Re: [Freeipa-devel] DNS forward zone upgrade problem: post-mortem

2015-01-05 Thread Martin Basti
On 05/01/15 19:01, Simo Sorce wrote: On Mon, 05 Jan 2015 17:35:49 +0100 Martin Basti wrote: On 05/01/15 17:18, Petr Spacek wrote: Hello, as you may now, me and Martin^2 Basti screwed upgrades from RHEL 6.x to RHEL 7.1+. Cause = RHEL 7.1/bind-dyndb-ldap 6.x supports new object class idns

Re: [Freeipa-devel] [PATCH 0081] Add initial tests for OTP

2015-01-05 Thread Nathaniel McCallum
On Thu, 2014-11-20 at 11:13 -0500, Nathaniel McCallum wrote: > This tests the general workflow for OTP including most possible > token combinations. This includes 5872 tests. Further optimization > is possible to reduce the number of duplicate tests run. > > Things not yet tested: > * ipa-kdb > *

Re: [Freeipa-devel] DNS forward zone upgrade problem: post-mortem

2015-01-05 Thread Simo Sorce
On Mon, 05 Jan 2015 17:35:49 +0100 Martin Basti wrote: > On 05/01/15 17:18, Petr Spacek wrote: > > Hello, > > > > as you may now, me and Martin^2 Basti screwed upgrades from RHEL > > 6.x to RHEL 7.1+. > > > > Cause > > = > > RHEL 7.1/bind-dyndb-ldap 6.x supports new object class > > idnsForwa

Re: [Freeipa-devel] DNS forward zone upgrade problem: post-mortem

2015-01-05 Thread Martin Basti
On 05/01/15 17:18, Petr Spacek wrote: Hello, as you may now, me and Martin^2 Basti screwed upgrades from RHEL 6.x to RHEL 7.1+. Cause = RHEL 7.1/bind-dyndb-ldap 6.x supports new object class idnsForwardZone and has modified idnsZone object class semantics . This new semantics match what is

[Freeipa-devel] DNS forward zone upgrade problem: post-mortem

2015-01-05 Thread Petr Spacek
Hello, as you may now, me and Martin^2 Basti screwed upgrades from RHEL 6.x to RHEL 7.1+. Cause = RHEL 7.1/bind-dyndb-ldap 6.x supports new object class idnsForwardZone and has modified idnsZone object class semantics . This new semantics match what is called "master zones" in BIND terminolo

Re: [Freeipa-devel] SSH Public Key - Centralized Solution

2015-01-05 Thread Adam Young
On 01/05/2015 04:47 AM, Petr Vobornik wrote: Enforcing these restrictions could be solved by a 389 plugin but that requires more work (from my POV). Agreed. I don't think it can be properly done without the 389 plugin. ___ Freeipa-devel mailing list

Re: [Freeipa-devel] [PATCHES 0175-0176] New forward zone test cases

2015-01-05 Thread Martin Basti
On 17/12/14 15:15, Martin Basti wrote: On 16/12/14 17:14, Martin Basti wrote: On 15/12/14 20:15, Martin Basti wrote: On 15/12/14 19:18, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/4750 Patches need rebase and minor pytest modification to apply on master, I will do that after

Re: [Freeipa-devel] New/Updated FreeIPA design pages

2015-01-05 Thread Simo Sorce
On Mon, 05 Jan 2015 14:15:17 +0100 Martin Basti wrote: > On 15/12/14 23:01, Simo Sorce wrote: > > Hello fellow developers, I added this new design: > > http://www.freeipa.org/page/V4/Domain_Levels > > > > It is a prerequisite for both the Replica Promotion design: > > http://www.freeipa.org/page/

Re: [Freeipa-devel] New/Updated FreeIPA design pages

2015-01-05 Thread Martin Basti
On 15/12/14 23:01, Simo Sorce wrote: Hello fellow developers, I added this new design: http://www.freeipa.org/page/V4/Domain_Levels It is a prerequisite for both the Replica Promotion design: http://www.freeipa.org/page/V4/Replica_Promotion and the Topology plugins design: http://www.freeipa.org

Re: [Freeipa-devel] SSH Public Key - Centralized Solution

2015-01-05 Thread Petr Vobornik
On 12/30/2014 01:57 AM, Prashant Bapat wrote: Hi Again, For enforcing SSH key rotation every N days, I'm thinking the following. Please let me know if this makes sense. 1. Limit the number of keys per user to 2. Control this via the webUI during they public key upload. 2. Append the current tim

Re: [Freeipa-devel] SSH Public Key - Centralized Solution

2015-01-05 Thread Prashant Bapat
Ping! Any pointers for doing this would be appreciated. On 30 December 2014 at 06:27, Prashant Bapat wrote: > Hi Again, > > For enforcing SSH key rotation every N days, I'm thinking the following. > Please let me know if this makes sense. > > 1. Limit the number of keys per user to 2. Control t

Re: [Freeipa-devel] Modifying ID Range

2015-01-05 Thread Sumit Bose
On Wed, Dec 24, 2014 at 08:50:29AM +0530, Prashant Bapat wrote: > Hi, > > What I'm trying to do is to modify the Range FreeIPA uses. I removed the > random Range Id created during install, added a new range that I wanted. > But problem is when I try to add a new user or a group now its still using