[SSSD] Re: [PATCH] libipa_hbac cleanup patches

2016-03-11 Thread Lukas Slebodnik
On (10/03/16 20:37), Lukas Slebodnik wrote: >On (10/03/16 20:02), Jakub Hrozek wrote: >>On Thu, Mar 10, 2016 at 12:53:44PM +0100, Lukas Slebodnik wrote: >>> diff --git a/Makefile.am b/Makefile.am >>> index d6eb0fc..f8111d0 100644 >>> --- a/Makefile.am >>> +++ b/Makefile.am >>> @@ -946,6 +946,10 @@

[SSSD] Re: [PATCH] libipa_hbac cleanup patches

2016-03-11 Thread Jakub Hrozek
On Fri, Mar 11, 2016 at 10:07:16AM +0100, Lukas Slebodnik wrote: > On (10/03/16 20:37), Lukas Slebodnik wrote: > >On (10/03/16 20:02), Jakub Hrozek wrote: > >>On Thu, Mar 10, 2016 at 12:53:44PM +0100, Lukas Slebodnik wrote: > >>> diff --git a/Makefile.am b/Makefile.am > >>> index d6eb0fc..f8111d0 1

[SSSD] Re: [PATCH] pam_sss: reorder pam_message array

2016-03-11 Thread Sumit Bose
On Thu, Mar 10, 2016 at 12:54:15PM +0100, Pavel Březina wrote: > On 03/08/2016 05:55 PM, Sumit Bose wrote: > >Hi, > > > >This patch fixes a 2FA issues observed with sudo. See commit message for > >details. > > > >bye, > >Sumit > > > > > >0001-pam_sss-reorder-pam_message-array.patch > > > > > > From

[SSSD] Re: [PATCH] IPA SUDO: support old ipasudocmd rdn

2016-03-11 Thread Jakub Hrozek
On Fri, Mar 04, 2016 at 02:00:57PM +0100, Pavel Březina wrote: > https://fedorahosted.org/sssd/ticket/2969 I'm sorry, but I still can't use sudo with IPA 3.x server: (Fri Mar 11 10:01:02 2016) [sssd[be[obsolete.test]]] [ipa_sudo_fetch_cmds] (0x0400): About to fetch sudo commands (Fri Mar 11 10:01

[SSSD] Re: [PATCH] libipa_hbac cleanup patches

2016-03-11 Thread Jakub Hrozek
On Thu, Mar 10, 2016 at 08:37:23PM +0100, Lukas Slebodnik wrote: > On (10/03/16 20:02), Jakub Hrozek wrote: > >On Thu, Mar 10, 2016 at 12:53:44PM +0100, Lukas Slebodnik wrote: > >> diff --git a/Makefile.am b/Makefile.am > >> index d6eb0fc..f8111d0 100644 > >> --- a/Makefile.am > >> +++ b/Makefile.a

[SSSD] Re: Tlog integration and packages

2016-03-11 Thread Jakub Hrozek
On Thu, Mar 10, 2016 at 09:10:30PM +0200, Nikolai Kondrashov wrote: > On 03/04/2016 12:54 PM, Jakub Hrozek wrote: > >I was playing with tlog yesterday and for the 'local configuration' I > >suggest we start small and avoid adding too many options, because we'd > >have to support them for a long tim

[SSSD] Re: [PATCH] CLIENT: Retry request after EPIPE

2016-03-11 Thread Jakub Hrozek
On Fri, Feb 26, 2016 at 09:01:33PM +0100, Lukas Slebodnik wrote: > On (26/02/16 16:22), Lukas Slebodnik wrote: > >On (23/02/16 14:28), Lukas Slebodnik wrote: > >>On (23/02/16 13:37), Jakub Hrozek wrote: > >>>On Thu, Feb 18, 2016 at 02:04:54PM +0100, Lukas Slebodnik wrote: > ehlo, > > >>>

[SSSD] Re: [PATCH] Add a test for external group members resolution

2016-03-11 Thread Lukas Slebodnik
On (10/03/16 13:12), Pavel Březina wrote: >On 03/05/2016 03:03 PM, Jakub Hrozek wrote: >>Hi, >> >>I was in a hurry when I submitted the patch for external group members, >>so I didn't add a test. Bad developer, no cookie. >> >>The attached patch adds a test for that code. > >Ack. http://sssd-ci.duc

[SSSD] Re: [PATCH] CLIENT: Retry request after EPIPE

2016-03-11 Thread Lukas Slebodnik
On (11/03/16 11:41), Jakub Hrozek wrote: >On Fri, Feb 26, 2016 at 09:01:33PM +0100, Lukas Slebodnik wrote: >> On (26/02/16 16:22), Lukas Slebodnik wrote: >> >On (23/02/16 14:28), Lukas Slebodnik wrote: >> >>On (23/02/16 13:37), Jakub Hrozek wrote: >> >>>On Thu, Feb 18, 2016 at 02:04:54PM +0100, Luk

[SSSD] Re: [PATCH] IPA SUDO: support old ipasudocmd rdn

2016-03-11 Thread Pavel Březina
On 03/11/2016 11:03 AM, Jakub Hrozek wrote: On Fri, Mar 04, 2016 at 02:00:57PM +0100, Pavel Březina wrote: https://fedorahosted.org/sssd/ticket/2969 I'm sorry, but I still can't use sudo with IPA 3.x server: (Fri Mar 11 10:01:02 2016) [sssd[be[obsolete.test]]] [ipa_sudo_fetch_cmds] (0x0400):

[SSSD] Re: [PATCH] pam_sss: reorder pam_message array

2016-03-11 Thread Pavel Březina
On 03/11/2016 10:41 AM, Sumit Bose wrote: On Thu, Mar 10, 2016 at 12:54:15PM +0100, Pavel Březina wrote: On 03/08/2016 05:55 PM, Sumit Bose wrote: Hi, This patch fixes a 2FA issues observed with sudo. See commit message for details. bye, Sumit 0001-pam_sss-reorder-pam_message-array.patch

[SSSD] Re: Tlog integration and packages

2016-03-11 Thread Nikolai Kondrashov
On 03/11/2016 12:21 PM, Jakub Hrozek wrote: On Thu, Mar 10, 2016 at 09:10:30PM +0200, Nikolai Kondrashov wrote: On 03/04/2016 12:54 PM, Jakub Hrozek wrote: I was even wondering if it wasn't easiest to always set the original shell as a PAM env variable if a shell is overriden? If we did that, w

[SSSD] Re: [PATCH]: test ldap provider with TLS or SSL

2016-03-11 Thread Nikolai Kondrashov
Hi Dan, Thanks a lot for your work! Please see my comments below. On 03/11/2016 06:29 AM, Dan Lavu wrote: Updated patch is attached, There were a few more packages I had to install to get CI running for Debian, should we had these to the makefile? root@sssd2:~# apt-get python-openssl dpkg

[SSSD] Re: [PATCH]: test ldap provider with TLS or SSL

2016-03-11 Thread Dan Lavu
WOAH, that's a lot of comments! ;) Thanks for taking the time, I have some questions inline and I'll start working on improving the code. On Fri, Mar 11, 2016 at 1:16 PM, Nikolai Kondrashov < nikolai.kondras...@redhat.com> wrote: > Hi Dan, > > Thanks a lot for your work! Please see my comments bel