Re: [SSSD] Understanding entry_negative_timeout

2013-09-20 Thread Jean-Baptiste Denis
On 09/19/2013 10:31 AM, Jean-Baptiste Denis wrote: Ok, I'll do that. I think I should wait the new version of your patch (goto/errno). I've tested the updated patch (just before Simo's remark) and tested it : it works, the negative result is cached and the request does not it the ldap domain

Re: [SSSD] [PATCH] AD: Failure to get flat name is not fatal

2013-09-20 Thread Pavel Březina
On 09/19/2013 07:03 PM, Jakub Hrozek wrote: On Thu, Sep 19, 2013 at 10:47:49AM +0200, Pavel Březina wrote: On 09/18/2013 07:26 PM, Jakub Hrozek wrote: On Wed, Sep 18, 2013 at 04:42:38PM +0200, Pavel Březina wrote: On 09/17/2013 10:18 PM, Jakub Hrozek wrote: On Fri, Sep 13, 2013 at 01:04:28PM

Re: [SSSD] [PATCH] NSS: Set UID and GID to negative cache after searching all domains

2013-09-20 Thread Pavel Březina
On 09/20/2013 02:30 AM, Simo Sorce wrote: On Thu, 2013-09-19 at 18:45 +0200, Jakub Hrozek wrote: On Wed, Sep 18, 2013 at 10:40:13PM +0200, Jakub Hrozek wrote: On Wed, Sep 18, 2013 at 01:41:36PM -0400, Simo Sorce wrote: On Wed, 2013-09-18 at 17:58 +0200, Jakub Hrozek wrote: Hi, the first

Re: [SSSD] Design Discussion: Improving AD provider access control

2013-09-20 Thread Pavel Březina
On 09/16/2013 03:34 PM, Jakub Hrozek wrote: On Mon, Sep 16, 2013 at 10:15:58AM +0200, Pavel Březina wrote: On 09/13/2013 02:57 PM, Jakub Hrozek wrote: Hi, I created a design page that describes a proposed way of improving the current AD provider access control. The main ticket that tracks the

Re: [SSSD] [PATCH] NSS: Set UID and GID to negative cache after searching all domains

2013-09-20 Thread Lukas Slebodnik
On (20/09/13 10:54), Pavel Březina wrote: On 09/20/2013 02:30 AM, Simo Sorce wrote: On Thu, 2013-09-19 at 18:45 +0200, Jakub Hrozek wrote: On Wed, Sep 18, 2013 at 10:40:13PM +0200, Jakub Hrozek wrote: On Wed, Sep 18, 2013 at 01:41:36PM -0400, Simo Sorce wrote: On Wed, 2013-09-18 at 17:58 +0200,

Re: [SSSD] [PATCH] man: improve sssd-sudo manual page

2013-09-20 Thread Pavel Březina
On 09/17/2013 03:39 PM, Jakub Hrozek wrote: On Tue, Sep 17, 2013 at 02:00:11PM +0200, Pavel Březina wrote: +emphasisNote/emphasis: in order to use netgroups or IPA +hostgroups in sudo rules, you also need to correctly set +citerefentry +

Re: [SSSD] Understanding entry_negative_timeout

2013-09-20 Thread Jakub Hrozek
On Fri, Sep 20, 2013 at 10:19:13AM +0200, Jean-Baptiste Denis wrote: On 09/19/2013 10:31 AM, Jean-Baptiste Denis wrote: Ok, I'll do that. I think I should wait the new version of your patch (goto/errno). I've tested the updated patch (just before Simo's remark) and tested it : it works,

[SSSD] [PATCH] man: server side password policies always takes precedence

2013-09-20 Thread Pavel Březina
https://fedorahosted.org/sssd/ticket/2091 From 1cfaa9fb38d5a8bf0575b0bbe40a65450f39234a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Pavel=20B=C5=99ezina?= pbrez...@redhat.com Date: Fri, 20 Sep 2013 12:52:49 +0200 Subject: [PATCH] man: server side password policies always takes precedence

[SSSD] [PATCHES] Fix offline authentication for the AD provider

2013-09-20 Thread Sumit Bose
Hi, with the following two patches offline authentication in the AD provider is working again and https://fedorahosted.org/sssd/ticket/2060 should be fixed. I started working on a unit test for find_or_guess_upn() but it is not finished yet because of the number of internal structs needed which

Re: [SSSD] [PATCH] NSS: Set UID and GID to negative cache after searching all domains

2013-09-20 Thread Jakub Hrozek
On Fri, Sep 20, 2013 at 11:00:18AM +0200, Lukas Slebodnik wrote: On (20/09/13 10:54), Pavel Březina wrote: On 09/20/2013 02:30 AM, Simo Sorce wrote: On Thu, 2013-09-19 at 18:45 +0200, Jakub Hrozek wrote: On Wed, Sep 18, 2013 at 10:40:13PM +0200, Jakub Hrozek wrote: On Wed, Sep 18, 2013 at

Re: [SSSD] [PATCH] sdap_domain_add: remove too strict consistency check

2013-09-20 Thread Jakub Hrozek
On Fri, Sep 20, 2013 at 01:49:08PM +0200, Sumit Bose wrote: Hi, without the following patch member domains in a trusted forest cannot be properly initialized in the IPA provider. bye, Sumit ACK (We talked about removing this code earlier with Sumit on IRC)

Re: [SSSD] [PATCH] Two minor man page patches

2013-09-20 Thread Jakub Hrozek
On Tue, Sep 17, 2013 at 02:09:08PM +0200, Pavel Březina wrote: On 09/16/2013 05:22 PM, Jakub Hrozek wrote: I found these minor issues in our man pages, when triaging support issues with Red Hat GSS earlier today. The first patch changes the subtitle of the man pages. I wasn't completely

Re: [SSSD] [PATCHES] Alignment issues reported by Clang

2013-09-20 Thread Dmitri Pal
On 09/19/2013 08:28 PM, Simo Sorce wrote: On Thu, 2013-09-19 at 18:22 +0200, Lukas Slebodnik wrote: On (19/09/13 09:00), Simo Sorce wrote: On Thu, 2013-09-19 at 09:17 +0200, Sumit Bose wrote: On Wed, Sep 18, 2013 at 07:07:46PM +0200, Lukas Slebodnik wrote: On (12/09/13 16:55), Michal Židek

Re: [SSSD] [PATCH] Two minor man page patches

2013-09-20 Thread Pavel Březina
On 09/20/2013 03:57 PM, Jakub Hrozek wrote: On Tue, Sep 17, 2013 at 02:09:08PM +0200, Pavel Březina wrote: On 09/16/2013 05:22 PM, Jakub Hrozek wrote: I found these minor issues in our man pages, when triaging support issues with Red Hat GSS earlier today. The first patch changes the subtitle

[SSSD] [PATCHES] Fix old ccache testing behavior

2013-09-20 Thread Simo Sorce
Addresses #2053 and #2094 Check old ccaches only if needed, always precreate containing directory if we are goign to proceed with authentication and always fallback to old algorithm to check user presence on the system if systemd-login fails or returns negative result. (Patches as agreed on IRC

Re: [SSSD] [PATCH] man: improve sssd-sudo manual page

2013-09-20 Thread Jakub Hrozek
On Fri, Sep 20, 2013 at 01:21:33PM +0200, Jakub Hrozek wrote: On Fri, Sep 20, 2013 at 11:45:38AM +0200, Pavel Březina wrote: On 09/17/2013 03:39 PM, Jakub Hrozek wrote: On Tue, Sep 17, 2013 at 02:00:11PM +0200, Pavel Březina wrote: +emphasisNote/emphasis: in order to use

Re: [SSSD] [PATCH] Two minor man page patches

2013-09-20 Thread Jakub Hrozek
On Fri, Sep 20, 2013 at 07:01:04PM +0200, Pavel Březina wrote: On 09/20/2013 03:57 PM, Jakub Hrozek wrote: On Tue, Sep 17, 2013 at 02:09:08PM +0200, Pavel Březina wrote: On 09/16/2013 05:22 PM, Jakub Hrozek wrote: I found these minor issues in our man pages, when triaging support issues with

Re: [SSSD] [PATCH] sdap_domain_add: remove too strict consistency check

2013-09-20 Thread Jakub Hrozek
On Fri, Sep 20, 2013 at 02:34:27PM +0200, Jakub Hrozek wrote: On Fri, Sep 20, 2013 at 01:49:08PM +0200, Sumit Bose wrote: Hi, without the following patch member domains in a trusted forest cannot be properly initialized in the IPA provider. bye, Sumit ACK (We talked about