Re: [Freeipa-devel] [PATCH 0011] Move freeipa certmonger helpers to libexecdir.

2016-02-25 Thread Jan Cholasta
On 25.2.2016 14:13, David Kupka wrote: On 24/02/16 15:07, Rob Crittenden wrote: David Kupka wrote: On 23/02/16 16:41, Rob Crittenden wrote: David Kupka wrote: On 23/02/16 10:14, Martin Kosek wrote: On 02/23/2016 09:47 AM, David Kupka wrote: On 22/02/16 16:15, Martin Kosek wrote: On 02/22/2

Re: [Freeipa-devel] [PATCH 200] slapi-nis: update configuration to allow external members

2016-02-25 Thread Jan Cholasta
On 22.2.2016 19:56, Tomas Babej wrote: On 02/22/2016 06:14 PM, Alexander Bokovoy wrote: On Mon, 22 Feb 2016, Tomas Babej wrote: On 02/22/2016 11:48 AM, Alexander Bokovoy wrote: Hi, attached patch should update compat tree configuration if it exist to follow slapi-nis 0.55 which has suppor

Re: [Freeipa-devel] [PATCH 0426] spec: add missing requires to python*-ipalib package

2016-02-25 Thread Jan Cholasta
Hi, On 25.2.2016 18:05, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/5680 Patch attached. NACK. For python 3, the ldap module is provided by python3-pyldap. Any reason for the random ordering? The requires are not alphabetically ordered, so I would prefer if you just appende

Re: [Freeipa-devel] [REVIEW] Intial stab towards Authentication Indicators

2016-02-25 Thread Simo Sorce
On Thu, 2016-02-25 at 16:13 -0500, Nathaniel McCallum wrote: > On Thu, 2016-02-25 at 12:19 -0500, Nathaniel McCallum wrote: > > On Thu, 2016-02-25 at 10:49 -0500, Simo Sorce wrote: > > > > > > On Thu, 2016-02-25 at 10:32 -0500, Nathaniel McCallum wrote: > > > > > > > > > > > > On Wed, 2016-02-24

Re: [Freeipa-devel] [REVIEW] Intial stab towards Authentication Indicators

2016-02-25 Thread Nathaniel McCallum
On Thu, 2016-02-25 at 12:19 -0500, Nathaniel McCallum wrote: > On Thu, 2016-02-25 at 10:49 -0500, Simo Sorce wrote: > > > > On Thu, 2016-02-25 at 10:32 -0500, Nathaniel McCallum wrote: > > > > > > > > > On Wed, 2016-02-24 at 09:55 -0500, Nathaniel McCallum wrote: > > > > > > > > > > > > On Sun

Re: [Freeipa-devel] [PATCH] 0017 configure DNA shared config entry to allow connection with GSSAPI

2016-02-25 Thread thierry bordaz
On 02/25/2016 12:03 PM, Martin Babinsky wrote: On 02/24/2016 04:30 PM, thierry bordaz wrote: On 01/21/2016 05:04 PM, Martin Babinsky wrote: On 01/21/2016 01:37 PM, thierry bordaz wrote: Hi Thierry, I have couple of comments to your patch: 1.) there is a number of PEP8 errors in the patch

Re: [Freeipa-devel] [REVIEW] Intial stab towards Authentication Indicators

2016-02-25 Thread Nathaniel McCallum
On Thu, 2016-02-25 at 10:49 -0500, Simo Sorce wrote: > On Thu, 2016-02-25 at 10:32 -0500, Nathaniel McCallum wrote: > > > > On Wed, 2016-02-24 at 09:55 -0500, Nathaniel McCallum wrote: > > > > > > On Sun, 2016-02-21 at 20:50 -0500, Simo Sorce wrote: > > > > > > > > > > > > On Sun, 2016-02-21 at

[Freeipa-devel] [PATCH 0426] spec: add missing requires to python*-ipalib package

2016-02-25 Thread Martin Basti
https://fedorahosted.org/freeipa/ticket/5680 Patch attached. From 3f3cfeb7d26f0b775f2ad40650ba085763ebd86f Mon Sep 17 00:00:00 2001 From: Martin Basti Date: Thu, 25 Feb 2016 17:47:10 +0100 Subject: [PATCH] spec: Add missing dependencies to python*-ipalib package Standalone instalation of python

[Freeipa-devel] [PATCH] 953 advise: configure TLS in redhat_nss_pam_ldapd and redhat_nss_ldap plugins

2016-02-25 Thread Petr Vobornik
I did not add --enableldapstarttls to config_redhat_nss_ldap because I'm not sure if it is present on el5 (IMO it is not). authconfig in: * config_redhat_nss_ldap got * --enableldaptls * config_redhat_nss_pam_ldapd got * --enableldaptls * --enableldapstarttls options https://fedorahosted

Re: [Freeipa-devel] [PATCH 0425] pylint: suppress false positive no-member errors

2016-02-25 Thread Martin Basti
On 25.02.2016 15:48, Martin Basti wrote: The last pylint 1.5 patch, \o/ https://fedorahosted.org/freeipa/ticket/5615 self-NACK too broad disables -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: htt

Re: [Freeipa-devel] Locations design v2: LDAP schema & user interface

2016-02-25 Thread Simo Sorce
On Thu, 2016-02-25 at 15:54 +0100, Petr Spacek wrote: > On 25.2.2016 15:28, Simo Sorce wrote: > > On Thu, 2016-02-25 at 14:45 +0100, Petr Spacek wrote: > >> Variant C > >> - > >> An alternative is to be lazy and dumb. Maybe it would be enough for > >> the first > >> round ... > >> > >> We w

Re: [Freeipa-devel] [REVIEW] Intial stab towards Authentication Indicators

2016-02-25 Thread Simo Sorce
On Thu, 2016-02-25 at 10:32 -0500, Nathaniel McCallum wrote: > On Wed, 2016-02-24 at 09:55 -0500, Nathaniel McCallum wrote: > > On Sun, 2016-02-21 at 20:50 -0500, Simo Sorce wrote: > > > > > > On Sun, 2016-02-21 at 20:20 -0500, Nathaniel McCallum wrote: > > > > > > > > > > > > https://github.com

Re: [Freeipa-devel] [REVIEW] Intial stab towards Authentication Indicators

2016-02-25 Thread Nathaniel McCallum
On Wed, 2016-02-24 at 09:55 -0500, Nathaniel McCallum wrote: > On Sun, 2016-02-21 at 20:50 -0500, Simo Sorce wrote: > > > > On Sun, 2016-02-21 at 20:20 -0500, Nathaniel McCallum wrote: > > > > > > > > > https://github.com/npmccallum/freeipa/pull/1 > > > > > > The above (pseudo) pull request con

Re: [Freeipa-devel] [patch 0034] ipatests: extend permission plugin test with new expected output

2016-02-25 Thread Martin Basti
On 25.02.2016 09:52, Milan Kubík wrote: On 02/24/2016 07:05 PM, Martin Basti wrote: On 24.02.2016 08:34, Milan Kubík wrote: On 02/18/2016 03:52 PM, Milan Kubík wrote: On 02/15/2016 04:59 PM, Milan Kubík wrote: Patch attached. Applies on ipa-4-3 as well. Updated version of patch fixes

Re: [Freeipa-devel] [PATCH 0001] Add new parameter --ssh-update to ipa-client-install

2016-02-25 Thread Jan Cholasta
On 25.2.2016 15:59, Petr Spacek wrote: On 25.2.2016 14:36, Jan Cholasta wrote: Hi, On 25.2.2016 14:23, Martin Basti wrote: On 22.02.2016 22:13, Martin Štefany wrote: Hi, please, review the attached patch which adds --ssh-update to ipa-client- install. Ticket:https://fedorahosted.org/freei

Re: [Freeipa-devel] [PATCH 0001] Add new parameter --ssh-update to ipa-client-install

2016-02-25 Thread Petr Spacek
On 25.2.2016 14:36, Jan Cholasta wrote: > Hi, > > On 25.2.2016 14:23, Martin Basti wrote: >> >> >> On 22.02.2016 22:13, Martin Štefany wrote: >>> Hi, >>> >>> please, review the attached patch which adds --ssh-update to ipa-client- >>> install. >>> >>> Ticket:https://fedorahosted.org/freeipa/ticket

Re: [Freeipa-devel] [PATCH 0390] Fix build with GCC 4.9+

2016-02-25 Thread Petr Spacek
On 19.2.2016 13:55, Petr Spacek wrote: > Hello, > > Fix build with GCC 4.9+. > > GCC 4.9+ is too aggressive when optimizing functions with nonnull > attributes. This removes most of asserts() in the plugin. > GCC 6 adds warnings for these cases. > > We are disabling the unwanted condition prunin

Re: [Freeipa-devel] Locations design v2: LDAP schema & user interface

2016-02-25 Thread Petr Spacek
On 25.2.2016 15:28, Simo Sorce wrote: > On Thu, 2016-02-25 at 14:45 +0100, Petr Spacek wrote: >> Variant C >> - >> An alternative is to be lazy and dumb. Maybe it would be enough for >> the first >> round ... >> >> We would retain >> [first step - no change from variant A] >> * create locat

Re: [Freeipa-devel] [PATCH] 0005 webui: topology graph: canvas resizes itself according to the window size

2016-02-25 Thread Pavel Vomacka
On 02/17/2016 06:29 PM, Petr Vobornik wrote: On 02/15/2016 04:20 PM, Pavel Vomacka wrote: On 02/12/2016 01:52 PM, Pavel Vomacka wrote: On 02/11/2016 12:31 PM, Pavel Vomacka wrote: Hello, The canvas of the graph had static size. This patch fixes this issue and from now the graph canvas i

[Freeipa-devel] [PATCH 0425] pylint: suppress false positive no-member errors

2016-02-25 Thread Martin Basti
The last pylint 1.5 patch, \o/ https://fedorahosted.org/freeipa/ticket/5615 From 785fb245fbe04b4cc630e6bc1c1ee670d6eca6a8 Mon Sep 17 00:00:00 2001 From: Martin Basti Date: Thu, 25 Feb 2016 13:46:33 +0100 Subject: [PATCH] pylint: supress false positive no-member errors pylint 1.5 prints many fal

Re: [Freeipa-devel] Locations design v2: LDAP schema & user interface

2016-02-25 Thread Simo Sorce
On Thu, 2016-02-25 at 14:45 +0100, Petr Spacek wrote: > Variant C > - > An alternative is to be lazy and dumb. Maybe it would be enough for > the first > round ... > > We would retain > [first step - no change from variant A] > * create locations > * assign 'main' (aka 'primary' aka 'home'

[Freeipa-devel] [TESTS][PATCH 0011] WebUI: Creating user without private group

2016-02-25 Thread Lenka Doudova
Hi, here's a patch for webUI tests that provides test for creating user without private group. Related to ticket https://fedorahosted.org/freeipa/ticket/4986 Since the option to specify GID when creating a user is not available https://fedorahosted.org/freeipa/ticket/5505 the test creates a n

Re: [Freeipa-devel] Locations design v2: LDAP schema & user interface

2016-02-25 Thread Petr Spacek
On 24.2.2016 15:25, Simo Sorce wrote: > On Wed, 2016-02-24 at 10:00 +0100, Martin Kosek wrote: >> On 02/23/2016 06:59 PM, Petr Spacek wrote: >>> On 23.2.2016 18:14, Simo Sorce wrote: >> ... More seriously I think it is a great idea, but too premature to get all the way there now. We need

Re: [Freeipa-devel] [PATCH 0001] Add new parameter --ssh-update to ipa-client-install

2016-02-25 Thread Jan Cholasta
Hi, On 25.2.2016 14:23, Martin Basti wrote: On 22.02.2016 22:13, Martin Štefany wrote: Hi, please, review the attached patch which adds --ssh-update to ipa-client- install. Ticket:https://fedorahosted.org/freeipa/ticket/2655 Hello, thank you for your patch. Please attach a patch as a file

Re: [Freeipa-devel] [PATCH 0413] fix permission: Read Replication Agreements

2016-02-25 Thread Jan Cholasta
On 24.2.2016 15:43, Martin Basti wrote: On 24.02.2016 13:36, Jan Cholasta wrote: On 24.2.2016 13:07, Martin Basti wrote: On 24.02.2016 10:45, Jan Cholasta wrote: On 23.2.2016 17:20, Martin Basti wrote: On 22.02.2016 09:00, Jan Cholasta wrote: Hi, On 17.2.2016 14:49, Martin Basti wrote

Re: [Freeipa-devel] [PATCH 0001] Add new parameter --ssh-update to ipa-client-install

2016-02-25 Thread Martin Basti
On 22.02.2016 22:13, Martin Štefany wrote: Hi, please, review the attached patch which adds --ssh-update to ipa-client- install. Ticket: https://fedorahosted.org/freeipa/ticket/2655 Hello, thank you for your patch. Please attach a patch as a file next time. I have doubts that this should be

Re: [Freeipa-devel] [PATCH 0011] Move freeipa certmonger helpers to libexecdir.

2016-02-25 Thread David Kupka
On 24/02/16 15:07, Rob Crittenden wrote: David Kupka wrote: On 23/02/16 16:41, Rob Crittenden wrote: David Kupka wrote: On 23/02/16 10:14, Martin Kosek wrote: On 02/23/2016 09:47 AM, David Kupka wrote: On 22/02/16 16:15, Martin Kosek wrote: On 02/22/2016 04:04 PM, Jan Cholasta wrote: On 22

[Freeipa-devel] [PATCH 0401] ipa-adtrust-install: Allow dash in the NETBIOS name

2016-02-25 Thread Tomas Babej
Hi, Dash should be one of the allowed characters in the netbios names, so relax the too strict validation. Note: the set of allowed characters might expand in the future https://fedorahosted.org/freeipa/ticket/5286 Tomas From eab57f7d15758bd998d944b33f338a35a57de218 Mon Sep 17 00:00:00 2001 Fro

Re: [Freeipa-devel] [PATCH] 0017 configure DNA shared config entry to allow connection with GSSAPI

2016-02-25 Thread thierry bordaz
On 02/25/2016 01:56 PM, Martin Babinsky wrote: On 02/25/2016 12:17 PM, thierry bordaz wrote: On 02/25/2016 12:03 PM, Martin Babinsky wrote: On 02/24/2016 04:30 PM, thierry bordaz wrote: On 01/21/2016 05:04 PM, Martin Babinsky wrote: On 01/21/2016 01:37 PM, thierry bordaz wrote: Hi Thierr

Re: [Freeipa-devel] [PATCH 0424] Pylint: add missing attributes of exceptions to definition in pylint plugin

2016-02-25 Thread Martin Basti
On 25.02.2016 11:29, David Kupka wrote: On 24/02/16 18:54, Martin Basti wrote: Pylint is not able to handle IPA errors objects, because attributes are added into objects dynamically, and pylint 1.5 reports them as no-member errors. https://fedorahosted.org/freeipa/ticket/5615 Patch attached.

Re: [Freeipa-devel] [PATCH] 0017 configure DNA shared config entry to allow connection with GSSAPI

2016-02-25 Thread Martin Babinsky
On 02/25/2016 12:17 PM, thierry bordaz wrote: On 02/25/2016 12:03 PM, Martin Babinsky wrote: On 02/24/2016 04:30 PM, thierry bordaz wrote: On 01/21/2016 05:04 PM, Martin Babinsky wrote: On 01/21/2016 01:37 PM, thierry bordaz wrote: Hi Thierry, I have couple of comments to your patch: 1.

Re: [Freeipa-devel] [PATCH 0423] fix duplicated except

2016-02-25 Thread Martin Basti
On 25.02.2016 12:03, David Kupka wrote: On 25/02/16 11:40, Jan Cholasta wrote: On 25.2.2016 11:25, David Kupka wrote: On 24/02/16 17:56, Martin Basti wrote: During my playing with pylint, I fixed this issue which allows us to enable additional check in pylint (the nice one). Patch attached,

Re: [Freeipa-devel] [PATCH 0134] CI tests: use old schema when testing hostmask-based sudo rules

2016-02-25 Thread Tomas Babej
On 02/18/2016 10:32 AM, Martin Babinsky wrote: > https://fedorahosted.org/freeipa/ticket/5625 ACK, works fine for me. Thanks for the patch. Pushed to master: 94a836dd46e5e041443b7da03e4ce8a7a7aaa7e3 Pushed to ipa-4-2: 61475631f64206d771e3fd243220be242f4bdd38 Tomas -- Manage your subscription

Re: [Freeipa-devel] [PATCH] 0017 configure DNA shared config entry to allow connection with GSSAPI

2016-02-25 Thread thierry bordaz
On 02/25/2016 12:03 PM, Martin Babinsky wrote: On 02/24/2016 04:30 PM, thierry bordaz wrote: On 01/21/2016 05:04 PM, Martin Babinsky wrote: On 01/21/2016 01:37 PM, thierry bordaz wrote: Hi Thierry, I have couple of comments to your patch: 1.) there is a number of PEP8 errors in the patch

Re: [Freeipa-devel] [PATCH 0421] Make PTR records check optional for IPA installation

2016-02-25 Thread Petr Spacek
On 24.2.2016 15:13, Martin Basti wrote: > https://fedorahosted.org/freeipa/ticket/5686 > > Patch attached. LGTM, ACK if it passes QE testing. -- Petr^2 Spacek -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to Fr

Re: [Freeipa-devel] [PATCH] 0017 configure DNA shared config entry to allow connection with GSSAPI

2016-02-25 Thread Martin Babinsky
On 02/24/2016 04:30 PM, thierry bordaz wrote: On 01/21/2016 05:04 PM, Martin Babinsky wrote: On 01/21/2016 01:37 PM, thierry bordaz wrote: Hi Thierry, I have couple of comments to your patch: 1.) there is a number of PEP8 errors in the patch (http://paste.fedoraproject.org/313246/33893701

Re: [Freeipa-devel] [PATCH 0423] fix duplicated except

2016-02-25 Thread David Kupka
On 25/02/16 11:40, Jan Cholasta wrote: On 25.2.2016 11:25, David Kupka wrote: On 24/02/16 17:56, Martin Basti wrote: During my playing with pylint, I fixed this issue which allows us to enable additional check in pylint (the nice one). Patch attached, it should go only to master. Works for

[Freeipa-devel] [PATCH 0400] l10n: Remove Transifex configuration

2016-02-25 Thread Tomas Babej
Hi, We're not using Transifex to manage our translations anymore. Tomas From 89b2da7d936b6c8aad115e05375c4dcdf8af11c5 Mon Sep 17 00:00:00 2001 From: Tomas Babej Date: Wed, 20 Jan 2016 19:44:25 +0100 Subject: [PATCH] l10n: Remove Transifex configuration We're not using Transifex to manage our tr

Re: [Freeipa-devel] [PATCH 0423] fix duplicated except

2016-02-25 Thread Jan Cholasta
On 25.2.2016 11:25, David Kupka wrote: On 24/02/16 17:56, Martin Basti wrote: During my playing with pylint, I fixed this issue which allows us to enable additional check in pylint (the nice one). Patch attached, it should go only to master. Works for me, ACK. I always wonder how something

Re: [Freeipa-devel] IPA client realm/domain autodiscovery improvements

2016-02-25 Thread Petr Spacek
On 25.2.2016 11:02, Jan Cholasta wrote: > On 25.2.2016 10:35, Petr Spacek wrote: >> On 24.2.2016 16:30, Sumit Bose wrote: >>> On Wed, Feb 24, 2016 at 04:08:14PM +0100, David Kupka wrote: On 24/02/16 15:55, Sumit Bose wrote: > On Wed, Feb 24, 2016 at 03:30:40PM +0100, Martin Babinsky wrote:

Re: [Freeipa-devel] [PATCH 0424] Pylint: add missing attributes of exceptions to definition in pylint plugin

2016-02-25 Thread David Kupka
On 24/02/16 18:54, Martin Basti wrote: Pylint is not able to handle IPA errors objects, because attributes are added into objects dynamically, and pylint 1.5 reports them as no-member errors. https://fedorahosted.org/freeipa/ticket/5615 Patch attached. It would be better to define all error

Re: [Freeipa-devel] [PATCH 0423] fix duplicated except

2016-02-25 Thread David Kupka
On 24/02/16 17:56, Martin Basti wrote: During my playing with pylint, I fixed this issue which allows us to enable additional check in pylint (the nice one). Patch attached, it should go only to master. Works for me, ACK. I always wonder how something like this can even get to the sources.

Re: [Freeipa-devel] [patch 0033] spec file: update the python-polib dependency name to python2-polib

2016-02-25 Thread Jan Cholasta
On 25.2.2016 11:03, Milan Kubík wrote: On 02/15/2016 05:39 PM, Lukas Slebodnik wrote: On (15/02/16 17:00), Petr Vobornik wrote: On 02/15/2016 04:37 PM, Milan Kubík wrote: Reflect the updated name of the package. Seems to me as a packaging bug in python-polib. It should use python_provide mac

Re: [Freeipa-devel] [patch 0033] spec file: update the python-polib dependency name to python2-polib

2016-02-25 Thread Milan Kubík
On 02/25/2016 11:07 AM, Jan Cholasta wrote: On 25.2.2016 11:03, Milan Kubík wrote: On 02/15/2016 05:39 PM, Lukas Slebodnik wrote: On (15/02/16 17:00), Petr Vobornik wrote: On 02/15/2016 04:37 PM, Milan Kubík wrote: Reflect the updated name of the package. Seems to me as a packaging bug in p

Re: [Freeipa-devel] [patch 0033] spec file: update the python-polib dependency name to python2-polib

2016-02-25 Thread Milan Kubík
On 02/15/2016 05:39 PM, Lukas Slebodnik wrote: On (15/02/16 17:00), Petr Vobornik wrote: On 02/15/2016 04:37 PM, Milan Kubík wrote: Reflect the updated name of the package. Seems to me as a packaging bug in python-polib. It should use python_provide macro to handle the transition. There is n

Re: [Freeipa-devel] IPA client realm/domain autodiscovery improvements

2016-02-25 Thread Jan Cholasta
On 25.2.2016 10:35, Petr Spacek wrote: On 24.2.2016 16:30, Sumit Bose wrote: On Wed, Feb 24, 2016 at 04:08:14PM +0100, David Kupka wrote: On 24/02/16 15:55, Sumit Bose wrote: On Wed, Feb 24, 2016 at 03:30:40PM +0100, Martin Babinsky wrote: On 02/24/2016 03:20 PM, Sumit Bose wrote: On Wed, Fe

Re: [Freeipa-devel] [FREEIPA INSTALL ISSUE] Recent Tomcat build from F23 updates-testing breaks Dogtag installation

2016-02-25 Thread Martin Babinsky
On 02/25/2016 10:18 AM, Martin Babinsky wrote: Hello everyone, please note that package tomcat-8.0.32-3.fc23.noarch [1] messes with symlinks to Catalina classes used by Dogtag. This makes CA deployment blow up spectacularly during FreeIPA server/replica/etc installation. A bugzilla exists[2] for

Re: [Freeipa-devel] IPA client realm/domain autodiscovery improvements

2016-02-25 Thread Petr Spacek
On 24.2.2016 16:30, Sumit Bose wrote: > On Wed, Feb 24, 2016 at 04:08:14PM +0100, David Kupka wrote: >> On 24/02/16 15:55, Sumit Bose wrote: >>> On Wed, Feb 24, 2016 at 03:30:40PM +0100, Martin Babinsky wrote: On 02/24/2016 03:20 PM, Sumit Bose wrote: > On Wed, Feb 24, 2016 at 01:31:55PM +

[Freeipa-devel] [FREEIPA INSTALL ISSUE] Recent Tomcat build from F23 updates-testing breaks Dogtag installation

2016-02-25 Thread Martin Babinsky
Hello everyone, please note that package tomcat-8.0.32-3.fc23.noarch [1] messes with symlinks to Catalina classes used by Dogtag. This makes CA deployment blow up spectacularly during FreeIPA server/replica/etc installation. A bugzilla exists[2] for this issue and also mentions a workaround wh

Re: [Freeipa-devel] [patch 0034] ipatests: extend permission plugin test with new expected output

2016-02-25 Thread Milan Kubík
On 02/24/2016 07:05 PM, Martin Basti wrote: On 24.02.2016 08:34, Milan Kubík wrote: On 02/18/2016 03:52 PM, Milan Kubík wrote: On 02/15/2016 04:59 PM, Milan Kubík wrote: Patch attached. Applies on ipa-4-3 as well. Updated version of patch fixes test_old_permission_plugin as well. -- Mil