Re: [Freeipa-devel] [PATCH] 005 Deadlock in schema compat plugin (between automember_update_membership task and dse update)

2014-11-06 Thread Petr Vobornik
On 5.11.2014 21:11, Alexander Bokovoy wrote: On Wed, 05 Nov 2014, Martin Basti wrote: +remove: schema-compat-ignore-subtree: o=ipaca +add: schema-compat-restrict-subtree: '$SUFFIX' +add: schema-compat-restrict-subtree: 'cn=Schema Compatibility,cn=plugins,cn=config' dn: cn=Schema

Re: [Freeipa-devel] [PATCH] 005 Deadlock in schema compat plugin (between automember_update_membership task and dse update)

2014-11-06 Thread thierry bordaz
On 11/06/2014 09:40 AM, Petr Vobornik wrote: On 5.11.2014 21:11, Alexander Bokovoy wrote: On Wed, 05 Nov 2014, Martin Basti wrote: +remove: schema-compat-ignore-subtree: o=ipaca +add: schema-compat-restrict-subtree: '$SUFFIX' +add: schema-compat-restrict-subtree: 'cn=Schema

Re: [Freeipa-devel] [PATCH] 0026 Stop dirsrv last in ipactl stop.

2014-11-06 Thread Jan Cholasta
Hi, Dne 4.11.2014 v 12:57 David Kupka napsal(a): https://fedorahosted.org/freeipa/ticket/4632 Thanks, ACK. Honza -- Jan Cholasta ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-devel

Re: [Freeipa-devel] [PATCH] 005 Deadlock in schema compat plugin (between automember_update_membership task and dse update)

2014-11-06 Thread Alexander Bokovoy
On Thu, 06 Nov 2014, thierry bordaz wrote: On 11/06/2014 09:40 AM, Petr Vobornik wrote: On 5.11.2014 21:11, Alexander Bokovoy wrote: On Wed, 05 Nov 2014, Martin Basti wrote: +remove: schema-compat-ignore-subtree: o=ipaca +add: schema-compat-restrict-subtree: '$SUFFIX' +add:

Re: [Freeipa-devel] [PATCH 0156] Fix upgrade: create new connection after restarting DS

2014-11-06 Thread Jan Cholasta
Hi, Dne 4.11.2014 v 16:29 Martin Basti napsal(a): On 04/11/14 16:08, Martin Basti wrote: Ticket: https://fedorahosted.org/freeipa/ticket/4670 Patch attached I forgot to mention, this is an ancient bug, IMO the fix should go to all branches. Thanks, ACK. Honza -- Jan Cholasta

Re: [Freeipa-devel] [PATCH] 0026 Stop dirsrv last in ipactl stop.

2014-11-06 Thread Petr Vobornik
On 6.11.2014 10:32, Jan Cholasta wrote: Hi, Dne 4.11.2014 v 12:57 David Kupka napsal(a): https://fedorahosted.org/freeipa/ticket/4632 Thanks, ACK. Honza Pushed to: master: 9335552418e515cd97da549da403447e5cae842c ipa-4-1: 25abb1154b7b9b6164612f624143bc583e896b12 -- Petr Vobornik

Re: [Freeipa-devel] [PATCH 0156] Fix upgrade: create new connection after restarting DS

2014-11-06 Thread Petr Vobornik
On 6.11.2014 10:42, Jan Cholasta wrote: Hi, Dne 4.11.2014 v 16:29 Martin Basti napsal(a): On 04/11/14 16:08, Martin Basti wrote: Ticket: https://fedorahosted.org/freeipa/ticket/4670 Patch attached I forgot to mention, this is an ancient bug, IMO the fix should go to all branches.

Re: [Freeipa-devel] [PATCH] 005 Deadlock in schema compat plugin (between automember_update_membership task and dse update)

2014-11-06 Thread Petr Vobornik
On 6.11.2014 10:41, Alexander Bokovoy wrote: On Thu, 06 Nov 2014, thierry bordaz wrote: On 11/06/2014 09:40 AM, Petr Vobornik wrote: On 5.11.2014 21:11, Alexander Bokovoy wrote: On Wed, 05 Nov 2014, Martin Basti wrote: +remove: schema-compat-ignore-subtree: o=ipaca +add:

Re: [Freeipa-devel] [PATCH 0076] Ensure that a password exists after OTP validation

2014-11-06 Thread Petr Vobornik
On 5.11.2014 21:22, Alexander Bokovoy wrote: On Wed, 05 Nov 2014, Nathaniel McCallum wrote: Before this patch users could log in using only the OTP value. This arose because ipapwd_authentication() successfully determined that an empty password was invalid, but 389 itself would see this as an

Re: [Freeipa-devel] [PATCH 0076] Ensure that a password exists after OTP validation

2014-11-06 Thread thierry bordaz
On 11/05/2014 09:14 PM, Nathaniel McCallum wrote: Before this patch users could log in using only the OTP value. This arose because ipapwd_authentication() successfully determined that an empty password was invalid, but 389 itself would see this as an anonymous bind. An anonymous bind would

Re: [Freeipa-devel] [PATCH 0076] Ensure that a password exists after OTP validation

2014-11-06 Thread Alexander Bokovoy
On Thu, 06 Nov 2014, thierry bordaz wrote: On 11/05/2014 09:14 PM, Nathaniel McCallum wrote: Before this patch users could log in using only the OTP value. This arose because ipapwd_authentication() successfully determined that an empty password was invalid, but 389 itself would see this as an

Re: [Freeipa-devel] [PATCH 0076] Ensure that a password exists after OTP validation

2014-11-06 Thread thierry bordaz
On 11/06/2014 12:35 PM, Alexander Bokovoy wrote: On Thu, 06 Nov 2014, thierry bordaz wrote: On 11/05/2014 09:14 PM, Nathaniel McCallum wrote: Before this patch users could log in using only the OTP value. This arose because ipapwd_authentication() successfully determined that an empty password

Re: [Freeipa-devel] [PATCH 0156] Fix upgrade: create new connection after restarting DS

2014-11-06 Thread Martin Basti
On 06/11/14 10:46, Petr Vobornik wrote: On 6.11.2014 10:42, Jan Cholasta wrote: Hi, Dne 4.11.2014 v 16:29 Martin Basti napsal(a): On 04/11/14 16:08, Martin Basti wrote: Ticket: https://fedorahosted.org/freeipa/ticket/4670 Patch attached I forgot to mention, this is an ancient bug, IMO

[Freeipa-devel] [PATCH] 0169 Update slapi-nis dependency to 0.54.1

2014-11-06 Thread Alexander Bokovoy
Hi! I've released slapi-nis 0.54.1 to add LDAP BIND support for ID overrides in schema compat plugin and to ignore searches of the overrides themselves outside of the schema compat subtrees. FreeIPA 4.1 and later should depend on this version. I've pushed package updates to rawhide and F21, the

Re: [Freeipa-devel] [PATCH 0076] Ensure that a password exists after OTP validation

2014-11-06 Thread Alexander Bokovoy
On Thu, 06 Nov 2014, thierry bordaz wrote: On 11/06/2014 12:35 PM, Alexander Bokovoy wrote: On Thu, 06 Nov 2014, thierry bordaz wrote: On 11/05/2014 09:14 PM, Nathaniel McCallum wrote: Before this patch users could log in using only the OTP value. This arose because ipapwd_authentication()

Re: [Freeipa-devel] [PATCH 0076] Ensure that a password exists after OTP validation

2014-11-06 Thread thierry bordaz
On 11/06/2014 02:14 PM, Alexander Bokovoy wrote: On Thu, 06 Nov 2014, thierry bordaz wrote: On 11/06/2014 12:35 PM, Alexander Bokovoy wrote: On Thu, 06 Nov 2014, thierry bordaz wrote: On 11/05/2014 09:14 PM, Nathaniel McCallum wrote: Before this patch users could log in using only the OTP

Re: [Freeipa-devel] Releasing testing tools as standalone projects

2014-11-06 Thread Petr Viktorin
On 11/03/2014 04:07 PM, Petr Viktorin wrote: Hello! There's been some interest in releasing pieces of FreeIPA's testing infrastructure so it can be reused in other projects. I will soon take the pytest-beakerlib plugin (currently in my patch 0672), and making a stand-alone project out of it.

[Freeipa-devel] [PATCH 0285] specfile: Add BuildRequires for pki-base 10.2.1-0

2014-11-06 Thread Tomas Babej
Hi, this solves the build errors we've been seeing recently on master branch. https://fedorahosted.org/freeipa/ticket/4688 Copr for pki-base 10.2.1-0 is available here: http://copr.fedoraproject.org/coprs/edewata/pki/ -- Tomas Babej Associate Software Engineer | Red Hat | Identity Management

Re: [Freeipa-devel] Releasing testing tools as standalone projects

2014-11-06 Thread Scott Poore
- Original Message - From: Petr Viktorin pvikt...@redhat.com To: freeipa-devel@redhat.com Sent: Thursday, November 6, 2014 7:29:31 AM Subject: Re: [Freeipa-devel] Releasing testing tools as standalone projects On 11/03/2014 04:07 PM, Petr Viktorin wrote: Hello! There's been

[Freeipa-devel] Announcing FreeIPA 4.0.5

2014-11-06 Thread Petr Vobornik
The FreeIPA team would like to announce FreeIPA v4.0.5 security release! It can be downloaded from http://www.freeipa.org/page/Downloads. Builds for Fedora 21 are available in the official [https://copr.fedoraproject.org/coprs/mkosek/freeipa-4.0/ COPR repository]. == Highlights in 4.0.5 ==

[Freeipa-devel] Announcing FreeIPA 4.1.1

2014-11-06 Thread Petr Vobornik
The FreeIPA team would like to announce FreeIPA v4.1.1 security release! It can be downloaded from http://www.freeipa.org/page/Downloads. The builds will be available for Fedora 21. Builds for Fedora 20 are available in the official COPR repository

Re: [Freeipa-devel] [PATCH 0074] Make token window sizes configurable

2014-11-06 Thread Nathaniel McCallum
On Tue, 2014-11-04 at 11:17 -0500, Nathaniel McCallum wrote: On Wed, 2014-10-29 at 09:34 -0400, Nathaniel McCallum wrote: On Wed, 2014-10-29 at 12:21 +0100, Petr Viktorin wrote: On 10/29/2014 10:37 AM, Martin Kosek wrote: On 10/28/2014 09:59 PM, Nathaniel McCallum wrote: On Thu,

[Freeipa-devel] [PATCH 0077] Improve otptoken help messages

2014-11-06 Thread Nathaniel McCallum
https://fedorahosted.org/freeipa/ticket/4689 From 46e9f334afa0a640f5d772e754b047124b75bc41 Mon Sep 17 00:00:00 2001 From: Nathaniel McCallum npmccal...@redhat.com Date: Thu, 6 Nov 2014 15:19:01 -0500 Subject: [PATCH] Improve otptoken help messages https://fedorahosted.org/freeipa/ticket/4689 ---

[Freeipa-devel] [PATCH 0078] Enable QR code display by default in otptoken-add

2014-11-06 Thread Nathaniel McCallum
This is possible because python-qrcode's output now fits in a standard terminal. Also, update ipa-otp-import and otptoken-add-yubikey to disable QR code output as it doesn't make sense in these contexts. https://fedorahosted.org/freeipa/ticket/4703 From 86d9c7f6ec82db1c4b29e97c0529970e888d7bb8

[Freeipa-devel] [PATCH] 1110 fix search scope

2014-11-06 Thread Rob Crittenden
The wrong search scope was being used to determine if a given master had a CA installed during ipa-csreplica-manage connect. rob From 103d1ef5c7317e6efc9a0513a2a69d0bb23a1384 Mon Sep 17 00:00:00 2001 From: Rob Crittenden rcrit...@redhat.com Date: Thu, 6 Nov 2014 16:10:01 -0500 Subject: [PATCH]

Re: [Freeipa-devel] [PATCH] 1110 fix search scope

2014-11-06 Thread Nathaniel McCallum
On Thu, 2014-11-06 at 16:16 -0500, Rob Crittenden wrote: The wrong search scope was being used to determine if a given master had a CA installed during ipa-csreplica-manage connect. ACK ___ Freeipa-devel mailing list Freeipa-devel@redhat.com

Re: [Freeipa-devel] [PATCH 0019] Prefer TCP connections to UDP in krb5 clients

2014-11-06 Thread Nathaniel McCallum
On Fri, 2013-10-04 at 06:12 -0400, Simo Sorce wrote: - Original Message - On 3.10.2013 23:43, Nathaniel McCallum wrote: Patch attached. I'm curious - what is the purpose of this patch? To prevent 1 second timeouts and re-transmits when OTP is in place? What is the

Re: [Freeipa-devel] [PATCH 0019] Prefer TCP connections to UDP in krb5 clients

2014-11-06 Thread Simo Sorce
On Thu, 06 Nov 2014 18:00:21 -0500 Nathaniel McCallum npmccal...@redhat.com wrote: On Fri, 2013-10-04 at 06:12 -0400, Simo Sorce wrote: - Original Message - On 3.10.2013 23:43, Nathaniel McCallum wrote: Patch attached. I'm curious - what is the purpose of this patch?

Re: [Freeipa-devel] [PATCH 0019] Prefer TCP connections to UDP in krb5 clients

2014-11-06 Thread Martin Kosek
On 11/07/2014 01:46 AM, Simo Sorce wrote: On Thu, 06 Nov 2014 18:00:21 -0500 Nathaniel McCallum npmccal...@redhat.com wrote: On Fri, 2013-10-04 at 06:12 -0400, Simo Sorce wrote: - Original Message - On 3.10.2013 23:43, Nathaniel McCallum wrote: Patch attached. I'm curious - what

Re: [Freeipa-devel] [PATCH 0156] Fix upgrade: create new connection after restarting DS

2014-11-06 Thread Martin Kosek
On 11/06/2014 02:11 PM, Martin Basti wrote: On 06/11/14 10:46, Petr Vobornik wrote: On 6.11.2014 10:42, Jan Cholasta wrote: Hi, Dne 4.11.2014 v 16:29 Martin Basti napsal(a): On 04/11/14 16:08, Martin Basti wrote: Ticket: https://fedorahosted.org/freeipa/ticket/4670 Patch attached I