/09/14 15:44, David Kupka wrote: On 09/23/2014 08:25 PM, Martin Basti wrote: On 23/09/14 13:23, David Kupka wrote: On 09/18/2014 06:34 PM, Martin Basti

Re: [Freeipa-devel] [PATCH] 0010 Add 'host' setting into default.conf configuration file

2014-09-26 Thread Martin Kosek
On 09/02/2014 10:18 AM, Jan Cholasta wrote: Dne 27.8.2014 v 16:49 David Kupka napsal(a): On 08/27/2014 11:22 AM, Jan Cholasta wrote: Dne 26.8.2014 v 15:55 Rob Crittenden napsal(a): David Kupka wrote: On 08/26/2014 03:08 PM, Jan Cholasta wrote: Hi, Dne 26.8.2014 v 13:01 David Kupka

Re: [Freeipa-devel] [PATCHES 0114-0115] DNS: allow to add root zone '.'

2014-09-26 Thread Martin Basti
On 25/09/14 17:13, Martin Kosek wrote: On 09/25/2014 04:39 PM, Petr Viktorin wrote: On 09/25/2014 04:32 PM, Petr Spacek wrote: On 25.9.2014 10:31, Martin Basti wrote: On 24/09/14 16:24, Martin Basti wrote: On 24/09/14 16:05, Martin Basti wrote: On 23/09/14 17:45, Petr Vobornik wrote: On

Re: [Freeipa-devel] [PATCHES 0114-0115] DNS: allow to add root zone '.'

2014-09-26 Thread Martin Kosek
On 09/26/2014 10:20 AM, Martin Basti wrote: On 25/09/14 17:13, Martin Kosek wrote: On 09/25/2014 04:39 PM, Petr Viktorin wrote: On 09/25/2014 04:32 PM, Petr Spacek wrote: On 25.9.2014 10:31, Martin Basti wrote: On 24/09/14 16:24, Martin Basti wrote: On 24/09/14 16:05, Martin Basti wrote:

Re: [Freeipa-devel] [PATCH] 0009 Detect and configure all usable IP addresses.

2014-09-26 Thread David Kupka
On 09/26/2014 09:34 AM, Jan Cholasta wrote: Dne 26.9.2014 v 08:28 David Kupka napsal(a): On 09/25/2014 04:17 PM, David Kupka wrote: On 09/24/2014 08:54 PM, Martin Basti wrote: On 24/09/14 15:44, David Kupka wrote: On 09/23/2014 08:25 PM, Martin Basti wrote: On 23/09/14 13:23, David Kupka

Re: [Freeipa-devel] [PATCHES] 0633-0634 Move setting SELinux booleans to platform code; Set SELinux booleans when restoring

2014-09-26 Thread Martin Kosek
On 09/25/2014 11:34 AM, thierry bordaz wrote: On 09/25/2014 10:58 AM, Petr Viktorin wrote: On 09/24/2014 06:02 PM, thierry bordaz wrote: On 08/15/2014 10:40 PM, Petr Viktorin wrote: A fix for https://fedorahosted.org/freeipa/ticket/4157 This depends on my patches 0631-0632 (for

Re: [Freeipa-devel] [PATCH] 129 ipa-kdb: fix unit tests

2014-09-26 Thread Martin Kosek
On 09/24/2014 01:38 PM, Jakub Hrozek wrote: On Tue, Jul 22, 2014 at 05:24:51PM +0200, Sumit Bose wrote: Hi, it looks like the ipa-kdb unit test is broken. This patch tries to fix it. bye, Sumit ACK ... Pushed to: master: 757272a3f818e85e7f0b88060efbcd76d3a93f8b ipa-4-1:

Re: [Freeipa-devel] [PATCH] 0637 upgradeinstance: Restore listeners on failure

2014-09-26 Thread Martin Kosek
On 09/25/2014 01:24 PM, Martin Kosek wrote: On 09/24/2014 10:43 AM, Martin Kosek wrote: On 08/22/2014 06:07 PM, Petr Viktorin wrote: https://fedorahosted.org/freeipa/ticket/4499 Actually I wonder why we use backup_state/restore_state for these settings. Rob, was there a reason for not just

Re: [Freeipa-devel] [PATCHES] 0633-0634 Move setting SELinux booleans to platform code; Set SELinux booleans when restoring

2014-09-26 Thread thierry bordaz
On 09/26/2014 11:23 AM, Martin Kosek wrote: On 09/25/2014 11:34 AM, thierry bordaz wrote: On 09/25/2014 10:58 AM, Petr Viktorin wrote: On 09/24/2014 06:02 PM, thierry bordaz wrote: On 08/15/2014 10:40 PM, Petr Viktorin wrote: A fix for https://fedorahosted.org/freeipa/ticket/4157 This

Re: [Freeipa-devel] [PATCH] 314 Allow specifying key algorithm of the IPA CA cert in ipa-server-install

2014-09-26 Thread Martin Kosek
On 09/23/2014 11:46 AM, Jan Cholasta wrote: Dne 6.8.2014 v 18:17 Jan Cholasta napsal(a): Dne 6.8.2014 v 14:43 Rob Crittenden napsal(a): Jan Cholasta wrote: Hi, the attached patch fixes https://fedorahosted.org/freeipa/ticket/4447. +cert_group.add_option(--ca-key-algorithm,

Re: [Freeipa-devel] [PATCHES] 0633-0634 Move setting SELinux booleans to platform code; Set SELinux booleans when restoring

2014-09-26 Thread Martin Kosek
On 09/26/2014 11:57 AM, thierry bordaz wrote: On 09/26/2014 11:23 AM, Martin Kosek wrote: On 09/25/2014 11:34 AM, thierry bordaz wrote: On 09/25/2014 10:58 AM, Petr Viktorin wrote: On 09/24/2014 06:02 PM, thierry bordaz wrote: On 08/15/2014 10:40 PM, Petr Viktorin wrote: A fix for

Re: [Freeipa-devel] [PATCH 0116] Refactoring of service autobind

2014-09-26 Thread Martin Kosek
On 09/25/2014 03:06 PM, Martin Basti wrote: On 25/09/14 14:47, Jan Cholasta wrote: Dne 25.9.2014 v 10:51 Martin Basti napsal(a): On 19/09/14 14:30, Jan Cholasta wrote: Dne 19.9.2014 v 13:32 Martin Basti napsal(a): On 01/09/14 16:26, Martin Basti wrote: On 28/08/14 14:01, Jan Cholasta wrote:

Re: [Freeipa-devel] [PATCH 0118] Allow to disable service (in LDAP)

2014-09-26 Thread Martin Kosek
On 09/25/2014 05:14 PM, Jan Cholasta wrote: Dne 25.9.2014 v 16:15 Martin Basti napsal(a): On 22/09/14 19:30, Martin Basti wrote: On 19/09/14 14:47, Jan Cholasta wrote: Dne 19.9.2014 v 13:33 Martin Basti napsal(a): On 02/09/14 11:59, Martin Basti wrote: On 02/09/14 09:10, Jan Cholasta wrote:

Re: [Freeipa-devel] [PATCH] 0010 Add 'host' setting into default.conf configuration file

2014-09-26 Thread David Kupka
On 09/26/2014 09:56 AM, Martin Kosek wrote: On 09/02/2014 10:18 AM, Jan Cholasta wrote: Dne 27.8.2014 v 16:49 David Kupka napsal(a): On 08/27/2014 11:22 AM, Jan Cholasta wrote: Dne 26.8.2014 v 15:55 Rob Crittenden napsal(a): David Kupka wrote: On 08/26/2014 03:08 PM, Jan Cholasta wrote:

Re: [Freeipa-devel] [PATCH] 314 Allow specifying key algorithm of the IPA CA cert in ipa-server-install

2014-09-26 Thread Jan Cholasta
Dne 26.9.2014 v 12:02 Martin Kosek napsal(a): On 09/23/2014 11:46 AM, Jan Cholasta wrote: Dne 6.8.2014 v 18:17 Jan Cholasta napsal(a): Dne 6.8.2014 v 14:43 Rob Crittenden napsal(a): Jan Cholasta wrote: Hi, the attached patch fixes https://fedorahosted.org/freeipa/ticket/4447. +

Re: [Freeipa-devel] [PATCH] 0010 Add 'host' setting into default.conf configuration file

2014-09-26 Thread Martin Kosek
On 09/26/2014 01:37 PM, David Kupka wrote: On 09/26/2014 09:56 AM, Martin Kosek wrote: On 09/02/2014 10:18 AM, Jan Cholasta wrote: Dne 27.8.2014 v 16:49 David Kupka napsal(a): On 08/27/2014 11:22 AM, Jan Cholasta wrote: Dne 26.8.2014 v 15:55 Rob Crittenden napsal(a): David Kupka wrote: On

Re: [Freeipa-devel] [PATCHES] 336-339 Installer certificate options usability fixes

2014-09-26 Thread Jan Cholasta
Dne 24.9.2014 v 18:13 Jan Cholasta napsal(a): Hi, the attached patches fix https://fedorahosted.org/freeipa/ticket/4480 and https://fedorahosted.org/freeipa/ticket/4489. (Note that design page for this is TBD.) Honza Polished the code up a bit and rebased on top of current ipa-4-1. Updated

Re: [Freeipa-devel] [PATCH] 314 Allow specifying key algorithm of the IPA CA cert in ipa-server-install

2014-09-26 Thread Martin Kosek
On 09/26/2014 01:41 PM, Jan Cholasta wrote: Dne 26.9.2014 v 12:02 Martin Kosek napsal(a): On 09/23/2014 11:46 AM, Jan Cholasta wrote: Dne 6.8.2014 v 18:17 Jan Cholasta napsal(a): Dne 6.8.2014 v 14:43 Rob Crittenden napsal(a): Jan Cholasta wrote: Hi, the attached patch fixes

Re: [Freeipa-devel] [PATCH] 0009 Detect and configure all usable IP addresses.

2014-09-26 Thread David Kupka
On 09/26/2014 10:30 AM, David Kupka wrote: On 09/26/2014 09:34 AM, Jan Cholasta wrote: Dne 26.9.2014 v 08:28 David Kupka napsal(a): On 09/25/2014 04:17 PM, David Kupka wrote: On 09/24/2014 08:54 PM, Martin Basti wrote: On 24/09/14 15:44, David Kupka wrote: On 09/23/2014 08:25 PM, Martin

Re: [Freeipa-devel] [PATCH][DOC] Update Solaris Documentation, add proxy agent, and profile

2014-09-26 Thread Gabe Alford
Hello, Just wondering if we have found a reviewer for this patch set? It would be nice to have this as a part of the docs. Thanks, Gabe On Wed, Apr 16, 2014 at 5:13 AM, Petr Spacek pspa...@redhat.com wrote: On 16.4.2014 05:01, Gabe Alford wrote: The following patches update the

Re: [Freeipa-devel] [PATCH][DOC] Update Solaris Documentation, add proxy agent, and profile

2014-09-26 Thread Martin Kosek
I saw a similar interest on freeipa-users list in FreeIPA 3.3 and Solaris 10 Client Integration: thread. Also note it is proposed to only have the guide maintained in the downstream guide in [Freeipa-users] What should we do with upstream guide? thread (I know you know about it). So it is

[Freeipa-devel] [PATCH] 0001 Refactor selinuxenabled check

2014-09-26 Thread Francesco Marella
From 81d3d673944fc61de4616b5572d24719637d1d50 Mon Sep 17 00:00:00 2001 From: Francesco Marella fmare...@gmx.com Date: Fri, 26 Sep 2014 14:07:25 +0200 Subject: [PATCH] Refactor selinuxenabled check Ticket: https://fedorahosted.org/freeipa/ticket/4571 --- ipaplatform/fedora/tasks.py | 44

Re: [Freeipa-devel] [PATCH] 0001 Refactor selinuxenabled check

2014-09-26 Thread Petr Viktorin
Hello! Thanks for the patch! The new function is not one of the platform-independent tasks, and doesn't even use `self`, so you can define it as a module-level helper function. But more importantly, this won't work: the blocks you are replacing return from their functions. You'd need to

Re: [Freeipa-devel] [PATCH] 0001 Refactor selinuxenabled check

2014-09-26 Thread thierry bordaz
On 09/26/2014 03:35 PM, Francesco Marella wrote: ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel Hello, I think that if we want to keep the same previous behaviour, then if

Re: [Freeipa-devel] [PATCH][DOC] Update Solaris Documentation, add proxy agent, and profile

2014-09-26 Thread Gabe Alford
If we can, let's try to push the doc patch 0014 downstream (except for patch 0015 as that patch is an ldif update). Gabe On Fri, Sep 26, 2014 at 7:16 AM, Martin Kosek mko...@redhat.com wrote: I saw a similar interest on freeipa-users list in FreeIPA 3.3 and Solaris 10 Client Integration:

Re: [Freeipa-devel] [PATCH] 0637 upgradeinstance: Restore listeners on failure

2014-09-26 Thread Petr Viktorin
On 09/26/2014 11:46 AM, Martin Kosek wrote: On 09/25/2014 01:24 PM, Martin Kosek wrote: On 09/24/2014 10:43 AM, Martin Kosek wrote: On 08/22/2014 06:07 PM, Petr Viktorin wrote: https://fedorahosted.org/freeipa/ticket/4499 Actually I wonder why we use backup_state/restore_state for these

Re: [Freeipa-devel] [PATCH] 0001 Refactor selinuxenabled check

2014-09-26 Thread Francesco Marella
On 26/09/2014 15:41, Petr Viktorin wrote: Hello! Thanks for the patch! The new function is not one of the platform-independent tasks, and doesn't even use `self`, so you can define it as a module-level helper function. But more importantly, this won't work: the blocks you are replacing

Re: [Freeipa-devel] [PATCH] 314 Allow specifying key algorithm of the IPA CA cert in ipa-server-install

2014-09-26 Thread Simo Sorce
On Fri, 26 Sep 2014 13:54:34 +0200 Martin Kosek mko...@redhat.com wrote: I tested the patch (it works fine with Dogtag 10), but I got very confused. What CA option are we setting? Signing algorithm or Key Algorithm? I thought we are only setting Signing algorithm, but in that case:

Re: [Freeipa-devel] [PATCH] 0637 upgradeinstance: Restore listeners on failure

2014-09-26 Thread Martin Kosek
On 09/26/2014 04:14 PM, Petr Viktorin wrote: On 09/26/2014 11:46 AM, Martin Kosek wrote: On 09/25/2014 01:24 PM, Martin Kosek wrote: On 09/24/2014 10:43 AM, Martin Kosek wrote: On 08/22/2014 06:07 PM, Petr Viktorin wrote: https://fedorahosted.org/freeipa/ticket/4499 Actually I wonder why we

Re: [Freeipa-devel] [PATCH] 0009 Detect and configure all usable IP addresses.

2014-09-26 Thread David Kupka
On 09/26/2014 02:47 PM, David Kupka wrote: On 09/26/2014 10:30 AM, David Kupka wrote: On 09/26/2014 09:34 AM, Jan Cholasta wrote: Dne 26.9.2014 v 08:28 David Kupka napsal(a): On 09/25/2014 04:17 PM, David Kupka wrote: On 09/24/2014 08:54 PM, Martin Basti wrote: On 24/09/14 15:44, David

Re: [Freeipa-devel] [PATCHES] 336-339 Installer certificate options usability fixes

2014-09-26 Thread Petr Viktorin
On 09/24/2014 06:13 PM, Jan Cholasta wrote: Hi, the attached patches fix https://fedorahosted.org/freeipa/ticket/4480 and https://fedorahosted.org/freeipa/ticket/4489. (Note that design page for this is TBD.) Honza 336: Instead of len(data[:match.start() + 1].splitlines()) you can do

Re: [Freeipa-devel] [PATCHES] 319, 324-335 CA management and renewal fixes

2014-09-26 Thread Rob Crittenden
Jan Cholasta wrote: Dne 23.9.2014 v 20:39 Rob Crittenden napsal(a): Jan Cholasta wrote: Hi, the attached patches fix various bugs and shortcomings in the CA management and renewal code. Related tickets: https://fedorahosted.org/freeipa/ticket/4416,

Re: [Freeipa-devel] [PATCH] 0001 Refactor selinuxenabled check

2014-09-26 Thread Francesco Marella
This should be the final one. fm On 26/09/2014 16:30, Francesco Marella wrote: On 26/09/2014 15:41, Petr Viktorin wrote: Hello! Thanks for the patch! The new function is not one of the platform-independent tasks, and doesn't even use `self`, so you can define it as a module-level helper

Re: [Freeipa-devel] [PATCHES] 336-339 Installer certificate options usability fixes

2014-09-26 Thread Rob Crittenden
Petr Viktorin wrote: On 09/24/2014 06:13 PM, Jan Cholasta wrote: Hi, the attached patches fix https://fedorahosted.org/freeipa/ticket/4480 and https://fedorahosted.org/freeipa/ticket/4489. (Note that design page for this is TBD.) Isn't this backwards then? 336: Instead of

Re: [Freeipa-devel] [PATCH] 749-754 webui: new ID views section

2014-09-26 Thread Petr Vobornik
On 25.9.2014 19:07, Petr Vobornik wrote: All issues will be done separately as already stated in other sub-thread. I've removed issues which are discussed in the other sub-thread. 2. The tab titles in the ID view details page are quite long, and the User ID overrides and Group ID overrides

Re: [Freeipa-devel] [PATCH] 0001 Refactor selinuxenabled check

2014-09-26 Thread thierry bordaz
Hello, When called from set_selinux_booleans, if not selinux_enabled, you may want to 'return False' rather than 'return'. Now it looks like callers of set_selinux_booleans do not check the returned value :-) thanks thierry On 09/26/2014 05:26 PM, Francesco Marella wrote:

Re: [Freeipa-devel] [PATCH] 0009 Detect and configure all usable IP addresses.

2014-09-26 Thread Martin Basti
On 26/09/14 14:47, David Kupka wrote: On 09/26/2014 10:30 AM, David Kupka wrote: On 09/26/2014 09:34 AM, Jan Cholasta wrote: Dne 26.9.2014 v 08:28 David Kupka napsal(a): On 09/25/2014 04:17 PM, David Kupka wrote: On 09/24/2014 08:54 PM, Martin Basti wrote: On 24/09/14 15:44, David Kupka

Re: [Freeipa-devel] [PATCH] 0001 Refactor selinuxenabled check

2014-09-26 Thread Francesco Marella
On 26/09/2014 17:43, thierry bordaz wrote: Hello, When called from set_selinux_booleans, if not selinux_enabled, you may want to 'return False' rather than 'return'. Now it looks like callers of set_selinux_booleans do not check the returned value :-) thanks thierry

Re: [Freeipa-devel] [PATCH] 0009 Detect and configure all usable IP addresses.

2014-09-26 Thread David Kupka
On 09/26/2014 05:50 PM, Martin Basti wrote: On 26/09/14 14:47, David Kupka wrote: On 09/26/2014 10:30 AM, David Kupka wrote: On 09/26/2014 09:34 AM, Jan Cholasta wrote: Dne 26.9.2014 v 08:28 David Kupka napsal(a): On 09/25/2014 04:17 PM, David Kupka wrote: On 09/24/2014 08:54 PM, Martin

Re: [Freeipa-devel] [PATCH] 0009 Detect and configure all usable IP addresses.

2014-09-26 Thread Martin Kosek
On 09/26/2014 05:50 PM, Martin Basti wrote: On 26/09/14 14:47, David Kupka wrote: On 09/26/2014 10:30 AM, David Kupka wrote: On 09/26/2014 09:34 AM, Jan Cholasta wrote: Dne 26.9.2014 v 08:28 David Kupka napsal(a): On 09/25/2014 04:17 PM, David Kupka wrote: On 09/24/2014 08:54 PM, Martin

Re: [Freeipa-devel] [PATCH] 0001 Refactor selinuxenabled check

2014-09-26 Thread thierry bordaz
On 09/26/2014 05:53 PM, Francesco Marella wrote: On 26/09/2014 17:43, thierry bordaz wrote: Hello, When called from set_selinux_booleans, if not selinux_enabled, you may want to 'return False' rather than 'return'. Now it looks like callers of set_selinux_booleans do not check

Re: [Freeipa-devel] [PATCHES] 319, 324-335 CA management and renewal fixes

2014-09-26 Thread Jan Cholasta
Dne 26.9.2014 v 17:13 Rob Crittenden napsal(a): Jan Cholasta wrote: Dne 23.9.2014 v 20:39 Rob Crittenden napsal(a): Jan Cholasta wrote: Hi, the attached patches fix various bugs and shortcomings in the CA management and renewal code. Related tickets:

Re: [Freeipa-devel] [PATCHES] 336-339 Installer certificate options usability fixes

2014-09-26 Thread Jan Cholasta
Dne 26.9.2014 v 17:37 Rob Crittenden napsal(a): Petr Viktorin wrote: On 09/24/2014 06:13 PM, Jan Cholasta wrote: Hi, the attached patches fix https://fedorahosted.org/freeipa/ticket/4480 and https://fedorahosted.org/freeipa/ticket/4489. (Note that design page for this is TBD.) Isn't this