URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
jhrozek commented:
"""
CI: http://sssd-ci.duckdns.org/logs/job/57/35/summary.html
sssd-1-13: b6d0b0a14c7f09371cbb2afd0347f6a16fcfc8dd
"""
See the full comment at
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
jhrozek commented:
"""
(CI pending)
"""
See the full comment at
https://github.com/SSSD/sssd/pull/39#issuecomment-262709772
___
sssd-devel
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
jhrozek commented:
"""
ack, this version works for me
"""
See the full comment at
https://github.com/SSSD/sssd/pull/39#issuecomment-262709744
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
celestian commented:
"""
Squashed version pushed.
"""
See the full comment at
https://github.com/SSSD/sssd/pull/39#issuecomment-262694326
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
lslebodn commented:
"""
On (23/11/16 08:07), celestian wrote:
>I pushed new version. The patch is the same plus I added back-ported patch
>from #80 (with cerry-pick tag).
>
NACK to
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
celestian commented:
"""
I pushed new version. The patch is the same plus I added back-ported patch from
#80 (with cerry-pick tag).
"""
See the full comment at
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
jhrozek commented:
"""
regardless of what we choose, the patch for PR #80 does not apply atop this
patch, can we have a version that applies to the 1.13 branch, please?
"""
See the
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
lslebodn commented:
"""
On (23/11/16 06:19), celestian wrote:
>Thanks for CR.
>After pushing it is important to cherry pick #80 as well.
>
I do not agree. The ticket #3241 was a
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
jhrozek commented:
"""
For some reason the downstream tests are stuck and time out, even with
known-good packages. I will keep trying but for downstream's sake I'm going to
push the
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
celestian commented:
"""
Thanks for CR.
After pushing it is important to cherry pick #80 as well.
"""
See the full comment at
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
jhrozek commented:
"""
ACK, this version works for me. I will run also downstream tests to be sure,
but my manual testing passed.
"""
See the full comment at
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
celestian commented:
"""
So, I pushed new version. Now ```sysdb_get_sudo_filter()``` uses
```nameAlias``` values.
(And after pushing #80 I will cherry-pick it to 1.13 too.)
"""
See
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
jhrozek commented:
"""
Apart from fixing ticket #3241, why does sysdb_get_sudo_filter add its own
lowercased name and does not add all nameAlias values instead?
"""
See the full
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
celestian commented:
"""
I am afraid there is the same issue as in
https://fedorahosted.org/sssd/ticket/3241. The patch will be added soon.
"""
See the full comment at
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
celestian commented:
"""
We discussed this issue with @jhrozek.
I misunderstood the case -- the right is -- user is ```Administrator```, the
sudoRule is written for user
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
celestian commented:
"""
I am sure this is enough. Maybe it is not the most direct solution. I try to
explain it:
We have user ```Administrator```, sysdb record looks like (minor
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
jhrozek commented:
"""
Are you sure this is enough? Because when the patch is applied, I see that we
only match the sudoUser value with the original case. Don't we also need to
match
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
jhrozek commented:
"""
oops...clicked send to early. I meant to say "So the filter never matches the
lowercase sudoUser".
"""
See the full comment at
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
jhrozek commented:
"""
On Tue, Nov 08, 2016 at 05:06:41AM -0800, celestian wrote:
> Yes, the second patch explicitly qualifies the names. I don't know if there
> is possibility to add
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
celestian commented:
"""
Yes, the second patch explicitly qualifies the names. I don't know if there is
possibility to add wrong domain to the given user name this way. That's the
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
jhrozek commented:
"""
On Tue, Nov 08, 2016 at 04:13:43AM -0800, celestian wrote:
> I pushed new version, only one difference -- I fix cherry-pick pointer.
> The patch works without
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
celestian commented:
"""
I pushed new version, only one difference -- I fix cherry-pick pointer.
The patch works without ```sudoUserAlias``` but it still adds fq names to
sudoUser.
Is
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
celestian commented:
"""
Since we have patch set for 1.15 pushed I will prepare proper cherry picking.
"""
See the full comment at
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
pbrezina commented:
"""
So what is the current plan here?
"""
See the full comment at
https://github.com/SSSD/sssd/pull/39#issuecomment-259118986
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
celestian commented:
"""
I pushed new version.
Note: The patch set for 1.15 (and 1.14) is in new version too. It is possible
that it will be needed to make cherry pick of Adding
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
jhrozek commented:
"""
Setting changes requested to rework the patch to only include the sudoUser and
not sudoUserAlias
"""
See the full comment at
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
pbrezina commented:
"""
The patch looks good to me. I'd feel better if we somehow managed to backport
patch that solves the fully qualified issue in 1.14 though.
I'm not that sure
URL: https://github.com/SSSD/sssd/pull/39
Title: #39: RESPONDER: Enable sudoRule in case insen. domains (1.13)
celestian commented:
"""
I just pushed new version of patch set. It is inspired by patch set for 1.14.
And there is one little difference -- adding fq name for users in
28 matches
Mail list logo