[Freeipa-devel] [PATCH] 0012 Add record(s) to /etc/host when IPA is configured as DNS server.

2014-09-02 Thread David Kupka
This patch depends on freeipa-dkupka-0009 as it modifies the same part of code. https://fedorahosted.org/freeipa/ticket/4220 -- David Kupka From 549e682809d9e0ccc6debe6676f22b3f9d1755f4 Mon Sep 17 00:00:00 2001 From: David Kupka Date: Tue, 2 Sep 2014 10:49:26 +0200 Subject: [PATCH] Add record

Re: [Freeipa-devel] [PATCH] 0012 Add record(s) to /etc/host when IPA is configured as DNS server.

2014-09-02 Thread David Kupka
Ok, the patch no longer depends on 0009. The reason is that 0012 is going to ipa-4.0 and 0009 to ipa-4.1. On 09/02/2014 12:13 PM, David Kupka wrote: This patch depends on freeipa-dkupka-0009 as it modifies the same part of code. https://fedorahosted.org/freeipa/ticket/4220

Re: [Freeipa-devel] [PATCH] 0009 Detect and configure all usable IP addresses.

2014-09-02 Thread David Kupka
The patch now depends on freeipa-dkupka-0012 as both modifies the same part of code. On 09/02/2014 10:29 AM, David Kupka wrote: Forget to add str() conversion to some places when removing map(). Now it should be working again. On 08/27/2014 02:24 PM, David Kupka wrote: Patch modified

Re: [Freeipa-devel] [PATCH] 0008 Use certmonger D-Bus API instead of messing with its files.

2014-09-03 Thread David Kupka
On 09/02/2014 01:56 PM, Jan Cholasta wrote: Dne 29.8.2014 v 14:34 David Kupka napsal(a): Hope, I've addressed all the issues (except 9 and 11, inline). Let's go for another round :-) On 08/27/2014 11:05 AM, Jan Cholasta wrote: Hi, Dne 25.8.2014 v 15:39 David Kupka napsal(a): On

Re: [Freeipa-devel] [PATCH] 0008 Use certmonger D-Bus API instead of messing with its files.

2014-09-03 Thread David Kupka
On 09/03/2014 04:05 PM, Jan Cholasta wrote: Dne 3.9.2014 v 12:37 David Kupka napsal(a): On 09/02/2014 01:56 PM, Jan Cholasta wrote: Dne 29.8.2014 v 14:34 David Kupka napsal(a): Hope, I've addressed all the issues (except 9 and 11, inline). Let's go for another round :-) On 08/27/

Re: [Freeipa-devel] [PATCH] 0008 Use certmonger D-Bus API instead of messing with its files.

2014-09-04 Thread David Kupka
On 09/03/2014 04:45 PM, Jan Cholasta wrote: Dne 3.9.2014 v 16:25 David Kupka napsal(a): On 09/03/2014 04:05 PM, Jan Cholasta wrote: Dne 3.9.2014 v 12:37 David Kupka napsal(a): On 09/02/2014 01:56 PM, Jan Cholasta wrote: Dne 29.8.2014 v 14:34 David Kupka napsal(a): Hope, I've addresse

Re: [Freeipa-devel] [PATCH] 0011 Allow user to force Kerberos realm during installation

2014-09-04 Thread David Kupka
On 09/03/2014 05:09 PM, Jan Cholasta wrote: Hi, Dne 27.8.2014 v 13:56 David Kupka napsal(a): Usually it isn't wise to allow something like this. But in environment with broken DNS (described in ticket) there is probably not many alternatives. https://fedorahosted.org/freeipa/ticket/444

Re: [Freeipa-devel] [PATCH 0042] Make lint work on Fedora 22.

2015-04-08 Thread David Kupka
On 04/06/2015 02:48 PM, Simo Sorce wrote: On Mon, 2015-03-30 at 12:15 +0200, David Kupka wrote: On 03/30/2015 07:12 AM, Jan Cholasta wrote: Dne 28.3.2015 v 00:05 Petr Vobornik napsal(a): On 27.3.2015 14:58, David Kupka wrote: pylint changed slightly so we must react otherwise we'll be u

Re: [Freeipa-devel] [PATCH 0042] Make lint work on Fedora 22.

2015-04-08 Thread David Kupka
On 04/08/2015 10:23 AM, Jan Cholasta wrote: Dne 8.4.2015 v 10:22 David Kupka napsal(a): On 04/06/2015 02:48 PM, Simo Sorce wrote: On Mon, 2015-03-30 at 12:15 +0200, David Kupka wrote: On 03/30/2015 07:12 AM, Jan Cholasta wrote: Dne 28.3.2015 v 00:05 Petr Vobornik napsal(a): On 27.3.2015 14

Re: [Freeipa-devel] [PATCH 0042] Make lint work on Fedora 22.

2015-04-08 Thread David Kupka
On 04/08/2015 02:53 PM, Simo Sorce wrote: On Wed, 2015-04-08 at 10:22 +0200, David Kupka wrote: On 04/06/2015 02:48 PM, Simo Sorce wrote: On Mon, 2015-03-30 at 12:15 +0200, David Kupka wrote: On 03/30/2015 07:12 AM, Jan Cholasta wrote: Dne 28.3.2015 v 00:05 Petr Vobornik napsal(a): On

Re: [Freeipa-devel] [PATCH 0042] Make lint work on Fedora 22.

2015-04-13 Thread David Kupka
On 04/10/2015 02:55 PM, Simo Sorce wrote: On Fri, 2015-04-10 at 12:55 +0200, Lukas Slebodnik wrote: On (08/04/15 08:53), Simo Sorce wrote: On Wed, 2015-04-08 at 10:22 +0200, David Kupka wrote: On 04/06/2015 02:48 PM, Simo Sorce wrote: On Mon, 2015-03-30 at 12:15 +0200, David Kupka wrote: On

Re: [Freeipa-devel] design review: Certificate Profiles

2015-04-16 Thread David Kupka
would change the command to 'ipa certprofile-add' to stay consistent with rest of FreeIPA commands. -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Re: [Freeipa-devel] [PATCHES 0227-0229] Server upgrade: introduce ipa-server-upgrade command

2015-04-20 Thread David Kupka
228. In patch 227 you add whole file ipa_server_upgrade.py and in patch 228 add forgotten import and change option description slightly. Otherwise it works for me. -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa

Re: [Freeipa-devel] [PATCH 0042] Make lint work on Fedora 22.

2015-04-23 Thread David Kupka
On 04/13/2015 01:23 PM, David Kupka wrote: On 04/10/2015 02:55 PM, Simo Sorce wrote: On Fri, 2015-04-10 at 12:55 +0200, Lukas Slebodnik wrote: On (08/04/15 08:53), Simo Sorce wrote: On Wed, 2015-04-08 at 10:22 +0200, David Kupka wrote: On 04/06/2015 02:48 PM, Simo Sorce wrote: On Mon, 2015

Re: [Freeipa-devel] [PATCH 0042] Make lint work on Fedora 22.

2015-04-24 Thread David Kupka
On 04/24/2015 03:17 PM, Martin Basti wrote: On 23/04/15 15:26, David Kupka wrote: On 04/13/2015 01:23 PM, David Kupka wrote: On 04/10/2015 02:55 PM, Simo Sorce wrote: On Fri, 2015-04-10 at 12:55 +0200, Lukas Slebodnik wrote: On (08/04/15 08:53), Simo Sorce wrote: On Wed, 2015-04-08 at 10:22

Re: [Freeipa-devel] [PATCH 0042] Make lint work on Fedora 22.

2015-04-27 Thread David Kupka
On 04/24/2015 03:58 PM, Tomas Babej wrote: On 04/24/2015 03:50 PM, Martin Basti wrote: On 24/04/15 15:22, David Kupka wrote: On 04/24/2015 03:17 PM, Martin Basti wrote: On 23/04/15 15:26, David Kupka wrote: On 04/13/2015 01:23 PM, David Kupka wrote: On 04/10/2015 02:55 PM, Simo Sorce

Re: [Freeipa-devel] [PATCH 0042] Make lint work on Fedora 22.

2015-04-27 Thread David Kupka
On 04/27/2015 12:18 PM, Martin Basti wrote: On 27/04/15 11:04, Martin Kosek wrote: On 04/27/2015 10:49 AM, Martin Basti wrote: On 27/04/15 10:31, David Kupka wrote: On 04/24/2015 03:58 PM, Tomas Babej wrote: On 04/24/2015 03:50 PM, Martin Basti wrote: On 24/04/15 15:22, David Kupka wrote

Re: [Freeipa-devel] [PATCHES 0227-0229] Server upgrade: introduce ipa-server-upgrade command

2015-04-27 Thread David Kupka
Updated patch attached Looks good to me and works as expected. Honza, are you OK with the patches? -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Re: [Freeipa-devel] [PATCH 0230] Server upgrade: fix comment in ldapupdater

2015-04-27 Thread David Kupka
On 04/16/2015 05:14 PM, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/4904 Patch attached I guess the rest of the comment is also outdated. Can you update it, too? -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman

Re: [Freeipa-devel] [PATCH] 0005 User life cycle: del/mod/find/show stageuser commands

2015-04-28 Thread David Kupka
ot found in Kerberos database" -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Re: [Freeipa-devel] [PATCH] 0005 User life cycle: del/mod/find/show stageuser commands

2015-04-28 Thread David Kupka
On 04/28/2015 10:28 AM, thierry bordaz wrote: On 04/28/2015 10:23 AM, David Kupka wrote: On 04/16/2015 01:00 PM, thierry bordaz wrote: Hello, Here is the next patch for User life cycle that introduces del/mod/find and show stageuser plugin commands. * -User Life Cycle (create

Re: [Freeipa-devel] [PATCH 0230] Server upgrade: fix comment in ldapupdater

2015-04-29 Thread David Kupka
On 04/28/2015 02:48 PM, Martin Basti wrote: On 27/04/15 18:42, David Kupka wrote: On 04/16/2015 05:14 PM, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/4904 Patch attached I guess the rest of the comment is also outdated. Can you update it, too? Updated patch attached

Re: [Freeipa-devel] behavior change in DNS dynamic updates: #155

2015-04-29 Thread David Kupka
implement 'this update is the last one, report the error here' logic. I do not see a way to change this without changes to BIND internals and IMHO it is not worth the effort. Thank you for your time! -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list: ht

Re: [Freeipa-devel] [PATCHES 0233-0234] DNSSEC: forwarders validation

2015-04-30 Thread David Kupka
ances of 'ends'. -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Re: [Freeipa-devel] [PATCH 0322-0337] Fix mysterious failures in PTR record synchronization

2015-05-06 Thread David Kupka
d nor bind-dyndb-ldap. To test the patch set I used ipa-client-install with patch freeipa-dkupka-0035-6. DNS server does not return an error unless creation/update of record that I requested has failed. This is exactly the behavior I expect, thanks. -- David Kupka -- Manage your subscriptio

Re: [Freeipa-devel] [PATCHES 0233-0234] DNSSEC: forwarders validation

2015-05-07 Thread David Kupka
On 05/06/2015 03:20 PM, Martin Basti wrote: On 05/05/15 15:00, Martin Basti wrote: On 30/04/15 15:37, David Kupka wrote: On 04/24/2015 02:56 PM, Martin Basti wrote: Patches attached. Hi, thanks for patches. 1. You changed message in DNSServerNotRespondingWarning class but not the test

Re: [Freeipa-devel] [PATCH] 381 Fix stop_tracking_certificates call in ipa-restore

2015-05-07 Thread David Kupka
l Hi, thanks for patch (with 5 months delay :-) The patch needs a trivial rebase but otherwise works for me and is needed for ipa-restore to work. -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to F

Re: [Freeipa-devel] [PATCH] 381 Fix stop_tracking_certificates call in ipa-restore

2015-05-07 Thread David Kupka
On 05/07/2015 10:11 AM, Jan Cholasta wrote: Dne 7.5.2015 v 10:04 David Kupka napsal(a): On 12/03/2014 10:23 AM, Jan Cholasta wrote: Hi, the attached patch fixes <https://fedorahosted.org/freeipa/ticket/4775>. Honza ___ Freeipa-devel mailin

[Freeipa-devel] [PATCH] 0048 Remove unused enable() method from DogtagInstance.

2015-05-12 Thread David Kupka
DogtagInstance.enable() overrides Service.enable() and does nothing usefulll. Also removing it solves bug discovered recently in uninstall procedure. -- David Kupka From dbf020b1703a9cf2f4d3614f4c9caa83f340f571 Mon Sep 17 00:00:00 2001 From: David Kupka Date: Tue, 12 May 2015 12:43:36 +0200

Re: [Freeipa-devel] [PATCH] 0048 Remove unused enable() method from DogtagInstance.

2015-05-12 Thread David Kupka
On 05/12/2015 02:16 PM, Martin Basti wrote: On 12/05/15 13:53, David Kupka wrote: DogtagInstance.enable() overrides Service.enable() and does nothing usefulll. Also removing it solves bug discovered recently in uninstall procedure. NACK 1) this is used in step() call, which means the tomcatd

Re: [Freeipa-devel] [PATCHES 0239-0243] Server Upgrade: minor fixes

2015-05-13 Thread David Kupka
On 05/12/2015 02:44 PM, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/4904 Patches attached. Works for me, ACK. -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http

Re: [Freeipa-devel] [TEST PLAN] User lifecycle plugin

2015-05-13 Thread David Kupka
be possible to add/modify the attributes in staging are freely all the check must be applied when the user is activated. -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Re: [Freeipa-devel] [PATCH] 0048 Remove unused enable() method from DogtagInstance.

2015-05-14 Thread David Kupka
On 05/13/2015 12:07 PM, Martin Basti wrote: On 12/05/15 16:54, David Kupka wrote: On 05/12/2015 02:16 PM, Martin Basti wrote: On 12/05/15 13:53, David Kupka wrote: DogtagInstance.enable() overrides Service.enable() and does nothing usefulll. Also removing it solves bug discovered recently in

Re: [Freeipa-devel] [PATCH] 0005 User life cycle: del/mod/find/show stageuser commands

2015-05-15 Thread David Kupka
elete) users matched Number of entries returned 0 ---- David - Original Message - From: "thierry bordaz" To: "Jan Cholasta" , "David Kupka" Cc: "freeipa-devel" Sent: Tuesday, May 12, 2015 5:05

Re: [Freeipa-devel] [PATCH] 832-850 Stage Users Web UI and its prerequisites

2015-05-15 Thread David Kupka
'delete permanently'. *) I would prefer if the choice between 'preserve' and 'permanently delete' in delete dialog was done by directly clicking button not switching 'mode' radio button and then clicking 'delete'. Otherwise everything s

Re: [Freeipa-devel] [PATCHES 0033-0034] fix recent bugs introduced by letting httpd use file-based ccache

2015-05-19 Thread David Kupka
On 05/15/2015 04:41 PM, Martin Babinsky wrote: On 05/15/2015 04:25 PM, Jan Cholasta wrote: Dne 15.5.2015 v 16:16 Martin Babinsky napsal(a): These two patches fix two issues reported by David Kupka in most recent freeipa-master builds, which are caused by my previous patch 0031 "prov

Re: [Freeipa-devel] [PATCH 0257] ULC: Fix: Upgrade for stage user admins failed

2015-05-25 Thread David Kupka
On 05/22/2015 05:59 PM, Martin Basti wrote: Patch attached. Thanks for patch. Works for me, ACK. -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute

[Freeipa-devel] [PATCH 0049] Move CA installation code into single module.

2015-06-03 Thread David Kupka
-- David Kupka From b5218e9c0101f852e25945cc7e64ff061a04ff4b Mon Sep 17 00:00:00 2001 From: David Kupka Date: Wed, 3 Jun 2015 17:43:27 +0200 Subject: [PATCH] Move CA installation code into single module. --- install/tools/ipa-ca-install | 185 ++- ipaserver

[Freeipa-devel] [PATCH 0050] Allow to skip lint when building FreeIPA.

2015-06-04 Thread David Kupka
-- David Kupka From f68607e9a3db4cd8893c465d804615aac34afc29 Mon Sep 17 00:00:00 2001 From: David Kupka Date: Thu, 4 Jun 2015 12:10:37 +0200 Subject: [PATCH] Allow to skip lint when building FreeIPA. Target 'lint' does nothing when SKIP_LINT is set to anything else than "no&q

Re: [Freeipa-devel] [PATCH 0050] Allow to skip lint when building FreeIPA.

2015-06-04 Thread David Kupka
On 06/04/2015 12:43 PM, Alexander Bokovoy wrote: On Thu, 04 Jun 2015, David Kupka wrote: -- David Kupka From f68607e9a3db4cd8893c465d804615aac34afc29 Mon Sep 17 00:00:00 2001 From: David Kupka Date: Thu, 4 Jun 2015 12:10:37 +0200 Subject: [PATCH] Allow to skip lint when building FreeIPA

Re: [Freeipa-devel] [PATCH 0049] Move CA installation code into single module.

2015-06-05 Thread David Kupka
On 06/03/2015 05:49 PM, David Kupka wrote: Updated patch attached. -- David Kupka From ca004a585f86a5e35d02a90dc9db0753f786b84a Mon Sep 17 00:00:00 2001 From: David Kupka Date: Wed, 3 Jun 2015 17:43:27 +0200 Subject: [PATCH] Move CA installation code into single module. --- install/tools

Re: [Freeipa-devel] [patch 0002] Abstract the HostTracker class from host plugin test

2015-06-05 Thread David Kupka
class which is used for most of the xml-rpc tests at the moment. For an example usage take a look at the host plugin test. Cheers, Milan Hello! Thanks for the patch. Works for me, ACK. -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman

Re: [Freeipa-devel] [PATCH 0049] Move CA installation code into single module.

2015-06-08 Thread David Kupka
On 06/08/2015 04:23 PM, Jan Cholasta wrote: Dne 8.6.2015 v 12:09 Jan Cholasta napsal(a): Dne 8.6.2015 v 08:25 Jan Cholasta napsal(a): Dne 5.6.2015 v 14:16 David Kupka napsal(a): On 06/03/2015 05:49 PM, David Kupka wrote: Updated patch attached. ACK. The patch needed a rebase and there

[Freeipa-devel] [PATCH 0051] Use 389-ds centralized scripts.

2015-06-09 Thread David Kupka
https://fedorahosted.org/freeipa/ticket/4051 -- David Kupka From da898ff6fbe760ff6786763297ecbf31bf10d300 Mon Sep 17 00:00:00 2001 From: David Kupka Date: Wed, 1 Apr 2015 11:27:36 -0400 Subject: [PATCH] Use 389-ds centralized scripts. Directory server is deprecating use of tools in instance

Re: [Freeipa-devel] [PATCHES 439-442] install: Migrate ipa-replica-install to the install framework

2015-06-10 Thread David Kupka
On 06/09/2015 02:06 PM, Jan Cholasta wrote: Hi, the attached patches implement another part of <https://fedorahosted.org/freeipa/ticket/4468>. Honza Works for me, ACK. -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/li

Re: [Freeipa-devel] Stage users - inconsistent permission names

2015-06-10 Thread David Kupka
System: Write Active Users RDN by administrators Rather "System: Modify User RDN" Permission name: System: Write Delete Users RDN by administrators Why is this permission needed, isn't "System: Modify Preserved Users" enough? Hello, it's probably my fault, I shou

[Freeipa-devel] [PATCH 0052] Stage User: Fix permissions naming and split them where, apropriate.

2015-06-10 Thread David Kupka
https://fedorahosted.org/freeipa/ticket/5057 -- David Kupka From ea25f9942c529ab91f1fe09f4eed087c6e5e92be Mon Sep 17 00:00:00 2001 From: David Kupka Date: Wed, 10 Jun 2015 12:52:10 +0200 Subject: [PATCH] Stage User: Fix permissions naming and split them where apropriate. Split permisions to

Re: [Freeipa-devel] [PATCH] 0005 User life cycle: del/mod/find/show stageuser commands

2015-06-10 Thread David Kupka
Dne 20.5.2015 v 11:26 Jan Cholasta napsal(a): Dne 18.5.2015 v 10:33 thierry bordaz napsal(a): On 05/15/2015 04:44 PM, David Kupka wrote: Hello Thierry, thanks for the patch set. Overall functionality of ULC feature looks good to me and is definitely "alpha ready". I found following

Re: [Freeipa-devel] [PATCHES 434, 443, 444] vault: Fix ipa-kra-install

2015-06-10 Thread David Kupka
gt;.) Honza There are two issues: 1) https://fedorahosted.org/freeipa/ticket/5059 but it is just missing check and can be fixed later. 2) kra.install() was called before http_install() but kra installation needs httpd running. This is fixed in attached patch. -- Davi

Re: [Freeipa-devel] [PATCHES 434, 443, 444] vault: Fix ipa-kra-install

2015-06-10 Thread David Kupka
Dne 10.6.2015 v 18:08 David Kupka napsal(a): Dne 10.6.2015 v 13:25 Jan Cholasta napsal(a): Hi, the attached patches fix several shortcomings in ipa-kra-install, see commit messages. <https://fedorahosted.org/freeipa/ticket/3872> (Patch 434 was introduced in <https://www.redhat.com

Re: [Freeipa-devel] [PATCH 0052] Stage User: Fix permissions naming and split them where, apropriate.

2015-06-11 Thread David Kupka
Dne 11.6.2015 v 14:12 thierry bordaz napsal(a): On 06/10/2015 02:14 PM, David Kupka wrote: https://fedorahosted.org/freeipa/ticket/5057 Hello David, The patch looks ok except it removes a permission to update 'uid' from an active user. This permission is required to delete(preserve)

Re: [Freeipa-devel] [PATCH 0052] Stage User: Fix permissions naming and split them where, apropriate.

2015-06-11 Thread David Kupka
Dne 11.6.2015 v 16:17 Martin Kosek napsal(a): On 06/11/2015 03:55 PM, David Kupka wrote: Dne 11.6.2015 v 14:12 thierry bordaz napsal(a): On 06/10/2015 02:14 PM, David Kupka wrote: https://fedorahosted.org/freeipa/ticket/5057 Hello David, The patch looks ok except it removes a permission to

Re: [Freeipa-devel] with new cert profiles patches ipa-replica-prepare fails after update

2015-06-18 Thread David Kupka
name, ca_db) File "/usr/lib/python2.7/site-packages/ipaserver/install/certs.py", line 337, in create_server_cert cdb.issue_server_cert(self.certreq_fname, self.certder_fname) File "/usr/lib/python2.7/site-packages/ipaserver/install/certs.py", line 419, in issue

Re: [Freeipa-devel] [PATCH] 0005 User life cycle: del/mod/find/show stageuser commands

2015-06-18 Thread David Kupka
/2015 02:02 PM, Jan Cholasta wrote: Dne 20.5.2015 v 11:26 Jan Cholasta napsal(a): Dne 18.5.2015 v 10:33 thierry bordaz napsal(a): On 05/15/2015 04:44 PM, David Kupka wrote: Hello Thierry, thanks for the patch set. Overall functionality of ULC feature looks good to me and is definitely "

[Freeipa-devel] [PATCH 0053] upgrade: Raise error when certmonger is not running.

2015-06-26 Thread David Kupka
https://fedorahosted.org/freeipa/ticket/5080 -- David Kupka From f5467b5a338647a20aef5e5657b9e21be5b0a2f5 Mon Sep 17 00:00:00 2001 From: David Kupka Date: Fri, 26 Jun 2015 10:42:23 +0200 Subject: [PATCH] upgrade: Raise error when certmonger is not running. Certmonger should be running (should

Re: [Freeipa-devel] [PATCH 0053] upgrade: Raise error when certmonger is not running.

2015-06-29 Thread David Kupka
On 26/06/15 19:45, Rob Crittenden wrote: Petr Vobornik wrote: On 06/26/2015 10:54 AM, David Kupka wrote: https://fedorahosted.org/freeipa/ticket/5080 ACK Is there a reason we don't simply start certmonger and quit if it fails to start? Woudln't that be friendlier? rob

Re: [Freeipa-devel] [PATCH] 877 fix force-sync, re-initialize of replica and a check for replication agreement existence

2015-06-29 Thread David Kupka
me, ACK. -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Re: [Freeipa-devel] [PATCH] 878 topology: check topology in ipa-replica-manage del

2015-06-29 Thread David Kupka
with the deletion if any errors are found. https://fedorahosted.org/freeipa/ticket/4302 Patch with * changed error messages * removed question to force removal (--force is needed) attached. Works for me, ACK. -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list

Re: [Freeipa-devel] [PATCH] 879 Verify replication topology for a suffix

2015-06-29 Thread David Kupka
ute force check(only one server removed at a time). In other words, it's easy. Computing indegree and outdegree of each node is easy as well. Additional checks can be also added later. https://fedorahosted.org/freeipa/ticket/4302 Rebased patch attached. No new check was implemented.

[Freeipa-devel] [PATCH 0054] cermonger: Use private unix socket when DBus SystemBus is not, available.

2015-07-01 Thread David Kupka
-- David Kupka From ece6e155007e5ab1c13c4cb61977fec5c68c8e51 Mon Sep 17 00:00:00 2001 From: David Kupka Date: Wed, 1 Jul 2015 16:26:15 +0200 Subject: [PATCH] cermonger: Use private unix socket when DBus SystemBus is not available. --- ipaplatform/base/paths.py | 1 + ipapython

Re: [Freeipa-devel] [PATCH 0054] cermonger: Use private unix socket when DBus SystemBus is not, available.

2015-07-02 Thread David Kupka
On 01/07/15 16:31, David Kupka wrote: Updated patch attached. -- David Kupka From 65eb52bff00135f4feb84dfde1e56a69bc8ea438 Mon Sep 17 00:00:00 2001 From: David Kupka Date: Wed, 1 Jul 2015 16:26:15 +0200 Subject: [PATCH] cermonger: Use private unix socket when DBus SystemBus is not

Re: [Freeipa-devel] [PATCH] 882 ipa-replica-manage del: relax segment deletement check if, topology is disconnected

2015-07-02 Thread David Kupka
, therefore presence of the segment has to be ignored. part of: https://fedorahosted.org/freeipa/ticket/5072 patch 883 adds 180s timeout to the check and changes check interval from 1s to 2s. Works for me, ACK. -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list:

Re: [Freeipa-devel] [PATCH] 885 topology: make cn of new segment consistent with topology plugin

2015-07-02 Thread David Kupka
On 30/06/15 16:16, Petr Vobornik wrote: SSIA Works for me, ACK. -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Re: [Freeipa-devel] [PATCH] 884 topologysegment: hide direction and enable options

2015-07-02 Thread David Kupka
On 30/06/15 16:15, Petr Vobornik wrote: These options should not be touched by users yet. https://fedorahosted.org/freeipa/ticket/5061 Works for me, ACK. -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel

[Freeipa-devel] [PATCH 0055] ipa-replica-prepare: Do not create DNS zone it automatically.

2015-07-02 Thread David Kupka
Since ipa-replica-* tools will be soon removed I think this simple check should be enough. -- David Kupka From c97001b0724599c4fa4943c4f01d2458b51238ac Mon Sep 17 00:00:00 2001 From: David Kupka Date: Fri, 3 Jul 2015 05:59:55 +0200 Subject: [PATCH] ipa-replica-prepare: Do not create DNS zone

Re: [Freeipa-devel] [RFC] Community Portal - Where to go next?

2015-07-02 Thread David Kupka
of WebUI so I would package it together, iow in freeipa-server. Or create another package depending on freeipa-server. -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Re: [Freeipa-devel] [PATCH 0055] ipa-replica-prepare: Do not create DNS zone it automatically.

2015-07-07 Thread David Kupka
On 03/07/15 06:17, David Kupka wrote: Since ipa-replica-* tools will be soon removed I think this simple check should be enough. Updated patch attached. -- David Kupka From 3df59261538f6b28e158802d8f6e4a47dadeab84 Mon Sep 17 00:00:00 2001 From: David Kupka Date: Fri, 3 Jul 2015 05:59:55

Re: [Freeipa-devel] [PATCH 0054] cermonger: Use private unix socket when DBus SystemBus is not, available.

2015-07-07 Thread David Kupka
On 03/07/15 08:46, Martin Kosek wrote: On 07/03/2015 08:41 AM, Jan Cholasta wrote: Dne 2.7.2015 v 14:34 David Kupka napsal(a): On 01/07/15 16:31, David Kupka wrote: Updated patch attached. Client install works, but uninstall does not: # ipa-client-install --uninstall -U certmonger

Re: [Freeipa-devel] Meaning of two strings in plugins/service.py

2015-07-08 Thread David Kupka
f keytab". But Petr (added) is author of this code and should know better. -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Re: [Freeipa-devel] [PATCH] 0026..0027 #5096 enforce caacl for SAN principals

2015-07-08 Thread David Kupka
On 03/07/15 16:26, Fraser Tweedale wrote: The attached patches fix: - a bug that caused caacl false negatives for hosts principals - #5096 cert-request: enforce caacl for subjectAltName principals Thanks, Fraser Works for me, ACK. -- David Kupka -- Manage your subscription for the

Re: [Freeipa-devel] [PATCH] 897 fix error message when certificate CN is invalid

2015-07-09 Thread David Kupka
On 09/07/15 00:28, Petr Vobornik wrote: The error message was probably copied from mail address check below. ACK. -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http

Re: [Freeipa-devel] [PATCH 0284] stageuser-activate: show user name in error message instead of DN

2015-07-13 Thread David Kupka
On 10/07/15 14:51, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/5038 I reworded the error message to keep the same format as stageuser-add and user-add. Patch attached. Works for me, ACK. -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list: https

Re: [Freeipa-devel] [PATCH 0283] copy-schema-to-ca: allow to overwrite schema files

2015-07-14 Thread David Kupka
On 10/07/15 14:31, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/5034 Patch attached. Works for me, ACK. -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http

[Freeipa-devel] [PATCH 0057] Do not use anonymous bind in migration UI.

2015-07-15 Thread David Kupka
-binds.html) 3. Go to FreeIPA migration page (ipa.example.com/ipa/migration/) and enter name and password of one of the migrated users. Without this patch you will get an error page. -- David Kupka From a9c50987842a08eb6928bd662a1db57b85d4b3cd Mon Sep 17 00:00:00 2001 From: David Kupka Date

Re: [Freeipa-devel] [PATCH 0057] Do not use anonymous bind in migration UI.

2015-07-15 Thread David Kupka
On 15/07/15 15:34, Jan Cholasta wrote: Dne 15.7.2015 v 15:21 David Kupka napsal(a): https://fedorahosted.org/freeipa/ticket/4953 To test this patch: 1. Migrate users from LDAP or other FreeIPA server (https://www.freeipa.org/page/Howto/Migration) 2. Disable anonymous bind to Directory Server

Re: [Freeipa-devel] [PATCH 0057] Do not use anonymous bind in migration UI.

2015-07-16 Thread David Kupka
On 15/07/15 16:04, David Kupka wrote: On 15/07/15 15:34, Jan Cholasta wrote: Dne 15.7.2015 v 15:21 David Kupka napsal(a): https://fedorahosted.org/freeipa/ticket/4953 To test this patch: 1. Migrate users from LDAP or other FreeIPA server (https://www.freeipa.org/page/Howto/Migration) 2

Re: [Freeipa-devel] [PATCH 0054] cermonger: Use private unix socket when DBus SystemBus is not, available.

2015-07-20 Thread David Kupka
On 15/07/15 13:41, Jan Cholasta wrote: Dne 7.7.2015 v 16:51 David Kupka napsal(a): On 03/07/15 08:46, Martin Kosek wrote: On 07/03/2015 08:41 AM, Jan Cholasta wrote: Dne 2.7.2015 v 14:34 David Kupka napsal(a): On 01/07/15 16:31, David Kupka wrote: Updated patch attached. Client

Re: [Freeipa-devel] [PATCH] 0035 client: Update DNS with all available local IP addresses.

2015-07-27 Thread David Kupka
On 15/01/15 17:13, David Kupka wrote: On 01/15/2015 03:22 PM, David Kupka wrote: On 01/15/2015 12:43 PM, David Kupka wrote: On 01/12/2015 06:34 PM, Martin Basti wrote: On 09/01/15 14:43, David Kupka wrote: On 01/07/2015 04:15 PM, Martin Basti wrote: On 07/01/15 12:27, David Kupka wrote

Re: [Freeipa-devel] [PATCH] 0035 client: Update DNS with all available local IP addresses.

2015-07-28 Thread David Kupka
On 27/07/15 16:45, David Kupka wrote: On 15/01/15 17:13, David Kupka wrote: On 01/15/2015 03:22 PM, David Kupka wrote: On 01/15/2015 12:43 PM, David Kupka wrote: On 01/12/2015 06:34 PM, Martin Basti wrote: On 09/01/15 14:43, David Kupka wrote: On 01/07/2015 04:15 PM, Martin Basti wrote: On

Re: [Freeipa-devel] [PATCH 0294] ULC: fix stageuser-add --from-delete command

2015-07-28 Thread David Kupka
. IMO this should be separate command, I will open a discussion. Works for me, ACK. It would be better to leave the ticket open until the issue is fully resolved. -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-

Re: [Freeipa-devel] [PATCH 0286, 0290] Sysrestore: copy files instead of moving them to avoid SELinux issues

2015-07-29 Thread David Kupka
le and raises AVC. In this case we can freely use mv -z since target platforms are Fedora and newest RHEL. The new patch fixing specfile attached. Works for me, ACK. -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa

[Freeipa-devel] [PATCH 0058] dns: do not add (forward)zone if it is already resolvable.

2015-07-29 Thread David Kupka
https://fedorahosted.org/freeipa/ticket/5087 -- David Kupka From 4ee9794a8d857e5a71f12b8fd05d337bbb4b062a Mon Sep 17 00:00:00 2001 From: David Kupka Date: Thu, 2 Jul 2015 15:10:40 +0200 Subject: [PATCH] dns: do not add (forward)zone if it is already resolvable. Check if the zone user wants to

Re: [Freeipa-devel] [PATCH] 907 webui: add LDAP vs Kerberos behavior description to user auth types

2015-08-10 Thread David Kupka
https://fedorahosted.org/freeipa/ticket/4935 Works for me, ACK. -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

[Freeipa-devel] [PATCH 0059] dbus: Create empty dbus.Array with specified signature

2015-08-10 Thread David Kupka
I was installing freeipa-server earlier today and it failed with "Unable to guess signature from empty list". I was unable to reproduce it but there is now harm in explicitly specifying the signature of the empty list to prevent this issue. -- David

Re: [Freeipa-devel] Replace stageuser-add --from-delete with user-undel --to-staged

2015-08-12 Thread David Kupka
d screen https://pvoborni.fedorapeople.org/images/user-lifecycle.jpg Thierry, do you agree with this? Martin^2 Hello, I really like the idea (as well as the drawing) of having the same cli for both active/deleted user. About the exact verb 'user-stage', I am always bad at this exe

Re: [Freeipa-devel] [PATCH 471] ULC: Prevent preserved users from being assigned membership

2015-08-12 Thread David Kupka
On 12/08/15 12:22, Jan Cholasta wrote: Hi, the attached patch fixes <https://fedorahosted.org/freeipa/ticket/5170>. Honza Works for me, ACK. -- David Kupka -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel Contrib

[Freeipa-devel] [PATCH 0060] user-undel: Fix error messages.

2015-08-12 Thread David Kupka
https://fedorahosted.org/freeipa/ticket/5207 Requires patch freeipa-jcholast-471.1. -- David Kupka From 3fbef326a6235297b95703edd2e77f8e7ab4e446 Mon Sep 17 00:00:00 2001 From: David Kupka Date: Thu, 13 Aug 2015 08:11:38 +0200 Subject: [PATCH] user-undel: Fix error messages. https

Re: [Freeipa-devel] [PATCH 0060] user-undel: Fix error messages.

2015-08-17 Thread David Kupka
On 14/08/15 17:18, Martin Basti wrote: On 08/13/2015 08:17 AM, David Kupka wrote: https://fedorahosted.org/freeipa/ticket/5207 Requires patch freeipa-jcholast-471.1. NACK This patch causes internal server error ipa user-del user --preserve [Fri Aug 14 17:16:13.691565 2015] [wsgi:error

Re: [Freeipa-devel] [PATCH] 0035 client: Update DNS with all available local IP addresses.

2015-08-18 Thread David Kupka
On 31/07/15 18:31, Martin Basti wrote: On 28/07/15 09:52, David Kupka wrote: On 27/07/15 16:45, David Kupka wrote: On 15/01/15 17:13, David Kupka wrote: On 01/15/2015 03:22 PM, David Kupka wrote: On 01/15/2015 12:43 PM, David Kupka wrote: On 01/12/2015 06:34 PM, Martin Basti wrote: On 09

[Freeipa-devel] Subject: [PATCH 0061-2] Fix backup/restore (#5071)

2015-08-19 Thread David Kupka
https://fedorahosted.org/freeipa/ticket/5071 -- David Kupka From c4a72b64aab5abfde15f06b037da1c3ab2cfa220 Mon Sep 17 00:00:00 2001 From: David Kupka Date: Thu, 13 Aug 2015 16:41:23 +0200 Subject: [PATCH 1/2] Add /etc/tmpfiles.d/dirsrv-.conf to backup https://fedorahosted.org/freeipa/ticket

Re: [Freeipa-devel] Subject: [PATCH 0061-2] Fix backup/restore (#5071)

2015-08-19 Thread David Kupka
On 19/08/15 09:21, David Kupka wrote: https://fedorahosted.org/freeipa/ticket/5071 Updated patches attached. -- David Kupka From 2924ddd15f5a7ee7a5c2dcdb3fdb37fedf1a5f3a Mon Sep 17 00:00:00 2001 From: David Kupka Date: Thu, 13 Aug 2015 16:41:23 +0200 Subject: [PATCH 1/2] Add /etc/tmpfiles.d

Re: [Freeipa-devel] Subject: [PATCH 0061-2] Fix backup/restore (#5071)

2015-08-19 Thread David Kupka
On 19/08/15 10:44, David Kupka wrote: On 19/08/15 09:21, David Kupka wrote: https://fedorahosted.org/freeipa/ticket/5071 Updated patches attached. Removed copy-pasted returns. Updated patch attached. -- David Kupka From 04644ea40b5bcf6385f5e68a8407bc6b8858b93c Mon Sep 17 00:00:00 2001 From

Re: [Freeipa-devel] [PATCH 0063] client: Update DNS with all available local IP addresses.

2015-08-19 Thread David Kupka
On 19/08/15 11:06, Jan Cholasta wrote: On 19.8.2015 10:36, Martin Basti wrote: On 08/18/2015 10:53 PM, Martin Basti wrote: On 08/18/2015 08:02 PM, David Kupka wrote: On 31/07/15 18:31, Martin Basti wrote: On 28/07/15 09:52, David Kupka wrote: On 27/07/15 16:45, David Kupka wrote: On 15

Re: [Freeipa-devel] [PATCH 0058] dns: do not add (forward)zone if it is already resolvable.

2015-08-20 Thread David Kupka
On 31/07/15 13:32, Martin Basti wrote: On 30/07/15 14:38, Martin Basti wrote: On 29/07/15 16:12, David Kupka wrote: https://fedorahosted.org/freeipa/ticket/5087 NACK You forgot to update API.txt file Thanks for catching that. Updated patch attached. I'm just curious, what is the r

Re: [Freeipa-devel] [PATCH 0058] dns: do not add (forward)zone if it is already resolvable.

2015-08-25 Thread David Kupka
On 24/08/15 16:51, Martin Basti wrote: On 08/20/2015 10:28 AM, David Kupka wrote: On 31/07/15 13:32, Martin Basti wrote: On 30/07/15 14:38, Martin Basti wrote: On 29/07/15 16:12, David Kupka wrote: https://fedorahosted.org/freeipa/ticket/5087 NACK You forgot to update API.txt file

Re: [Freeipa-devel] [PATCH 0058, 0064] dns: do not add (forward)zone if it is already resolvable.

2015-08-25 Thread David Kupka
On 25/08/15 10:37, David Kupka wrote: On 24/08/15 16:51, Martin Basti wrote: On 08/20/2015 10:28 AM, David Kupka wrote: On 31/07/15 13:32, Martin Basti wrote: On 30/07/15 14:38, Martin Basti wrote: On 29/07/15 16:12, David Kupka wrote: https://fedorahosted.org/freeipa/ticket/5087 NACK

[Freeipa-devel] [PATCH 0065] vault: Limit size of data stored in vault

2015-08-26 Thread David Kupka
https://fedorahosted.org/freeipa/ticket/5231 -- David Kupka From f86f4f89d1083c1474d8c470ae3b0f85ed1eb6bb Mon Sep 17 00:00:00 2001 From: David Kupka Date: Wed, 26 Aug 2015 14:11:21 +0200 Subject: [PATCH] vault: Limit size of data stored in vault https://fedorahosted.org/freeipa/ticket/5231

[Freeipa-devel] [PATCH 0066] ipactl: Do not start/stop/restart single service multiple times

2015-08-26 Thread David Kupka
https://fedorahosted.org/freeipa/ticket/5248 -- David Kupka From 349e8ada21526cb704d9d876a151aaa2764970f8 Mon Sep 17 00:00:00 2001 From: David Kupka Date: Wed, 26 Aug 2015 15:10:16 +0200 Subject: [PATCH] ipactl: Do not start/stop/restart single service multiple times In case multiple services

Re: [Freeipa-devel] [PATCH 0065] vault: Limit size of data stored in vault

2015-08-26 Thread David Kupka
On 26/08/15 15:45, Petr Vobornik wrote: On 08/26/2015 02:13 PM, David Kupka wrote: https://fedorahosted.org/freeipa/ticket/5231 Attaching updated patch. With changes discussed offline. Changes works for me, ACK. Not related to the patch: This patch limits the size to 1MB instead of

Re: [Freeipa-devel] [PATCH 0066] ipactl: Do not start/stop/restart single service multiple times

2015-08-26 Thread David Kupka
On 26/08/15 17:49, Tomas Babej wrote: On 08/26/2015 03:16 PM, David Kupka wrote: https://fedorahosted.org/freeipa/ticket/5248 +def deduplicate(lst): +new_lst = [] +s = set(lst) +for i in lst: +if i in s: +s.remove(i) +new_lst.append(i

<    1   2   3   4   5   >