[SSSD] Re: [Freeipa-devel] [RFC] Matching and Mapping Certificates

2016-10-06 Thread Alexander Bokovoy
On pe, 07 loka 2016, Fraser Tweedale wrote: On Thu, Oct 06, 2016 at 12:49:30PM +0200, Sumit Bose wrote: Question, do we need search-and-replace at all (or at this stage)? Most of the interesting values from the SAN should be directly map-able to LDAP attributes. And processing the string repres

[SSSD] Re: [Freeipa-devel] [RFC] Matching and Mapping Certificates

2016-10-06 Thread Rob Crittenden
Sumit Bose wrote: On Thu, Oct 06, 2016 at 10:33:48AM -0400, Rob Crittenden wrote: Sumit Bose wrote: Hi, Wow, this is really great. Hi Rob, thank you for the feedback. I think I'd pre-plan to support different configuration per issuer subject, with one named default. It shouldn't be a

[SSSD] Re: Design discussion: Fleet Commander integration

2016-10-06 Thread Sumit Bose
On Thu, Oct 06, 2016 at 04:41:10PM +0200, Jakub Hrozek wrote: > Hi, > > with Alexander's help, I wrote up a design page about how SSSD should > read Fleet Commander data from IPA and present them to the FC client > component. The SSSD part is described here: > https://fedorahosted.org/sssd/wik

[SSSD] Re: [Freeipa-devel] [RFC] Matching and Mapping Certificates

2016-10-06 Thread Sumit Bose
On Thu, Oct 06, 2016 at 10:33:48AM -0400, Rob Crittenden wrote: > Sumit Bose wrote: > > Hi, > > > > > > Wow, this is really great. Hi Rob, thank you for the feedback. > > I think I'd pre-plan to support different configuration per issuer subject, > with one named default. It shouldn't be a l

[SSSD] Design discussion: Fleet Commander integration

2016-10-06 Thread Jakub Hrozek
Hi, with Alexander's help, I wrote up a design page about how SSSD should read Fleet Commander data from IPA and present them to the FC client component. The SSSD part is described here: https://fedorahosted.org/sssd/wiki/DesignDocs/FleetCommanderIntegration and the IPA part is here: http

[SSSD] Re: [Freeipa-devel] [RFC] Matching and Mapping Certificates

2016-10-06 Thread Rob Crittenden
Sumit Bose wrote: Hi, I've started to write a SSSD design page about enhancing the current mapping of certificates to users and how to select/match a suitable certificate if multiple certificates are on a Smartcard. My currently thoughts and idea and be found at https://fedorahosted.org/sssd/wi

[SSSD] [sssd PR#39][comment] RESPONDER: Enable sudoRule in case insen. domains

2016-10-06 Thread pbrezina
URL: https://github.com/SSSD/sssd/pull/39 Title: #39: RESPONDER: Enable sudoRule in case insen. domains pbrezina commented: """ On 10/06/2016 01:42 PM, Jakub Hrozek wrote: > On Thu, Oct 06, 2016 at 03:51:05AM -0700, Pavel Březina wrote: >> The patch that should fix this is: > 61913b8f0d1ba54d826

[SSSD] [sssd PR#31][-Changes requested] nss: allow UPNs in SSS_NSS_GETSIDBYNAME and SSS_NSS_GETORIGBYNAME

2016-10-06 Thread sumit-bose
URL: https://github.com/SSSD/sssd/pull/31 Title: #31: nss: allow UPNs in SSS_NSS_GETSIDBYNAME and SSS_NSS_GETORIGBYNAME Label: -Changes requested ___ sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org To unsubscribe send an email to sssd-deve

[SSSD] [sssd PR#31][synchronized] nss: allow UPNs in SSS_NSS_GETSIDBYNAME and SSS_NSS_GETORIGBYNAME

2016-10-06 Thread sumit-bose
URL: https://github.com/SSSD/sssd/pull/31 Author: sumit-bose Title: #31: nss: allow UPNs in SSS_NSS_GETSIDBYNAME and SSS_NSS_GETORIGBYNAME Action: synchronized To pull the PR as Git branch: git remote add ghsssd https://github.com/SSSD/sssd git fetch ghsssd pull/31/head:pr31 git checkout pr31

[SSSD] [sssd PR#42][+Accepted] MAN: Typo in id mapping explanation

2016-10-06 Thread sumit-bose
URL: https://github.com/SSSD/sssd/pull/42 Title: #42: MAN: Typo in id mapping explanation Label: +Accepted ___ sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org

[SSSD] [sssd PR#39][comment] RESPONDER: Enable sudoRule in case insen. domains

2016-10-06 Thread jhrozek
URL: https://github.com/SSSD/sssd/pull/39 Title: #39: RESPONDER: Enable sudoRule in case insen. domains jhrozek commented: """ On Thu, Oct 06, 2016 at 03:51:05AM -0700, Pavel Březina wrote: > The patch that should fix this is: 61913b8f0d1ba54d82640500d7486fac5f72b030 Well, didn't we establish t

[SSSD] [sssd PR#42][-Changes requested] MAN: Typo in id mapping explanation

2016-10-06 Thread mzidek-rh
URL: https://github.com/SSSD/sssd/pull/42 Title: #42: MAN: Typo in id mapping explanation Label: -Changes requested ___ sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org

[SSSD] [sssd PR#42][comment] MAN: Typo in id mapping explanation

2016-10-06 Thread mzidek-rh
URL: https://github.com/SSSD/sssd/pull/42 Title: #42: MAN: Typo in id mapping explanation mzidek-rh commented: """ Updated according to Sumit's comment. """ See the full comment at https://github.com/SSSD/sssd/pull/42#issuecomment-251935126 ___ sssd-

[SSSD] [sssd PR#42][synchronized] MAN: Typo in id mapping explanation

2016-10-06 Thread mzidek-rh
URL: https://github.com/SSSD/sssd/pull/42 Author: mzidek-rh Title: #42: MAN: Typo in id mapping explanation Action: synchronized To pull the PR as Git branch: git remote add ghsssd https://github.com/SSSD/sssd git fetch ghsssd pull/42/head:pr42 git checkout pr42 From 757bbbeb2b7022309685e3e130

[SSSD] [sssd PR#42][+Changes requested] MAN: Typo in id mapping explanation

2016-10-06 Thread sumit-bose
URL: https://github.com/SSSD/sssd/pull/42 Title: #42: MAN: Typo in id mapping explanation Label: +Changes requested ___ sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org

[SSSD] [sssd PR#42][comment] MAN: Typo in id mapping explanation

2016-10-06 Thread sumit-bose
URL: https://github.com/SSSD/sssd/pull/42 Title: #42: MAN: Typo in id mapping explanation sumit-bose commented: """ The current defaults are: ` { "ldap_idmap_range_min", DP_OPT_NUMBER, { .number = 20 }, NULL_NUMBER }, { "ldap_idmap_range_max", DP_OPT_NUMBER, { .number = 200020LL

[SSSD] [sssd PR#42][comment] MAN: Typo in id mapping explanation

2016-10-06 Thread mzidek-rh
URL: https://github.com/SSSD/sssd/pull/42 Title: #42: MAN: Typo in id mapping explanation mzidek-rh commented: """ Another man page fix. Native speaker not required. """ See the full comment at https://github.com/SSSD/sssd/pull/42#issuecomment-251929365

[SSSD] [sssd PR#42][opened] MAN: Typo in id mapping explanation

2016-10-06 Thread mzidek-rh
URL: https://github.com/SSSD/sssd/pull/42 Author: mzidek-rh Title: #42: MAN: Typo in id mapping explanation Action: opened PR body: """ It is probably result of modifying the code and not updating the man page properly. Resolves: https://fedorahosted.org/sssd/ticket/3205 """ To pull the PR a

[SSSD] [sssd PR#39][comment] RESPONDER: Enable sudoRule in case insen. domains

2016-10-06 Thread pbrezina
URL: https://github.com/SSSD/sssd/pull/39 Title: #39: RESPONDER: Enable sudoRule in case insen. domains pbrezina commented: """ The patch that should fix this is: 61913b8f0d1ba54d82640500d7486fac5f72b030 Unfortunately it is written on top of cache_req refactoring in sudo responder which is not

[SSSD] [RFC] Matching and Mapping Certificates

2016-10-06 Thread Sumit Bose
Hi, I've started to write a SSSD design page about enhancing the current mapping of certificates to users and how to select/match a suitable certificate if multiple certificates are on a Smartcard. My currently thoughts and idea and be found at https://fedorahosted.org/sssd/wiki/DesignDocs/Matchi

[SSSD] [sssd PR#39][+Changes requested] RESPONDER: Enable sudoRule in case insen. domains

2016-10-06 Thread celestian
URL: https://github.com/SSSD/sssd/pull/39 Title: #39: RESPONDER: Enable sudoRule in case insen. domains Label: +Changes requested ___ sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org To unsubscribe send an email to sssd-devel-le...@lists.fe

[SSSD] [sssd PR#39][comment] RESPONDER: Enable sudoRule in case insen. domains

2016-10-06 Thread celestian
URL: https://github.com/SSSD/sssd/pull/39 Title: #39: RESPONDER: Enable sudoRule in case insen. domains celestian commented: """ Hi Fabiano, I wrote about it a bit with @jhrozek a I discussed it with @pbrezina today. Unfortunately on separate channels. Resume: 1. (sssd-1-13) We are able to f

[SSSD] [sssd PR#41][comment] MAN: Wrong defaults for AD provider

2016-10-06 Thread mzidek-rh
URL: https://github.com/SSSD/sssd/pull/41 Title: #41: MAN: Wrong defaults for AD provider mzidek-rh commented: """ It is man page change, but does not require native speaker for review. """ See the full comment at https://github.com/SSSD/sssd/pull/41#issuecomment-251912853

[SSSD] [sssd PR#41][opened] MAN: Wrong defaults for AD provider

2016-10-06 Thread mzidek-rh
URL: https://github.com/SSSD/sssd/pull/41 Author: mzidek-rh Title: #41: MAN: Wrong defaults for AD provider Action: opened PR body: """ ldap_user_name and ldap_group_name have different defalts then what the man page states. Resolves: https://fedorahosted.org/sssd/ticket/3022 """ To pull the

[SSSD] [sssd PR#40][opened] TESTS: Remove a leftover debug message

2016-10-06 Thread fidencio
URL: https://github.com/SSSD/sssd/pull/40 Author: fidencio Title: #40: TESTS: Remove a leftover debug message Action: opened PR body: """ The debug message was introduced when I was testing 65a38b8c9, but ended up not removed before submitting the patch. Signed-off-by: Fabiano Fidêncio """

[SSSD] [sssd PR#39][comment] RESPONDER: Enable sudoRule in case insen. domains

2016-10-06 Thread fidencio
URL: https://github.com/SSSD/sssd/pull/39 Title: #39: RESPONDER: Enable sudoRule in case insen. domains fidencio commented: """ On Thu, Oct 6, 2016 at 7:56 AM, celestian wrote: > It's time for little explanation. > > SSSD (version 1.13) is able to find properly sudoRule. But sudoUser and > log