[SSSD] Announcing SSSD 1.14.0

2016-07-07 Thread Jakub Hrozek
=== SSSD 1.14.0 === The SSSD team is proud to announce the release of version 1.14.0 of the System Security Services Daemon. As always, the source is available from https://fedorahosted.org/sssd RPM packages will be made available for Fedora shortly. == Feedback == Please

[SSSD] Re: [PATCH] sssctl: manual page

2016-07-07 Thread Jakub Hrozek
On Thu, Jul 07, 2016 at 07:18:55PM +0200, Michal Židek wrote: > On 07/07/2016 07:12 PM, Michal Židek wrote: > > On 07/07/2016 06:45 PM, Michal Židek wrote: > > > The man page looks good to me with exception > > > for one detail (see inline) > > > > > > On 07/04/2016 12:45 PM, Pavel Březina wrote:

[SSSD] Re: [PATCH] sssctl: manual page

2016-07-07 Thread Michal Židek
On 07/07/2016 07:12 PM, Michal Židek wrote: On 07/07/2016 06:45 PM, Michal Židek wrote: The man page looks good to me with exception for one detail (see inline) On 07/04/2016 12:45 PM, Pavel Březina wrote: + +COMMON OPTIONS + +Those options are available with

[SSSD] Re: [PATCH] SSH-CERT: always initialize cert_verify_opts

2016-07-07 Thread Jakub Hrozek
On Thu, Jul 07, 2016 at 06:13:04PM +0200, Jakub Hrozek wrote: > On Fri, Jun 17, 2016 at 02:50:36PM +0200, Sumit Bose wrote: > > Hi, > > > > please find attached two small patches related to the conversion of the > > public key in a certificate to a public ssh-key. > > > > The first fixes an

[SSSD] Re: [PATCH] SSH-CERT: always initialize cert_verify_opts

2016-07-07 Thread Jakub Hrozek
On Fri, Jun 17, 2016 at 02:50:36PM +0200, Sumit Bose wrote: > Hi, > > please find attached two small patches related to the conversion of the > public key in a certificate to a public ssh-key. > > The first fixes an issue which should only happen in master. The second > might be useful for

[SSSD] Re: [PATCH] CONFIGURE: Inform about optional build dependencies

2016-07-07 Thread Jakub Hrozek
On Thu, Jul 07, 2016 at 06:06:26PM +0200, Jakub Hrozek wrote: > On Thu, Jul 07, 2016 at 01:05:39PM +0200, Lukas Slebodnik wrote: > > On (05/07/16 07:59), Jakub Hrozek wrote: > > >On Fri, Jul 01, 2016 at 08:45:53AM +0200, Lukas Slebodnik wrote: > > >> ehlo, > > >> > > >> We usually inform about

[SSSD] Re: [PATCH] CONFIGURE: Inform about optional build dependencies

2016-07-07 Thread Jakub Hrozek
On Thu, Jul 07, 2016 at 01:05:39PM +0200, Lukas Slebodnik wrote: > On (05/07/16 07:59), Jakub Hrozek wrote: > >On Fri, Jul 01, 2016 at 08:45:53AM +0200, Lukas Slebodnik wrote: > >> ehlo, > >> > >> We usually inform about optional build dependencies at configure time > >> and which option can

[SSSD] Fwd: Re: [PATCH] LDAP: Lookup services by all protocols unless a protocol is specified

2016-07-07 Thread Jakub Hrozek
sssd-devel seems to be eating our mails lately, resending - Forwarded Message - From: "Jakub Hrozek" To: sssd-devel@lists.fedorahosted.org Sent: Thursday, July 7, 2016 4:44:30 PM Subject: Re: [SSSD] Re: [PATCH] LDAP: Lookup services by all protocols unless a protocol

[SSSD] Re: [PATCH] MAN: Config file merging

2016-07-07 Thread Lukas Slebodnik
On (07/07/16 10:05), Dan Lavu wrote: >Looks good, ACK. > master: * c82789aad172d7ebd9f616510bdbe950dccd51ac LS ___ sssd-devel mailing list sssd-devel@lists.fedorahosted.org https://lists.fedorahosted.org/admin/lists/sssd-devel@lists.fedorahosted.org

[SSSD] Re: [PATCH] MAN: Config file merging

2016-07-07 Thread Dan Lavu
Looks good, ACK. On Thu, Jul 7, 2016 at 4:39 AM, Michal Židek wrote: > On 07/04/2016 06:28 PM, Michal Židek wrote: > >> On 07/01/2016 10:34 PM, Dan Lavu wrote: >> >>> I couldn't apply your patch to my repo, so I just modified the text in >>> your patch. I have a question

[SSSD] Re: [PATCH] sssctl: Add config-check command

2016-07-07 Thread Lukas Slebodnik
On (07/07/16 15:21), Lukas Slebodnik wrote: >On (07/07/16 14:10), Michal Židek wrote: >>On 07/07/2016 01:54 PM, Michal Židek wrote: >>> On 07/07/2016 01:20 PM, Lukas Slebodnik wrote: >>> > On (07/07/16 12:37), Michal Židek wrote: >>> > > On 07/04/2016 05:27 PM, Michal Židek wrote: >>> > > > On

[SSSD] Re: [PATCH] sssctl: Add config-check command

2016-07-07 Thread Lukas Slebodnik
On (07/07/16 14:10), Michal Židek wrote: >On 07/07/2016 01:54 PM, Michal Židek wrote: >> On 07/07/2016 01:20 PM, Lukas Slebodnik wrote: >> > On (07/07/16 12:37), Michal Židek wrote: >> > > On 07/04/2016 05:27 PM, Michal Židek wrote: >> > > > On 07/01/2016 05:35 PM, Lukas Slebodnik wrote: >> > > >

[SSSD] Re: [PATCH] LDAP: Lookup services by all protocols unless a protocol is specified

2016-07-07 Thread Sumit Bose
On Thu, Jul 07, 2016 at 01:26:13PM +0200, Pavel Březina wrote: > On 07/07/2016 01:24 PM, Jakub Hrozek wrote: > > On Thu, Jul 07, 2016 at 12:39:28PM +0200, Pavel Březina wrote: > > > On 07/07/2016 12:34 PM, Jakub Hrozek wrote: > > > > On Thu, Jul 07, 2016 at 10:16:03AM +0200, Sumit Bose wrote: > >

[SSSD] Re: [PATCH] sssctl: Add config-check command

2016-07-07 Thread Michal Židek
On 07/07/2016 02:15 PM, Pavel Březina wrote: On 07/07/2016 01:54 PM, Michal Židek wrote: On 07/07/2016 01:20 PM, Lukas Slebodnik wrote: On (07/07/16 12:37), Michal Židek wrote: On 07/04/2016 05:27 PM, Michal Židek wrote: On 07/01/2016 05:35 PM, Lukas Slebodnik wrote: On (01/07/16 17:26),

[SSSD] Re: [PATCH] sssctl: Add config-check command

2016-07-07 Thread Pavel Březina
On 07/07/2016 01:54 PM, Michal Židek wrote: On 07/07/2016 01:20 PM, Lukas Slebodnik wrote: On (07/07/16 12:37), Michal Židek wrote: On 07/04/2016 05:27 PM, Michal Židek wrote: On 07/01/2016 05:35 PM, Lukas Slebodnik wrote: On (01/07/16 17:26), Michal Židek wrote: Hello! This patch adds new

[SSSD] Re: [PATCH] sssctl: Add config-check command

2016-07-07 Thread Michal Židek
On 07/07/2016 01:54 PM, Michal Židek wrote: On 07/07/2016 01:20 PM, Lukas Slebodnik wrote: On (07/07/16 12:37), Michal Židek wrote: On 07/04/2016 05:27 PM, Michal Židek wrote: On 07/01/2016 05:35 PM, Lukas Slebodnik wrote: On (01/07/16 17:26), Michal Židek wrote: Hello! This patch adds new

[SSSD] Re: [PATCH] sssctl: Add config-check command

2016-07-07 Thread Michal Židek
On 07/07/2016 01:20 PM, Lukas Slebodnik wrote: On (07/07/16 12:37), Michal Židek wrote: On 07/04/2016 05:27 PM, Michal Židek wrote: On 07/01/2016 05:35 PM, Lukas Slebodnik wrote: On (01/07/16 17:26), Michal Židek wrote: Hello! This patch adds new command config-check for sssctl tool. The

[SSSD] Re: [PATCH] sudo: solve problems with fully qualified names

2016-07-07 Thread Jakub Hrozek
On Wed, Jul 06, 2016 at 06:20:00PM +0200, Jakub Hrozek wrote: > On Wed, Jul 06, 2016 at 03:23:26PM +0200, Jakub Hrozek wrote: > > On Wed, Jun 01, 2016 at 11:52:44AM +0200, Pavel Březina wrote: > > > On 05/31/2016 01:44 PM, Jakub Hrozek wrote: > > > > On Fri, May 27, 2016 at 11:54:20AM +0200, Pavel

[SSSD] Re: [PATCH] LDAP: Lookup services by all protocols unless a protocol is specified

2016-07-07 Thread Pavel Březina
On 07/07/2016 01:24 PM, Jakub Hrozek wrote: On Thu, Jul 07, 2016 at 12:39:28PM +0200, Pavel Březina wrote: On 07/07/2016 12:34 PM, Jakub Hrozek wrote: On Thu, Jul 07, 2016 at 10:16:03AM +0200, Sumit Bose wrote: resend - Forwarded message from Sumit Bose - Date:

[SSSD] Re: [PATCH] LDAP: Lookup services by all protocols unless a protocol is specified

2016-07-07 Thread Jakub Hrozek
On Thu, Jul 07, 2016 at 12:39:28PM +0200, Pavel Březina wrote: > On 07/07/2016 12:34 PM, Jakub Hrozek wrote: > > On Thu, Jul 07, 2016 at 10:16:03AM +0200, Sumit Bose wrote: > > > resend > > > - Forwarded message from Sumit Bose - > > > > > > Date: Wed, 6 Jul 2016

[SSSD] Re: [PATCH] sssctl: Add config-check command

2016-07-07 Thread Lukas Slebodnik
On (07/07/16 12:37), Michal Židek wrote: >On 07/04/2016 05:27 PM, Michal Židek wrote: >> On 07/01/2016 05:35 PM, Lukas Slebodnik wrote: >> > On (01/07/16 17:26), Michal Židek wrote: >> > > Hello! >> > > >> > > This patch adds new command config-check >> > > for sssctl tool. The output looks like

[SSSD] Re: [PATCH][PUSHED] MAN: Include idmap_sss.8.xml in the manpage sources

2016-07-07 Thread Jakub Hrozek
On Thu, Jul 07, 2016 at 01:06:31PM +0200, Lukas Slebodnik wrote: > On (07/07/16 13:05), Pavel Březina wrote: > >On 06/30/2016 03:37 PM, Lukas Slebodnik wrote: > >> On (30/06/16 09:28), Sumit Bose wrote: > >> > On Wed, Jun 29, 2016 at 11:23:55PM +0200, Jakub Hrozek wrote: > >> > > Hi, > >> > > I

[SSSD] Re: [PATCH][PUSHED] MAN: Include idmap_sss.8.xml in the manpage sources

2016-07-07 Thread Lukas Slebodnik
On (07/07/16 13:05), Pavel Březina wrote: >On 06/30/2016 03:37 PM, Lukas Slebodnik wrote: >> On (30/06/16 09:28), Sumit Bose wrote: >> > On Wed, Jun 29, 2016 at 11:23:55PM +0200, Jakub Hrozek wrote: >> > > Hi, >> > > I pushed the attached patch under the one-liner rule (which I'm not a >> > > big

[SSSD] Re: [PATCH] CONFIGURE: Inform about optional build dependencies

2016-07-07 Thread Lukas Slebodnik
On (05/07/16 07:59), Jakub Hrozek wrote: >On Fri, Jul 01, 2016 at 08:45:53AM +0200, Lukas Slebodnik wrote: >> ehlo, >> >> We usually inform about optional build dependencies at configure time >> and which option can disable checking of this dependency. >> >> LS > >I agree with the intent, but I

[SSSD] Re: [PATCH][PUSHED] MAN: Include idmap_sss.8.xml in the manpage sources

2016-07-07 Thread Pavel Březina
On 06/30/2016 03:37 PM, Lukas Slebodnik wrote: On (30/06/16 09:28), Sumit Bose wrote: On Wed, Jun 29, 2016 at 11:23:55PM +0200, Jakub Hrozek wrote: Hi, I pushed the attached patch under the one-liner rule (which I'm not a big fan of, but it's late and I've been wanting to do this release for

[SSSD] Re: [PATCH] sssctl: print a message when managing sssd

2016-07-07 Thread Pavel Březina
On 07/05/2016 07:49 AM, Jakub Hrozek wrote: On Fri, Jul 01, 2016 at 01:24:35PM +0200, Pavel Březina wrote: From 8b877579f3d1a9bbfa728a6e78ff829d936efbb1 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Pavel=20B=C5=99ezina?= Date: Fri, 1 Jul 2016 13:23:57 +0200 Subject: [PATCH]

[SSSD] Re: [PATCH] PAM/KRB5: optional otp and password prompting

2016-07-07 Thread Jakub Hrozek
On Thu, Jul 07, 2016 at 12:39:01PM +0200, Jakub Hrozek wrote: > The prompts were changes as Nathaniel suggested and the basic sanity > checks worked with this patch. I'm going to push with Nathaniel's RB. * master: 78027feeb56d6fe216f699be86a4716aaef3f628

[SSSD] Re: [PATCH] Fix packet size calculation in sss_packet_new

2016-07-07 Thread Lukas Slebodnik
On (07/07/16 12:33), Pavel Březina wrote: >On 07/07/2016 11:55 AM, Nikolai Kondrashov wrote: >> Hi everyone, >> >> The attached patch fixes potential packet buffer overflow with certain body >> sizes. Found while reading through SSSD code. >> >> Nick > >Ack, nice catch. I fixed this one in

[SSSD] Re: [PATCH] LDAP: Lookup services by all protocols unless a protocol is specified

2016-07-07 Thread Pavel Březina
On 07/07/2016 12:34 PM, Jakub Hrozek wrote: On Thu, Jul 07, 2016 at 10:16:03AM +0200, Sumit Bose wrote: resend - Forwarded message from Sumit Bose - Date: Wed, 6 Jul 2016 11:13:48 +0200 From: Sumit Bose To: sssd-devel@lists.fedorahosted.org

[SSSD] Re: [PATCH] sssctl: Add config-check command

2016-07-07 Thread Michal Židek
On 07/04/2016 05:27 PM, Michal Židek wrote: On 07/01/2016 05:35 PM, Lukas Slebodnik wrote: On (01/07/16 17:26), Michal Židek wrote: Hello! This patch adds new command config-check for sssctl tool. The output looks like this: Issues identified by validators: 3 [rule/allowed_sections]:

[SSSD] Re: [PATCH] LDAP: Lookup services by all protocols unless a protocol is specified

2016-07-07 Thread Jakub Hrozek
On Thu, Jul 07, 2016 at 10:16:03AM +0200, Sumit Bose wrote: > resend > - Forwarded message from Sumit Bose - > > Date: Wed, 6 Jul 2016 11:13:48 +0200 > From: Sumit Bose > To: sssd-devel@lists.fedorahosted.org > Subject: Re: [SSSD] [PATCH] LDAP: Lookup

[SSSD] Re: [PATCH] Fix packet size calculation in sss_packet_new

2016-07-07 Thread Pavel Březina
On 07/07/2016 11:55 AM, Nikolai Kondrashov wrote: Hi everyone, The attached patch fixes potential packet buffer overflow with certain body sizes. Found while reading through SSSD code. Nick Ack, nice catch. I fixed this one in packet_grow some time ago.

[SSSD] [PATCH] Fix packet size calculation in sss_packet_new

2016-07-07 Thread Nikolai Kondrashov
Hi everyone, The attached patch fixes potential packet buffer overflow with certain body sizes. Found while reading through SSSD code. Nick >From d708e1915e4464db9a2b0990c732c4e2edb0c0df Mon Sep 17 00:00:00 2001 From: Nikolai Kondrashov Date: Thu, 7 Jul 2016

[SSSD] Re: fully qualified sysdb names for users and groups

2016-07-07 Thread Jakub Hrozek
On Thu, Jul 07, 2016 at 11:45:42AM +0200, Lukas Slebodnik wrote: > On (07/07/16 11:39), Pavel Březina wrote: > >On 07/06/2016 11:21 PM, Sumit Bose wrote: > >> > >> ok, CI passed http://sssd-ci.duckdns.org/logs/job/47/41/summary.html > >> > >> ACK > > > >I went through the code changes and it

[SSSD] Re: fully qualified sysdb names for users and groups

2016-07-07 Thread Lukas Slebodnik
On (07/07/16 11:39), Pavel Březina wrote: >On 07/06/2016 11:21 PM, Sumit Bose wrote: >> >> ok, CI passed http://sssd-ci.duckdns.org/logs/job/47/41/summary.html >> >> ACK > >I went through the code changes and it looks good to me. I have just one >nitpick for the changes in sssctl, can you move

[SSSD] Re: fully qualified sysdb names for users and groups

2016-07-07 Thread Pavel Březina
On 07/06/2016 11:21 PM, Sumit Bose wrote: On Wed, Jul 06, 2016 at 10:24:26PM +0200, Sumit Bose wrote: On Wed, Jul 06, 2016 at 09:02:05PM +0200, Jakub Hrozek wrote: On Wed, Jul 06, 2016 at 06:34:32PM +0200, Jakub Hrozek wrote: On Wed, Jul 06, 2016 at 11:13:02AM +0200, Lukas Slebodnik wrote:

[SSSD] Re: [PATCH] PAM/KRB5: optional otp and password prompting

2016-07-07 Thread Sumit Bose
On Wed, Jul 06, 2016 at 10:03:12AM -0400, Nathaniel McCallum wrote: > On Wed, 2016-07-06 at 15:55 +0200, Sumit Bose wrote: > > On Wed, Jul 06, 2016 at 09:03:45AM -0400, Nathaniel McCallum wrote: > > > > > > Patch WFM and looks clean. My only question is on the overall > > > > Thank you very much

[SSSD] Re: [PATCH] LDAP: Lookup services by all protocols unless a protocol is specified

2016-07-07 Thread Sumit Bose
resend - Forwarded message from Sumit Bose - Date: Wed, 6 Jul 2016 11:13:48 +0200 From: Sumit Bose To: sssd-devel@lists.fedorahosted.org Subject: Re: [SSSD] [PATCH] LDAP: Lookup services by all protocols unless a protocol is specified