Re: [SSSD] [PATCH] Don't pass user input as a printf format string argument

2014-01-08 Thread Jakub Hrozek
On Wed, Jan 08, 2014 at 09:02:52PM +0100, Stef Walter wrote: > On 08.01.2014 17:59, Simo Sorce wrote: > > On Wed, 2014-01-08 at 11:21 +0100, Stef Walter wrote: > >> On 07.01.2014 22:21, Simo Sorce wrote: > >>> Sorry I forgot another, I think you should either set errno on errors, > >>> or return an

Re: [SSSD] ding-libs: symbol versioning is necessary

2014-01-08 Thread Lukas Slebodnik
On (08/01/14 20:12), Jan Engelhardt wrote: > >On Wednesday 2014-01-08 19:37, Lukas Slebodnik wrote: >> >>>to indicate the new backwards-incompatibility. People, -version-info >>>1:0:0 => -version-info 2:0:1 is not enough! You must either >>> >>It was not backward incompatible change in the refarray

Re: [SSSD] [PATCH] Don't pass user input as a printf format string argument

2014-01-08 Thread Stef Walter
On 08.01.2014 17:59, Simo Sorce wrote: > On Wed, 2014-01-08 at 11:21 +0100, Stef Walter wrote: >> On 07.01.2014 22:21, Simo Sorce wrote: >>> Sorry I forgot another, I think you should either set errno on errors, >>> or return an errno_t instead of -1. Just returning -1 for all errors is >>> a poor

Re: [SSSD] ding-libs: symbol versioning is necessary

2014-01-08 Thread Jan Engelhardt
On Wednesday 2014-01-08 19:37, Lukas Slebodnik wrote: > >>to indicate the new backwards-incompatibility. People, -version-info >>1:0:0 => -version-info 2:0:1 is not enough! You must either >> >It was not backward incompatible change in the refarray, but libini_config >requires new version of libre

[SSSD] Access denied for users when using format DOMAIN\user

2014-01-08 Thread Pavel Reichl
Hello, please see attached patches. PR >From d5fbd3c3ef70f9d890f4eb73a97adb840a64470e Mon Sep 17 00:00:00 2001 From: Pavel Reichl Date: Wed, 8 Jan 2014 15:46:57 + Subject: [PATCH 1/2] simple access: match objects using flat name Use flat name to recognise users and groups belonging to main

Re: [SSSD] [PATCH] Don't pass user input as a printf format string argument

2014-01-08 Thread Simo Sorce
On Wed, 2014-01-08 at 11:21 +0100, Stef Walter wrote: > On 07.01.2014 22:21, Simo Sorce wrote: > > On Tue, 2014-01-07 at 21:31 +0100, Stef Walter wrote: > >> On 07.01.2014 20:34, Simo Sorce wrote: > >>> Ok fine, makes sense once explained (need this explanation in the > >>> docs/headers), but then

[SSSD] [PATCH] LDAP: Add a new error code for malformed access control filter

2014-01-08 Thread Jakub Hrozek
Hi, the attached patch solves https://fedorahosted.org/sssd/ticket/2164 by special casing an openldap return code. One drawback of the patch is that if the new return code bubbles all the way up, calls to strerror (as opposed to sss_strerror) wouldn't be able to print a nice error message. This p

Re: [SSSD] [PATCH] Fix FAST authentication for FreeIPA two-factor authentication case

2014-01-08 Thread Jakub Hrozek
On Tue, Dec 24, 2013 at 06:34:24AM -0500, Alexander Bokovoy wrote: > Hi! > > FAST auth is broken for OTP case at least for FreeIPA because krb5_child > returns an empty SSS_OTP message as the last one in the buffer. This message > never got processed by the krb5_child_handler due to the fact that

Re: [SSSD] forest attribute in AD domains

2014-01-08 Thread Sumit Bose
On Thu, Dec 19, 2013 at 09:10:59PM +0100, Pavel Reichl wrote: > On Thu, 2013-12-19 at 13:54 +0100, Sumit Bose wrote: > > On Tue, Dec 17, 2013 at 08:02:58PM +0100, Pavel Reichl wrote: > > > Hello, > > > > > > please see attached patch fixing missing attribute forest for AD > > > domains. > > > > t

Re: [SSSD] [Patch] Cmocka unit test patch for authtok module

2014-01-08 Thread Jakub Hrozek
On Wed, Jan 08, 2014 at 01:18:58PM +0545, Pallavi Jha wrote: > Hi, > > Thank you for the patch. I checked it and have included the changes in > the patch attached with this mail. Please look into it. ACK ___ sssd-devel mailing list sssd-devel@lists.fedo

Re: [SSSD] [PATCH] Don't pass user input as a printf format string argument

2014-01-08 Thread Stef Walter
On 07.01.2014 22:21, Simo Sorce wrote: > On Tue, 2014-01-07 at 21:31 +0100, Stef Walter wrote: >> On 07.01.2014 20:34, Simo Sorce wrote: >>> Ok fine, makes sense once explained (need this explanation in the >>> docs/headers), but then use a different name. >>> >>> If I see safe_snprintf, I assume t

Re: [SSSD] IPA: fix for recent AD group membership changes

2014-01-08 Thread Jakub Hrozek
On Tue, Jan 07, 2014 at 03:46:51PM +0100, Sumit Bose wrote: > Hi, > > some of the recent changes to the AD group membership lookups broke > those lookups for the IPA server mode. This patch should fix it. > > bye, > Sumit ACK After applying the patch, the IPA groups the AD user is a member of v

Re: [SSSD] [PATCH] LDAP: Fix typo and use the right attribute map

2014-01-08 Thread Alexander Bokovoy
On Wed, 08 Jan 2014, Jakub Hrozek wrote: Hi, the attached patch fixes #2191. From f12c4bb11ff35cdd785026aa571db8f659127763 Mon Sep 17 00:00:00 2001 From: Jakub Hrozek Date: Wed, 8 Jan 2014 08:11:46 +0100 Subject: [PATCH] LDAP: Fix typo and use the right attribute map https://fedorahosted.or