Re: [Freeipa-devel] [PATCH] 0001 Provide Kerberos over HTTP (MS-KKDCP)

2015-06-12 Thread Adam Young
On 06/12/2015 03:40 PM, Nathaniel McCallum wrote: It doesn't apply again. On Tue, 2015-06-09 at 15:55 +0200, Christian Heimes wrote: On 2015-05-27 15:16, Christian Heimes wrote: Hello, here is my first patch for FreeIPA. The patch integrates python -kdcproxy for MS-KKDCP support (aka Kerberos

Re: [Freeipa-devel] Community Portal Milestone

2015-06-12 Thread Adam Young
On 06/12/2015 03:34 PM, Drew Erny wrote: Hey, all, What fields, exactly, should a self-service user be able to enter? Thanks, Drew Erny Start with the minimum: First and Last name, email address. The userid is automatically assigned based on their name, and their is a high likelyhood

Re: [Freeipa-devel] Community Portal Milestone

2015-06-12 Thread Drew Erny
Hey, all, What fields, exactly, should a self-service user be able to enter? Thanks, Drew Erny -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Re: [Freeipa-devel] [PATCH] 0001 Provide Kerberos over HTTP (MS-KKDCP)

2015-06-12 Thread Nathaniel McCallum
It doesn't apply again. On Tue, 2015-06-09 at 15:55 +0200, Christian Heimes wrote: > On 2015-05-27 15:16, Christian Heimes wrote: > > Hello, > > > > here is my first patch for FreeIPA. The patch integrates python > > -kdcproxy > > for MS-KKDCP support (aka Kerberos over HTTPS). > > > > https://w

Re: [Freeipa-devel] [PATCH] 869 topology: restrict direction changes

2015-06-12 Thread Martin Babinsky
On 06/11/2015 01:41 PM, Petr Vobornik wrote: On 06/11/2015 01:11 PM, Ludwig Krispenz wrote: On 06/11/2015 12:53 PM, Petr Vobornik wrote: On 06/11/2015 12:35 PM, Ludwig Krispenz wrote: On 06/11/2015 12:19 PM, Petr Vobornik wrote: On 06/11/2015 10:22 AM, Martin Babinsky wrote: On 06/10/2015

Re: [Freeipa-devel] [PATCH] 875 topology: fix swapped topologysegment-reinitialize behavior

2015-06-12 Thread Martin Babinsky
On 06/12/2015 04:19 PM, Petr Vobornik wrote: setting "nsds5BeginReplicaRefresh;left" to "start" reinintializes the right node and not the left node. This patch fixes API to match the behavior. part of: https://fedorahosted.org/freeipa/ticket/4302 ACK -- Martin^3 Babinsky -- Manage your subs

Re: [Freeipa-devel] [PATCH] 873-874 ipa-replica-manage: adjust del to work with managed topology

2015-06-12 Thread Petr Vobornik
On 06/12/2015 04:45 PM, Ludwig Krispenz wrote: On 06/12/2015 04:18 PM, Petr Vobornik wrote: Some notes: 1. As mentioned in the WIP patch thread: original 'del' worked also with winsync agreements. I'm not sure why is that. Shouldn't 'disconnect' be used for winsync agreements? At least man pag

Re: [Freeipa-devel] [PATCH] 873-874 ipa-replica-manage: adjust del to work with managed topology

2015-06-12 Thread Ludwig Krispenz
On 06/12/2015 04:18 PM, Petr Vobornik wrote: Some notes: 1. As mentioned in the WIP patch thread: original 'del' worked also with winsync agreements. I'm not sure why is that. Shouldn't 'disconnect' be used for winsync agreements? At least man page says that. This patch doesn't support it if

[Freeipa-devel] [PATCH] 875 topology: fix swapped topologysegment-reinitialize behavior

2015-06-12 Thread Petr Vobornik
setting "nsds5BeginReplicaRefresh;left" to "start" reinintializes the right node and not the left node. This patch fixes API to match the behavior. part of: https://fedorahosted.org/freeipa/ticket/4302 -- Petr Vobornik From 63d7541247985a22463857110befdfc3394b25f7 Mon Sep 17 00:00:00 2001 From: P

[Freeipa-devel] [PATCH] 873-874 ipa-replica-manage: adjust del to work with managed topology

2015-06-12 Thread Petr Vobornik
Some notes: 1. As mentioned in the WIP patch thread: original 'del' worked also with winsync agreements. I'm not sure why is that. Shouldn't 'disconnect' be used for winsync agreements? At least man page says that. This patch doesn't support it if domain level > 0. Is it a blocker? Following

Re: [Freeipa-devel] DNA range distribution to replicas by default

2015-06-12 Thread Simo Sorce
- Original Message - > From: "thierry bordaz" > About the ranges, each replica has a unique replicaID, the selection of > the ranges could use this replicaID for most significant digit. This doesn't really work unless you know before hand how many replicas you have to partition the space

Re: [Freeipa-devel] DNA range distribution to replicas by default

2015-06-12 Thread thierry bordaz
On 06/12/2015 03:27 PM, Simo Sorce wrote: - Original Message - From: "Petr Spacek" To: "Simo Sorce" Cc: "freeipa-devel" , "Tomas Capek" , "Ludwig Krispenz" , "Thierry Bordaz" Sent: Friday, June 12, 2015 5:09:08 AM Subject: Re: [Freeipa-devel] DNA range distribution to replicas by def

Re: [Freeipa-devel] with new cert profiles patches ipa-replica-prepare fails after update

2015-06-12 Thread Petr Vobornik
On 06/12/2015 03:18 PM, Fraser Tweedale wrote: On Thu, Jun 11, 2015 at 09:59:03AM +0200, Martin Babinsky wrote: On 06/04/2015 04:03 PM, Petr Vobornik wrote: - ipa-replica-prepare works - old IPA server was upgraded to today's master (with Cert profiles patches) - ipa-replica-prepare fails with:

Re: [Freeipa-devel] DNA range distribution to replicas by default

2015-06-12 Thread Simo Sorce
- Original Message - > From: "Petr Spacek" > To: "Simo Sorce" > Cc: "freeipa-devel" , "Tomas Capek" > , "Ludwig Krispenz" > , "Thierry Bordaz" > Sent: Friday, June 12, 2015 5:09:08 AM > Subject: Re: [Freeipa-devel] DNA range distribution to replicas by default > > On 11.6.2015 16:11, S

Re: [Freeipa-devel] [PATCH 0264] Server Upgrade: disconnect ldap2 connection before DS restart

2015-06-12 Thread Martin Babinsky
On 06/10/2015 01:47 PM, Martin Basti wrote: Without this patch, upgrade may failed when api.Backend.ldap2 was connected before DS restart. Patch attached. ACK -- Martin^3 Babinsky -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeip

Re: [Freeipa-devel] with new cert profiles patches ipa-replica-prepare fails after update

2015-06-12 Thread Fraser Tweedale
On Thu, Jun 11, 2015 at 09:59:03AM +0200, Martin Babinsky wrote: > On 06/04/2015 04:03 PM, Petr Vobornik wrote: > >- ipa-replica-prepare works > >- old IPA server was upgraded to today's master (with Cert profiles > >patches) > >- ipa-replica-prepare fails with: > > > >Log: > > > >ipa: DEBUG: appro

Re: [Freeipa-devel] [PATCH] 0019 Server upgrade: disconnect ldap2 before DS restart

2015-06-12 Thread Fraser Tweedale
On Fri, Jun 12, 2015 at 02:17:30PM +0200, Martin Basti wrote: > On 12/06/15 14:12, Fraser Tweedale wrote: > >On Fri, Jun 12, 2015 at 10:00:18PM +1000, Fraser Tweedale wrote: > >> From eb1043521317e5759444caaedef1fd81eda55b47 Mon Sep 17 00:00:00 2001 > >>From: Fraser Tweedale > >>Date: Fri, 12 Jun

Re: [Freeipa-devel] [PATCH] 0019 Server upgrade: disconnect ldap2 before DS restart

2015-06-12 Thread Martin Basti
On 12/06/15 14:12, Fraser Tweedale wrote: On Fri, Jun 12, 2015 at 10:00:18PM +1000, Fraser Tweedale wrote: From eb1043521317e5759444caaedef1fd81eda55b47 Mon Sep 17 00:00:00 2001 From: Fraser Tweedale Date: Fri, 12 Jun 2015 07:54:23 -0400 Subject: [PATCH] Server upgrade: disconnect ldap2 before

Re: [Freeipa-devel] [PATCH] 0019 Server upgrade: disconnect ldap2 before DS restart

2015-06-12 Thread Fraser Tweedale
On Fri, Jun 12, 2015 at 10:00:18PM +1000, Fraser Tweedale wrote: > From eb1043521317e5759444caaedef1fd81eda55b47 Mon Sep 17 00:00:00 2001 > From: Fraser Tweedale > Date: Fri, 12 Jun 2015 07:54:23 -0400 > Subject: [PATCH] Server upgrade: disconnect ldap2 before DS restart > > If ldap2 is not disco

[Freeipa-devel] [PATCH] 0019 Server upgrade: disconnect ldap2 before DS restart

2015-06-12 Thread Fraser Tweedale
Attached patch fixes an upgrade issue from 4.1.4 to master. With this patch upgrade works, and ipa-replica-prepare works on upgraded server. Thanks, Fraser From eb1043521317e5759444caaedef1fd81eda55b47 Mon Sep 17 00:00:00 2001 From: Fraser Tweedale Date: Fri, 12 Jun 2015 07:54:23 -0400 Subject:

[Freeipa-devel] FreeIPA 4.2 Alpha preparations

2015-06-12 Thread Martin Kosek
Hello all, As discussed in the last 2 weeks, we are getting close to the 4.2 finish line and releasing FreeIPA 4.2 Alpha 1. We already have most of the major RFEs complete, some still miss some partial functionality, but most are testable and in Alpha state already. We need to now find out w

Re: [Freeipa-devel] DNA range distribution to replicas by default

2015-06-12 Thread Petr Spacek
On 11.6.2015 16:11, Simo Sorce wrote: > On Thu, 2015-06-11 at 12:38 +0200, Petr Spacek wrote: >> On 9.6.2015 15:06, Simo Sorce wrote: >>> On Tue, 2015-06-09 at 10:30 +0200, Petr Spacek wrote: Hello, I would like to discuss https://bugzilla.redhat.com/show_bug.cgi?id=1211366

Re: [Freeipa-devel] [PATCH] [WIP] ipa-replica-manage del with managed topology

2015-06-12 Thread Ludwig Krispenz
On 06/12/2015 10:20 AM, Petr Vobornik wrote: On 06/12/2015 09:24 AM, Ludwig Krispenz wrote: Hi Petr, On 06/11/2015 06:34 PM, Petr Vobornik wrote: Attaching a wip patch for `ipa-replica-manage del` to work with managed topology. There are two prerequisite patches, they add following commands.

Re: [Freeipa-devel] [PATCH] [WIP] ipa-replica-manage del with managed topology

2015-06-12 Thread Petr Vobornik
On 06/12/2015 09:24 AM, Ludwig Krispenz wrote: Hi Petr, On 06/11/2015 06:34 PM, Petr Vobornik wrote: Attaching a wip patch for `ipa-replica-manage del` to work with managed topology. There are two prerequisite patches, they add following commands. All commands has NO_CLI flag which means they a

Re: [Freeipa-devel] [PATCH] [WIP] ipa-replica-manage del with managed topology

2015-06-12 Thread Ludwig Krispenz
Hi Petr, On 06/11/2015 06:34 PM, Petr Vobornik wrote: Attaching a wip patch for `ipa-replica-manage del` to work with managed topology. There are two prerequisite patches, they add following commands. All commands has NO_CLI flag which means they are hidden in CLI. - server-del - serverservic