2009-10-12 16:00:00 -04:00
# Define ONLY_CLIENT to only make the ipa-client and ipa-python subpackages
2010-01-07 14:12:52 -05:00
%{!?ONLY_CLIENT:%global ONLY_CLIENT 0}
2009-10-12 16:00:00 -04:00
2010-01-07 14:12:52 -05:00
%global plugin_dir %{_libdir}/dirsrv/plugins
2013-03-12 15:25:40 +01:00
%global POLICYCOREUTILSVER 2.1.12-5
2010-02-09 13:14:25 -05:00
%global gettext_domain ipa
2009-02-02 13:50:53 -05:00
2013-11-27 13:13:16 +00:00
%if (0%{?fedora} > 15 || 0%{?rhel} >= 7)
%define _hardened_build 1
%endif
2011-01-17 10:26:19 +01:00
Name: freeipa
2009-02-02 13:50:53 -05:00
Version: __VERSION__
Release: __RELEASE__%{?dist}
Summary: The Identity, Policy and Audit system
Group: System Environment/Base
2010-12-09 13:59:11 +01:00
License: GPLv3+
2009-02-02 13:50:53 -05:00
URL: http://www.freeipa.org/
Source0: freeipa-%{version}.tar.gz
BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n)
2009-10-12 16:00:00 -04:00
%if ! %{ONLY_CLIENT}
2014-04-04 08:48:32 +02:00
BuildRequires: 389-ds-base-devel >= 1.3.2.16
2009-02-02 13:50:53 -05:00
BuildRequires: svrcore-devel
2011-02-21 13:04:38 -05:00
BuildRequires: policycoreutils >= %{POLICYCOREUTILSVER}
2011-10-21 16:44:36 +03:00
BuildRequires: systemd-units
2012-10-01 15:32:36 +02:00
%if 0%{?fedora} >= 18
2013-04-16 09:44:28 +02:00
BuildRequires: samba-devel >= 2:4.0.5-1
2012-10-01 15:32:36 +02:00
BuildRequires: samba-python
BuildRequires: libwbclient-devel
%else
2012-09-14 14:14:23 +02:00
BuildRequires: samba4-devel >= 4.0.0-139
2012-06-07 05:24:35 -04:00
BuildRequires: samba4-python
2012-10-01 15:32:36 +02:00
%endif
2012-07-25 11:23:11 -04:00
BuildRequires: libtalloc-devel
BuildRequires: libtevent-devel
2013-08-13 10:56:26 +02:00
%endif # ONLY_CLIENT
2009-02-02 13:50:53 -05:00
BuildRequires: nspr-devel
2011-02-21 13:04:38 -05:00
BuildRequires: nss-devel
2009-02-02 13:50:53 -05:00
BuildRequires: openssl-devel
BuildRequires: openldap-devel
2013-03-12 15:25:40 +01:00
BuildRequires: krb5-devel >= 1.11
2011-02-21 13:04:38 -05:00
BuildRequires: krb5-workstation
BuildRequires: libuuid-devel
2011-08-11 10:42:29 +02:00
BuildRequires: libcurl-devel >= 7.21.7-2
BuildRequires: xmlrpc-c-devel >= 1.27.4
2011-02-21 13:04:38 -05:00
BuildRequires: popt-devel
2009-02-02 13:50:53 -05:00
BuildRequires: autoconf
BuildRequires: automake
BuildRequires: m4
2011-02-21 13:04:38 -05:00
BuildRequires: libtool
BuildRequires: gettext
BuildRequires: python-devel
BuildRequires: python-ldap
2009-02-23 18:41:00 +01:00
BuildRequires: python-setuptools
BuildRequires: python-krbV
2011-01-13 14:29:16 -05:00
BuildRequires: python-nss
BuildRequires: python-netaddr
2013-12-03 09:14:00 -07:00
BuildRequires: python-kerberos >= 1.1-14
2011-05-05 15:06:54 +02:00
BuildRequires: python-rhsm
2011-02-11 09:34:57 -05:00
BuildRequires: pyOpenSSL
2011-05-05 15:06:54 +02:00
BuildRequires: pylint
2012-03-23 01:44:04 -04:00
BuildRequires: python-polib
2011-07-22 16:30:44 +03:00
BuildRequires: libipa_hbac-python
2012-02-15 10:26:42 -05:00
BuildRequires: python-memcached
2012-10-31 10:59:04 +01:00
BuildRequires: sssd >= 1.9.2
2012-03-23 12:21:08 -04:00
BuildRequires: python-lxml
BuildRequires: python-pyasn1 >= 0.0.9a
2013-10-01 14:26:38 -04:00
BuildRequires: python-qrcode
2012-05-11 14:38:09 +02:00
BuildRequires: python-dns
2012-11-21 18:33:49 +02:00
BuildRequires: m2crypto
2012-11-14 16:45:41 +01:00
BuildRequires: check
2011-11-30 13:29:10 +01:00
BuildRequires: libsss_idmap-devel
2013-07-11 13:33:31 +02:00
BuildRequires: libsss_nss_idmap-devel
2013-01-22 09:56:13 +01:00
BuildRequires: java-1.7.0-openjdk
2014-03-13 17:09:49 -04:00
BuildRequires: rhino
2013-04-11 14:03:25 -04:00
BuildRequires: libverto-devel
BuildRequires: systemd
2013-07-16 11:47:27 -04:00
BuildRequires: libunistring-devel
2013-10-10 13:41:31 +02:00
BuildRequires: python-lesscpy
2013-12-03 09:14:00 -07:00
BuildRequires: python-kerberos
BuildRequires: python-cherrypy
2009-02-02 13:50:53 -05:00
2013-04-04 18:20:25 +03:00
# Find out Kerberos middle version to infer ABI changes in DAL driver
# We cannot load DAL driver into KDC with wrong ABI.
# This is also needed to support ipa-devel repository where krb5 1.11 is available for F18
%global krb5_dal_version %{expand:%(echo "#include <kdb.h>"|cpp -dM|grep KRB5_KDB_DAL_MAJOR_VERSION|cut -d' ' -f3)}
2009-02-02 13:50:53 -05:00
%description
IPA is an integrated solution to provide centrally managed Identity (machine,
user, virtual machines, groups, authentication credentials), Policy
(configuration settings, access control information) and Audit (events,
logs, analysis thereof).
2009-10-12 16:00:00 -04:00
%if ! %{ONLY_CLIENT}
2009-02-02 13:50:53 -05:00
%package server
Summary: The IPA authentication server
Group: System Environment/Base
Requires: %{name}-python = %{version}-%{release}
Requires: %{name}-client = %{version}-%{release}
Requires: %{name}-admintools = %{version}-%{release}
2014-04-04 08:48:32 +02:00
Requires: 389-ds-base >= 1.3.2.16
2013-05-10 13:50:21 +02:00
Requires: openldap-clients > 2.4.35-4
2013-04-26 12:36:05 -04:00
%if 0%{?fedora} == 18
Requires: nss >= 3.14.3-2
Requires: nss-tools >= 3.14.3-2
%else
Requires: nss >= 3.14.3-12.0
Requires: nss-tools >= 3.14.3-12.0
%endif
2013-04-04 18:20:25 +03:00
%if 0%{?krb5_dal_version} >= 4
2014-02-07 11:56:33 -05:00
Requires: krb5-server >= 1.11.5-3
2013-03-12 15:25:40 +01:00
%else
2013-04-04 18:20:25 +03:00
%if 0%{krb5_dal_version} == 3
2013-03-12 15:25:40 +01:00
# krb5 1.11 bumped DAL interface major version, a rebuild is needed
2012-10-10 16:50:55 -04:00
Requires: krb5-server < 1.11
2013-03-12 15:25:40 +01:00
Requires: krb5-server >= 1.10
%else
Requires: krb5-server >= 1.10
%endif
%endif
2010-12-13 14:46:09 -05:00
Requires: krb5-pkinit-openssl
2011-07-22 09:06:13 -04:00
Requires: cyrus-sasl-gssapi%{?_isa}
2009-02-02 13:50:53 -05:00
Requires: ntp
2013-11-26 08:53:34 +00:00
Requires: httpd >= 2.4.6-6
2010-02-24 11:29:23 -07:00
Requires: mod_wsgi
2012-06-20 14:09:55 -04:00
%if 0%{?fedora} >= 18
Requires: mod_auth_kerb >= 5.4-16
%else
2012-02-15 17:06:54 +01:00
Requires: mod_auth_kerb >= 5.4-8
2012-06-20 14:09:55 -04:00
%endif
2013-11-26 08:53:34 +00:00
Requires: mod_nss >= 1.0.8-26
2009-02-02 13:50:53 -05:00
Requires: python-ldap
Requires: python-krbV
Requires: acl
2012-11-14 16:45:41 +01:00
Requires: python-pyasn1
2012-02-06 13:15:06 -05:00
Requires: memcached
Requires: python-memcached
2013-10-15 20:49:07 +02:00
Requires: dbus-python
2013-03-27 14:58:16 +01:00
Requires: systemd-units >= 38
2011-10-21 16:44:36 +03:00
Requires(pre): systemd-units
Requires(post): systemd-units
2014-04-04 08:48:32 +02:00
Requires: selinux-policy >= 3.12.1-135
2009-02-02 13:50:53 -05:00
Requires(post): selinux-policy-base
2013-08-08 14:39:14 +02:00
Requires: slapi-nis >= 0.47.7
2014-03-28 10:04:41 +01:00
Requires: pki-ca >= 10.1.1
2012-11-14 16:45:41 +01:00
Requires: dogtag-pki-server-theme
2011-08-23 14:15:27 +02:00
%if 0%{?rhel}
Requires: subscription-manager
%endif
2011-10-21 16:44:36 +03:00
Requires(preun): python systemd-units
Requires(postun): python systemd-units
2012-05-11 14:38:09 +02:00
Requires: python-dns
2012-10-08 07:54:47 -04:00
Requires: zip
2012-10-24 12:35:36 +02:00
Requires: policycoreutils >= %{POLICYCOREUTILSVER}
2012-11-14 16:45:41 +01:00
Requires: tar
2013-01-24 16:14:31 -05:00
Requires(pre): certmonger >= 0.65
2014-02-06 11:27:29 -05:00
Requires(pre): 389-ds-base >= 1.3.2.11
2013-12-04 16:15:20 +01:00
Requires: fontawesome-fonts
Requires: open-sans-fonts
2009-02-02 13:50:53 -05:00
2013-06-13 14:40:52 +02:00
# With FreeIPA 3.3, package freeipa-server-selinux was obsoleted as the
# entire SELinux policy is stored in the system policy
Obsoletes: freeipa-server-selinux < 3.3.0
2011-09-09 12:30:00 +02:00
# We have a soft-requires on bind. It is an optional part of
# IPA but if it is configured we need a way to require versions
# that work for us.
2012-08-02 16:25:15 +02:00
%if 0%{?fedora} >= 18
2013-08-09 11:55:49 +02:00
Conflicts: bind-dyndb-ldap < 3.5
2012-08-02 16:25:15 +02:00
%else
2012-05-25 14:13:01 +02:00
Conflicts: bind-dyndb-ldap < 1.1.0-0.12.rc1
2012-08-02 16:25:15 +02:00
%endif
2012-03-20 15:35:54 +01:00
Conflicts: bind < 9.8.2-0.4.rc2
2011-09-09 12:30:00 +02:00
2013-04-30 14:35:19 -04:00
# Versions of nss-pam-ldapd < 0.8.4 require a mapping from uniqueMember to
# member.
Conflicts: nss-pam-ldapd < 0.8.4
2011-01-27 17:02:24 -05:00
Obsoletes: ipa-server >= 1.0
2011-01-17 10:26:19 +01:00
2009-02-02 13:50:53 -05:00
%description server
IPA is an integrated solution to provide centrally managed Identity (machine,
user, virtual machines, groups, authentication credentials), Policy
(configuration settings, access control information) and Audit (events,
logs, analysis thereof). If you are installing an IPA server you need
to install this package (in other words, most people should NOT install
this package).
2012-02-28 13:24:41 +02:00
%package server-trust-ad
Summary: Virtual package to install packages required for Active Directory trusts
Group: System Environment/Base
Requires: %{name}-server = %version-%release
2012-11-21 18:33:49 +02:00
Requires: m2crypto
2012-10-01 15:32:36 +02:00
%if 0%{?fedora} >= 18
Requires: samba-python
2013-04-16 09:44:28 +02:00
Requires: samba >= 2:4.0.5-1
2012-10-01 15:32:36 +02:00
Requires: samba-winbind
%else
2012-02-28 13:24:41 +02:00
Requires: samba4-python
Requires: samba4
2012-08-20 03:57:55 -04:00
Requires: samba4-winbind
2012-10-01 15:32:36 +02:00
%endif
Requires: libsss_idmap
2013-05-07 12:47:29 +02:00
%if 0%{?fedora} >= 19
2013-05-06 17:10:56 +02:00
Requires: libsss_nss_idmap-python
2013-05-07 12:47:29 +02:00
%endif
2012-10-10 09:46:08 +03:00
# We use alternatives to divert winbind_krb5_locator.so plugin to libkrb5
# on the installes where server-trust-ad subpackage is installed because
# IPA AD trusts cannot be used at the same time with the locator plugin
# since Winbindd will be configured in a different mode
Requires(post): %{_sbindir}/update-alternatives
2012-10-26 13:12:17 +02:00
Requires(post): python
2012-10-10 09:46:08 +03:00
Requires(postun): %{_sbindir}/update-alternatives
Requires(preun): %{_sbindir}/update-alternatives
2012-02-28 13:24:41 +02:00
%description server-trust-ad
2013-08-13 10:59:57 +02:00
Cross-realm trusts with Active Directory in IPA require working Samba 4
installation. This package is provided for convenience to install all required
dependencies at once.
2012-02-28 13:24:41 +02:00
2013-12-03 09:14:00 -07:00
%package server-foreman-smartproxy
Summary: Foreman-compatible REST API for IPA
Group: System Environment/Base
Requires: %{name}-client = %version-%release
Requires: python-cherrypy
Requires: gssproxy >= 0.3.1
Requires: python-kerberos >= 1.1-14
2014-05-06 15:52:11 -04:00
Requires: mod_wsgi
2013-12-03 09:14:00 -07:00
%description server-foreman-smartproxy
A Foreman-compatible REST API for managing hosts and hostgroups.
2013-08-13 10:56:26 +02:00
%endif # ONLY_CLIENT
2009-02-02 13:50:53 -05:00
%package client
Summary: IPA authentication for use on clients
Group: System Environment/Base
Requires: %{name}-python = %{version}-%{release}
Requires: python-ldap
2011-07-22 09:06:13 -04:00
Requires: cyrus-sasl-gssapi%{?_isa}
2009-02-02 13:50:53 -05:00
Requires: ntp
Requires: krb5-workstation
Requires: authconfig
Requires: pam_krb5
2009-02-19 17:20:37 -05:00
Requires: wget
2012-11-14 16:45:41 +01:00
Requires: libcurl >= 7.21.7-2
Requires: xmlrpc-c >= 1.27.4
2013-10-04 10:23:14 +02:00
Requires: sssd >= 1.11.1
2013-01-24 16:14:31 -05:00
Requires: certmonger >= 0.65
2010-09-09 18:10:14 -04:00
Requires: nss-tools
2011-02-17 08:30:36 -05:00
Requires: bind-utils
2012-02-27 10:59:25 +01:00
Requires: oddjob-mkhomedir
2012-03-28 08:51:02 +02:00
Requires: python-krbV
2012-05-11 14:38:09 +02:00
Requires: python-dns
2012-05-29 14:20:38 -04:00
Requires: libsss_autofs
Requires: autofs
Requires: libnfsidmap
Requires: nfs-utils
2012-10-31 10:15:28 +01:00
Requires(post): policycoreutils
2009-02-02 13:50:53 -05:00
2011-01-27 17:02:24 -05:00
Obsoletes: ipa-client >= 1.0
2011-01-17 10:26:19 +01:00
2009-02-02 13:50:53 -05:00
%description client
IPA is an integrated solution to provide centrally managed Identity (machine,
user, virtual machines, groups, authentication credentials), Policy
(configuration settings, access control information) and Audit (events,
logs, analysis thereof). If your network uses IPA for authentication,
this package should be installed on every client machine.
2009-10-12 16:00:00 -04:00
%if ! %{ONLY_CLIENT}
2009-02-02 13:50:53 -05:00
%package admintools
Summary: IPA administrative tools
Group: System Environment/Base
Requires: %{name}-python = %{version}-%{release}
2010-10-15 15:03:51 -04:00
Requires: %{name}-client = %{version}-%{release}
2009-02-02 13:50:53 -05:00
Requires: python-krbV
Requires: python-ldap
2011-01-27 17:02:24 -05:00
Obsoletes: ipa-admintools >= 1.0
2011-01-17 10:26:19 +01:00
2009-02-02 13:50:53 -05:00
%description admintools
IPA is an integrated solution to provide centrally managed Identity (machine,
user, virtual machines, groups, authentication credentials), Policy
(configuration settings, access control information) and Audit (events,
logs, analysis thereof). This package provides command-line tools for
IPA administrators.
2013-08-13 10:56:26 +02:00
%endif # ONLY_CLIENT
2009-02-02 13:50:53 -05:00
%package python
Summary: Python libraries used by IPA
Group: System Environment/Libraries
2012-11-14 16:45:41 +01:00
Requires: python-kerberos
2009-02-02 13:50:53 -05:00
Requires: gnupg
2011-05-27 20:17:22 +02:00
Requires: iproute
2013-07-23 17:21:47 +02:00
Requires: keyutils
2009-02-19 17:20:37 -05:00
Requires: pyOpenSSL
2012-11-14 16:45:41 +01:00
Requires: python-nss
2009-11-23 16:52:06 -05:00
Requires: python-lxml
2010-11-08 22:34:14 -05:00
Requires: python-netaddr
2011-07-22 16:30:44 +03:00
Requires: libipa_hbac-python
2014-03-26 12:49:56 +01:00
Requires: python-qrcode
Requires: python-pyasn1
2009-02-02 13:50:53 -05:00
2011-01-27 17:02:24 -05:00
Obsoletes: ipa-python >= 1.0
2011-01-17 10:26:19 +01:00
2009-02-02 13:50:53 -05:00
%description python
IPA is an integrated solution to provide centrally managed Identity (machine,
user, virtual machines, groups, authentication credentials), Policy
(configuration settings, access control information) and Audit (events,
logs, analysis thereof). If you are using IPA you need to install this
package.
2013-05-21 13:40:27 +02:00
%if ! %{ONLY_CLIENT}
%package tests
Summary: IPA tests and test tools
Requires: %{name}-client = %{version}-%{release}
Requires: %{name}-python = %{version}-%{release}
2013-07-24 14:43:43 +02:00
Requires: tar
Requires: xz
2013-05-21 13:40:27 +02:00
Requires: python-nose
Requires: python-paste
Requires: python-coverage
Requires: python-polib
2013-08-12 15:38:32 +02:00
Requires: python-paramiko >= 1.7.7
2013-05-21 13:40:27 +02:00
%description tests
IPA is an integrated solution to provide centrally managed Identity (machine,
user, virtual machines, groups, authentication credentials), Policy
(configuration settings, access control information) and Audit (events,
logs, analysis thereof).
This package contains tests that verify IPA functionality.
2013-08-13 10:56:26 +02:00
%endif # ONLY_CLIENT
2013-05-21 13:40:27 +02:00
2009-02-02 13:50:53 -05:00
%prep
%setup -n freeipa-%{version} -q
%build
2014-05-21 10:06:03 +02:00
%ifarch ppc %{power64} s390 s390x aarch64
2014-01-03 13:52:54 +01:00
# UI compilation segfaulted on some arches when the stack was lower (#1040576)
2013-12-13 15:20:40 +01:00
export JAVA_STACK_SIZE="8m"
%endif
2013-12-04 18:37:18 +01:00
export CFLAGS="%{optflags} $CFLAGS"
2013-12-04 18:39:44 +01:00
export LDFLAGS="%{__global_ldflags} $LDFLAGS"
2013-11-11 13:02:40 +01:00
%if 0%{?fedora} >= 19
export SUPPORTED_PLATFORM=fedora19
%else
2012-12-05 10:50:05 +01:00
%if 0%{?fedora} >= 18
# use fedora18 platform which is based on fedora16 platform with systemd
# support + fedora18 changes
export SUPPORTED_PLATFORM=fedora18
%else
2011-10-21 16:44:36 +03:00
export SUPPORTED_PLATFORM=fedora16
2012-12-05 10:50:05 +01:00
%endif
2013-11-11 13:02:40 +01:00
%endif
2014-03-13 14:39:03 +01:00
2011-10-21 16:44:36 +03:00
# Force re-generate of platform support
2014-03-13 14:39:03 +01:00
export IPA_VENDOR_VERSION_SUFFIX=-%{release}
rm -f ipapython/services.py ipapython/version.py
2009-02-02 13:50:53 -05:00
make version-update
2010-06-02 14:54:58 -04:00
cd ipa-client; ../autogen.sh --prefix=%{_usr} --sysconfdir=%{_sysconfdir} --localstatedir=%{_localstatedir} --libdir=%{_libdir} --mandir=%{_mandir}; cd ..
2009-10-12 16:00:00 -04:00
%if ! %{ONLY_CLIENT}
2010-12-03 15:02:29 -05:00
cd daemons; ../autogen.sh --prefix=%{_usr} --sysconfdir=%{_sysconfdir} --localstatedir=%{_localstatedir} --libdir=%{_libdir} --mandir=%{_mandir} --with-openldap; cd ..
2009-02-03 16:56:41 -05:00
cd install; ../autogen.sh --prefix=%{_usr} --sysconfdir=%{_sysconfdir} --localstatedir=%{_localstatedir} --libdir=%{_libdir} --mandir=%{_mandir}; cd ..
2013-08-13 10:56:26 +02:00
%endif # ONLY_CLIENT
2009-02-02 13:50:53 -05:00
2009-10-12 16:00:00 -04:00
%if ! %{ONLY_CLIENT}
2011-06-17 10:58:01 +02:00
make IPA_VERSION_IS_GIT_SNAPSHOT=no %{?_smp_mflags} all
2009-10-12 16:00:00 -04:00
%else
2011-06-17 10:58:01 +02:00
make IPA_VERSION_IS_GIT_SNAPSHOT=no %{?_smp_mflags} client
2013-08-13 10:56:26 +02:00
%endif # ONLY_CLIENT
2009-02-02 13:50:53 -05:00
%install
rm -rf %{buildroot}
2013-11-11 13:02:40 +01:00
%if 0%{?fedora} >= 19
export SUPPORTED_PLATFORM=fedora19
%else
2012-12-05 10:50:05 +01:00
%if 0%{?fedora} >= 18
# use fedora18 platform which is based on fedora16 platform with systemd
# support + fedora18 changes
export SUPPORTED_PLATFORM=fedora18
%else
2011-10-21 16:44:36 +03:00
export SUPPORTED_PLATFORM=fedora16
2012-12-05 10:50:05 +01:00
%endif
2013-11-11 13:02:40 +01:00
%endif
2011-10-21 16:44:36 +03:00
# Force re-generate of platform support
2014-03-13 14:39:03 +01:00
export IPA_VENDOR_VERSION_SUFFIX=-%{release}
rm -f ipapython/services.py ipapython/version.py
make version-update
2009-10-12 16:00:00 -04:00
%if ! %{ONLY_CLIENT}
2009-02-02 13:50:53 -05:00
make install DESTDIR=%{buildroot}
2009-10-12 16:00:00 -04:00
%else
make client-install DESTDIR=%{buildroot}
2013-08-13 10:56:26 +02:00
%endif # ONLY_CLIENT
2010-02-09 13:14:25 -05:00
%find_lang %{gettext_domain}
2009-02-02 13:50:53 -05:00
2009-10-12 16:00:00 -04:00
%if ! %{ONLY_CLIENT}
2009-02-02 13:50:53 -05:00
# Remove .la files from libtool - we don't want to package
# these files
rm %{buildroot}/%{plugin_dir}/libipa_pwd_extop.la
2009-09-14 17:04:08 -04:00
rm %{buildroot}/%{plugin_dir}/libipa_enrollment_extop.la
2009-02-02 13:50:53 -05:00
rm %{buildroot}/%{plugin_dir}/libipa_winsync.la
2010-06-24 10:31:52 -04:00
rm %{buildroot}/%{plugin_dir}/libipa_repl_version.la
2010-10-15 10:49:29 -04:00
rm %{buildroot}/%{plugin_dir}/libipa_uuid.la
2010-10-19 17:11:31 -04:00
rm %{buildroot}/%{plugin_dir}/libipa_modrdn.la
2011-01-18 14:58:58 -05:00
rm %{buildroot}/%{plugin_dir}/libipa_lockout.la
2011-11-09 19:03:48 -05:00
rm %{buildroot}/%{plugin_dir}/libipa_cldap.la
2013-03-08 18:54:58 +01:00
rm %{buildroot}/%{plugin_dir}/libipa_dns.la
2012-06-21 12:54:34 +02:00
rm %{buildroot}/%{plugin_dir}/libipa_sidgen.la
rm %{buildroot}/%{plugin_dir}/libipa_sidgen_task.la
2011-11-30 13:29:10 +01:00
rm %{buildroot}/%{plugin_dir}/libipa_extdom_extop.la
2012-06-18 21:25:31 +02:00
rm %{buildroot}/%{plugin_dir}/libipa_range_check.la
2013-12-16 16:19:08 -05:00
rm %{buildroot}/%{plugin_dir}/libipa_otp_lasttoken.la
2011-05-19 16:24:57 -04:00
rm %{buildroot}/%{_libdir}/krb5/plugins/kdb/ipadb.la
2011-10-25 10:33:30 +02:00
rm %{buildroot}/%{_libdir}/samba/pdb/ipasam.la
2009-02-02 13:50:53 -05:00
# Some user-modifiable HTML files are provided. Move these to /etc
# and link back.
mkdir -p %{buildroot}/%{_sysconfdir}/ipa/html
mkdir -p %{buildroot}/%{_localstatedir}/cache/ipa/sysrestore
2012-06-08 08:31:37 +02:00
mkdir -p %{buildroot}/%{_localstatedir}/cache/ipa/sysupgrade
2009-02-02 13:50:53 -05:00
mkdir %{buildroot}%{_usr}/share/ipa/html/
2012-10-01 17:36:42 +02:00
ln -s ../../../..%{_sysconfdir}/ipa/html/ffconfig.js \
%{buildroot}%{_usr}/share/ipa/html/ffconfig.js
ln -s ../../../..%{_sysconfdir}/ipa/html/ffconfig_page.js \
%{buildroot}%{_usr}/share/ipa/html/ffconfig_page.js
2009-02-02 13:50:53 -05:00
ln -s ../../../..%{_sysconfdir}/ipa/html/ssbrowser.html \
%{buildroot}%{_usr}/share/ipa/html/ssbrowser.html
ln -s ../../../..%{_sysconfdir}/ipa/html/unauthorized.html \
%{buildroot}%{_usr}/share/ipa/html/unauthorized.html
2011-01-25 14:44:42 -05:00
ln -s ../../../..%{_sysconfdir}/ipa/html/browserconfig.html \
%{buildroot}%{_usr}/share/ipa/html/browserconfig.html
2009-02-02 13:50:53 -05:00
2009-05-14 09:29:16 -04:00
# So we can own our Apache configuration
2011-01-25 11:03:40 -05:00
mkdir -p %{buildroot}%{_sysconfdir}/httpd/conf.d/
/bin/touch %{buildroot}%{_sysconfdir}/httpd/conf.d/ipa.conf
2011-08-17 15:36:18 -04:00
/bin/touch %{buildroot}%{_sysconfdir}/httpd/conf.d/ipa-pki-proxy.conf
2011-01-25 11:03:40 -05:00
/bin/touch %{buildroot}%{_sysconfdir}/httpd/conf.d/ipa-rewrite.conf
2012-01-31 18:32:47 +01:00
mkdir -p %{buildroot}%{_usr}/share/ipa/html/
/bin/touch %{buildroot}%{_usr}/share/ipa/html/ca.crt
/bin/touch %{buildroot}%{_usr}/share/ipa/html/configure.jar
2012-10-04 17:08:17 +02:00
/bin/touch %{buildroot}%{_usr}/share/ipa/html/kerberosauth.xpi
2012-01-31 18:32:47 +01:00
/bin/touch %{buildroot}%{_usr}/share/ipa/html/krb.con
2012-10-04 17:08:17 +02:00
/bin/touch %{buildroot}%{_usr}/share/ipa/html/krb.js
2012-01-31 18:32:47 +01:00
/bin/touch %{buildroot}%{_usr}/share/ipa/html/krb5.ini
/bin/touch %{buildroot}%{_usr}/share/ipa/html/krbrealm.con
/bin/touch %{buildroot}%{_usr}/share/ipa/html/preferences.html
2011-07-20 18:11:05 -04:00
mkdir -p %{buildroot}%{_initrddir}
2012-02-06 13:15:06 -05:00
mkdir %{buildroot}%{_sysconfdir}/sysconfig/
install -m 644 init/ipa_memcached.conf %{buildroot}%{_sysconfdir}/sysconfig/ipa_memcached
2013-03-20 17:28:17 +01:00
# Web UI plugin dir
mkdir -p %{buildroot}%{_usr}/share/ipa/ui/js/plugins
2012-11-14 16:45:41 +01:00
# NOTE: systemd specific section
2013-09-04 18:18:13 +02:00
mkdir -p %{buildroot}%{_prefix}/lib/tmpfiles.d
install -m 0644 init/systemd/ipa.conf.tmpfiles %{buildroot}%{_prefix}/lib/tmpfiles.d/%{name}.conf
2012-11-14 16:45:41 +01:00
# END
2012-02-06 13:15:06 -05:00
mkdir -p %{buildroot}%{_localstatedir}/run/
install -d -m 0700 %{buildroot}%{_localstatedir}/run/ipa_memcached/
2012-10-31 14:10:41 -04:00
install -d -m 0700 %{buildroot}%{_localstatedir}/run/ipa/
2012-02-06 13:15:06 -05:00
2012-10-10 09:46:08 +03:00
mkdir -p %{buildroot}%{_libdir}/krb5/plugins/libkrb5
touch %{buildroot}%{_libdir}/krb5/plugins/libkrb5/winbind_krb5_locator.so
2012-11-14 16:45:41 +01:00
# NOTE: systemd specific section
2011-10-21 16:44:36 +03:00
mkdir -p %{buildroot}%{_unitdir}
install -m 644 init/systemd/ipa.service %{buildroot}%{_unitdir}/ipa.service
2012-02-06 13:15:06 -05:00
install -m 644 init/systemd/ipa_memcached.service %{buildroot}%{_unitdir}/ipa_memcached.service
2012-11-14 16:45:41 +01:00
# END
2013-03-13 09:36:41 -04:00
mkdir -p %{buildroot}/%{_localstatedir}/lib/ipa/backup
2013-08-13 10:56:26 +02:00
%endif # ONLY_CLIENT
2010-12-04 15:42:14 -05:00
2011-01-25 11:03:40 -05:00
mkdir -p %{buildroot}%{_sysconfdir}/ipa/
/bin/touch %{buildroot}%{_sysconfdir}/ipa/default.conf
2012-01-31 18:32:47 +01:00
/bin/touch %{buildroot}%{_sysconfdir}/ipa/ca.crt
2009-10-12 16:00:00 -04:00
mkdir -p %{buildroot}/%{_localstatedir}/lib/ipa-client/sysrestore
2009-05-14 09:29:16 -04:00
2009-11-23 16:19:14 -05:00
%if ! %{ONLY_CLIENT}
2011-01-25 11:03:40 -05:00
mkdir -p %{buildroot}%{_sysconfdir}/bash_completion.d
install -pm 644 contrib/completion/ipa.bash_completion %{buildroot}%{_sysconfdir}/bash_completion.d/ipa
2011-02-01 14:24:46 -05:00
mkdir -p %{buildroot}%{_sysconfdir}/cron.d
2009-11-23 16:19:14 -05:00
2012-06-12 15:58:50 +03:00
(cd %{buildroot}/%{python_sitelib}/ipaserver && find . -type f | \
2013-08-13 10:56:26 +02:00
grep -v dcerpc | grep -v adtrustinstance | \
sed -e 's,\.py.*$,.*,g' | sort -u | \
sed -e 's,\./,%%{python_sitelib}/ipaserver/,g' ) >server-python.list
2013-05-21 13:40:27 +02:00
(cd %{buildroot}/%{python_sitelib}/ipatests && find . -type f | \
sed -e 's,\.py.*$,.*,g' | sort -u | \
sed -e 's,\./,%%{python_sitelib}/ipatests/,g' ) >tests-python.list
2013-08-13 10:56:26 +02:00
%endif # ONLY_CLIENT
2012-06-12 15:58:50 +03:00
2009-02-02 13:50:53 -05:00
%clean
rm -rf %{buildroot}
2009-10-12 16:00:00 -04:00
%if ! %{ONLY_CLIENT}
2009-02-02 13:50:53 -05:00
%post server
2012-11-14 16:45:41 +01:00
# NOTE: systemd specific section
2011-10-21 16:44:36 +03:00
/bin/systemctl --system daemon-reload 2>&1 || :
2012-11-14 16:45:41 +01:00
# END
2011-03-18 11:19:53 -04:00
if [ $1 -gt 1 ] ; then
2013-01-24 16:14:31 -05:00
/bin/systemctl condrestart certmonger.service 2>&1 || :
2011-03-18 11:19:53 -04:00
fi
2009-02-02 13:50:53 -05:00
2011-11-23 16:52:40 -05:00
%posttrans server
# This must be run in posttrans so that updates from previous
# execution that may no longer be shipped are not applied.
2013-03-12 15:25:40 +01:00
/usr/sbin/ipa-ldap-updater --upgrade --quiet >/dev/null || :
2013-07-11 17:35:26 +03:00
/usr/sbin/ipa-upgradeconfig --quiet >/dev/null || :
# Restart IPA processes. This must be also run in postrans so that plugins
# and software is in consistent state
2013-11-27 14:53:57 +01:00
python2 -c "import sys; from ipaserver.install import installutils; sys.exit(0 if installutils.is_ipa_configured() else 1);" > /dev/null 2>&1
2013-07-11 17:35:26 +03:00
# NOTE: systemd specific section
if [ $? -eq 0 ]; then
/bin/systemctl try-restart ipa.service >/dev/null 2>&1 || :
fi
# END
2011-11-23 16:52:40 -05:00
2009-02-02 13:50:53 -05:00
%preun server
if [ $1 = 0 ]; then
2012-11-14 16:45:41 +01:00
# NOTE: systemd specific section
2011-10-21 16:44:36 +03:00
/bin/systemctl --quiet stop ipa.service || :
/bin/systemctl --quiet disable ipa.service || :
2012-11-14 16:45:41 +01:00
# END
2009-02-02 13:50:53 -05:00
fi
2012-02-13 09:16:26 -05:00
%pre server
# Stop ipa_kpasswd if it exists before upgrading so we don't have a
# zombie process when we're done.
if [ -e /usr/sbin/ipa_kpasswd ]; then
2012-11-14 16:45:41 +01:00
# NOTE: systemd specific section
2012-02-13 09:16:26 -05:00
/bin/systemctl stop ipa_kpasswd.service >/dev/null 2>&1 || :
2012-11-14 16:45:41 +01:00
# END
2012-02-13 09:16:26 -05:00
fi
2012-10-10 09:46:08 +03:00
%postun server-trust-ad
if [ "$1" -ge "1" ]; then
2013-08-13 10:56:26 +02:00
if [ "`readlink %{_sysconfdir}/alternatives/winbind_krb5_locator.so`" == "/dev/null" ]; then
%{_sbindir}/alternatives --set winbind_krb5_locator.so /dev/null
fi
2012-10-10 09:46:08 +03:00
fi
%post server-trust-ad
%{_sbindir}/update-alternatives --install %{_libdir}/krb5/plugins/libkrb5/winbind_krb5_locator.so \
2013-08-13 10:56:26 +02:00
winbind_krb5_locator.so /dev/null 90
2013-07-11 17:35:26 +03:00
%posttrans server-trust-ad
2013-11-27 14:53:57 +01:00
python2 -c "import sys; from ipaserver.install import installutils; sys.exit(0 if installutils.is_ipa_configured() else 1);" > /dev/null 2>&1
2012-10-26 13:12:17 +02:00
if [ $? -eq 0 ]; then
2012-11-14 16:45:41 +01:00
# NOTE: systemd specific section
2012-10-26 13:12:17 +02:00
/bin/systemctl try-restart httpd.service >/dev/null 2>&1 || :
2012-11-14 16:45:41 +01:00
# END
2012-10-26 13:12:17 +02:00
fi
2012-10-10 09:46:08 +03:00
%preun server-trust-ad
if [ $1 -eq 0 ]; then
2013-08-13 10:56:26 +02:00
%{_sbindir}/update-alternatives --remove winbind_krb5_locator.so /dev/null
2012-10-10 09:46:08 +03:00
fi
2013-12-03 09:14:00 -07:00
%post server-foreman-smartproxy
if [ $1 -gt 1 ] ; then
2014-05-06 15:52:11 -04:00
/bin/systemctl try-restart httpd.service >/dev/null 2>&1 || :
2013-12-03 09:14:00 -07:00
fi
2013-08-13 10:56:26 +02:00
%endif # ONLY_CLIENT
2009-02-02 13:50:53 -05:00
2012-10-31 10:15:28 +01:00
%post client
if [ $1 -gt 1 ] ; then
# Has the client been configured?
restore=0
test -f '/var/lib/ipa-client/sysrestore/sysrestore.index' && restore=$(wc -l '/var/lib/ipa-client/sysrestore/sysrestore.index' | awk '{print $1}')
if [ -f '/etc/sssd/sssd.conf' -a $restore -ge 2 ]; then
2013-08-13 10:56:26 +02:00
if ! grep -E -q '/var/lib/sss/pubconf/krb5.include.d/' /etc/krb5.conf 2>/dev/null ; then
2012-10-31 10:15:28 +01:00
echo "includedir /var/lib/sss/pubconf/krb5.include.d/" > /etc/krb5.conf.ipanew
cat /etc/krb5.conf >> /etc/krb5.conf.ipanew
mv /etc/krb5.conf.ipanew /etc/krb5.conf
/sbin/restorecon /etc/krb5.conf
fi
fi
2014-01-24 10:16:48 +01:00
if [ -f '/etc/sysconfig/ntpd' -a $restore -ge 2 ]; then
if grep -E -q 'OPTIONS=.*-u ntp:ntp' /etc/sysconfig/ntpd 2>/dev/null; then
sed -r '/OPTIONS=/ { s/\s+-u ntp:ntp\s+/ /; s/\s*-u ntp:ntp\s*// }' /etc/sysconfig/ntpd >/etc/sysconfig/ntpd.ipanew
mv /etc/sysconfig/ntpd.ipanew /etc/sysconfig/ntpd
/sbin/restorecon /etc/sysconfig/ntpd
/bin/systemctl condrestart ntpd.service 2>&1 || :
fi
fi
2012-10-31 10:15:28 +01:00
fi
2009-02-02 13:50:53 -05:00
2013-04-18 18:06:54 +02:00
%triggerin -n freeipa-client -- openssh-server
# Has the client been configured?
restore=0
test -f '/var/lib/ipa-client/sysrestore/sysrestore.index' && restore=$(wc -l '/var/lib/ipa-client/sysrestore/sysrestore.index' | awk '{print $1}')
if [ -f '/etc/ssh/sshd_config' -a $restore -ge 2 ]; then
2013-08-13 10:56:26 +02:00
if grep -E -q '^(AuthorizedKeysCommand /usr/bin/sss_ssh_authorizedkeys|PubKeyAgent /usr/bin/sss_ssh_authorizedkeys %u)$' /etc/ssh/sshd_config 2>/dev/null; then
2013-04-18 18:06:54 +02:00
sed -r '
/^(AuthorizedKeysCommand(User|RunAs)|PubKeyAgentRunAs)[ \t]/ d
' /etc/ssh/sshd_config >/etc/ssh/sshd_config.ipanew
if /usr/sbin/sshd -t -f /dev/null -o 'AuthorizedKeysCommand=/usr/bin/sss_ssh_authorizedkeys' -o 'AuthorizedKeysCommandUser=nobody'; then
sed -ri '
s/^PubKeyAgent (.+) %u$/AuthorizedKeysCommand \1/
s/^AuthorizedKeysCommand .*$/\0\nAuthorizedKeysCommandUser nobody/
' /etc/ssh/sshd_config.ipanew
elif /usr/sbin/sshd -t -f /dev/null -o 'AuthorizedKeysCommand=/usr/bin/sss_ssh_authorizedkeys' -o 'AuthorizedKeysCommandRunAs=nobody'; then
sed -ri '
s/^PubKeyAgent (.+) %u$/AuthorizedKeysCommand \1/
s/^AuthorizedKeysCommand .*$/\0\nAuthorizedKeysCommandRunAs nobody/
' /etc/ssh/sshd_config.ipanew
elif /usr/sbin/sshd -t -f /dev/null -o 'PubKeyAgent=/usr/bin/sss_ssh_authorizedkeys %u' -o 'PubKeyAgentRunAs=nobody'; then
sed -ri '
s/^AuthorizedKeysCommand (.+)$/PubKeyAgent \1 %u/
s/^PubKeyAgent .*$/\0\nPubKeyAgentRunAs nobody/
' /etc/ssh/sshd_config.ipanew
fi
mv /etc/ssh/sshd_config.ipanew /etc/ssh/sshd_config
/sbin/restorecon /etc/ssh/sshd_config
chmod 600 /etc/ssh/sshd_config
/bin/systemctl condrestart sshd.service 2>&1 || :
fi
fi
2009-10-12 16:00:00 -04:00
%if ! %{ONLY_CLIENT}
2012-06-12 15:58:50 +03:00
%files server -f server-python.list
2009-02-02 13:50:53 -05:00
%defattr(-,root,root,-)
2011-01-25 11:03:40 -05:00
%doc COPYING README Contributors.txt
2013-03-13 09:36:41 -04:00
%{_sbindir}/ipa-backup
%{_sbindir}/ipa-restore
2011-06-17 16:47:39 -04:00
%{_sbindir}/ipa-ca-install
2009-11-23 09:26:50 +01:00
%{_sbindir}/ipa-dns-install
2009-02-02 13:50:53 -05:00
%{_sbindir}/ipa-server-install
2011-05-22 19:17:07 +02:00
%{_sbindir}/ipa-replica-conncheck
2009-02-02 13:50:53 -05:00
%{_sbindir}/ipa-replica-install
%{_sbindir}/ipa-replica-prepare
%{_sbindir}/ipa-replica-manage
2011-07-14 23:35:01 -04:00
%{_sbindir}/ipa-csreplica-manage
2009-02-02 13:50:53 -05:00
%{_sbindir}/ipa-server-certinstall
2011-02-11 14:05:20 -05:00
%{_sbindir}/ipa-ldap-updater
%{_sbindir}/ipa-compat-manage
%{_sbindir}/ipa-nis-manage
2011-09-20 09:13:42 -07:00
%{_sbindir}/ipa-managed-entries
2009-02-02 13:50:53 -05:00
%{_sbindir}/ipactl
%{_sbindir}/ipa-upgradeconfig
2013-06-10 14:43:24 +02:00
%{_sbindir}/ipa-advise
2013-10-16 07:26:39 +00:00
%{_libexecdir}/certmonger/dogtag-ipa-ca-renew-agent-submit
2013-04-11 14:03:25 -04:00
%{_libexecdir}/ipa-otpd
2012-02-06 13:15:06 -05:00
%config(noreplace) %{_sysconfdir}/sysconfig/ipa_memcached
%dir %attr(0700,apache,apache) %{_localstatedir}/run/ipa_memcached/
2012-10-31 14:10:41 -04:00
%dir %attr(0700,root,root) %{_localstatedir}/run/ipa/
2012-11-14 16:45:41 +01:00
# NOTE: systemd specific section
2013-09-04 18:18:13 +02:00
%{_prefix}/lib/tmpfiles.d/%{name}.conf
2011-10-21 16:44:36 +03:00
%attr(644,root,root) %{_unitdir}/ipa.service
2012-02-06 13:15:06 -05:00
%attr(644,root,root) %{_unitdir}/ipa_memcached.service
2013-04-11 14:03:25 -04:00
%attr(644,root,root) %{_unitdir}/ipa-otpd.socket
%attr(644,root,root) %{_unitdir}/ipa-otpd@.service
2012-11-14 16:45:41 +01:00
# END
2011-01-05 15:51:56 -05:00
%dir %{python_sitelib}/ipaserver
2012-06-12 15:58:50 +03:00
%dir %{python_sitelib}/ipaserver/install
%dir %{python_sitelib}/ipaserver/install/plugins
2013-06-10 14:43:24 +02:00
%dir %{python_sitelib}/ipaserver/advise
%dir %{python_sitelib}/ipaserver/advise/plugins
2012-06-12 15:58:50 +03:00
%dir %{python_sitelib}/ipaserver/plugins
2012-04-10 21:21:08 +02:00
%dir %{_libdir}/ipa/certmonger
%attr(755,root,root) %{_libdir}/ipa/certmonger/*
2009-02-02 13:50:53 -05:00
%dir %{_usr}/share/ipa
2010-03-01 21:41:41 -07:00
%{_usr}/share/ipa/wsgi.py*
2012-10-24 04:37:16 -04:00
%{_usr}/share/ipa/copy-schema-to-ca.py*
2009-02-02 13:50:53 -05:00
%{_usr}/share/ipa/*.ldif
%{_usr}/share/ipa/*.uldif
%{_usr}/share/ipa/*.template
2013-08-01 14:12:39 +02:00
%dir %{_usr}/share/ipa/advise
%dir %{_usr}/share/ipa/advise/legacy
%{_usr}/share/ipa/advise/legacy/*.template
2012-10-02 16:47:28 +02:00
%dir %{_usr}/share/ipa/ffextension
%{_usr}/share/ipa/ffextension/bootstrap.js
%{_usr}/share/ipa/ffextension/install.rdf
%{_usr}/share/ipa/ffextension/chrome.manifest
%dir %{_usr}/share/ipa/ffextension/chrome
%dir %{_usr}/share/ipa/ffextension/chrome/content
%{_usr}/share/ipa/ffextension/chrome/content/kerberosauth.js
%{_usr}/share/ipa/ffextension/chrome/content/kerberosauth_overlay.xul
%dir %{_usr}/share/ipa/ffextension/locale
%dir %{_usr}/share/ipa/ffextension/locale/en-US
%{_usr}/share/ipa/ffextension/locale/en-US/kerberosauth.properties
2009-02-02 13:50:53 -05:00
%dir %{_usr}/share/ipa/html
2012-10-01 17:36:42 +02:00
%{_usr}/share/ipa/html/ffconfig.js
%{_usr}/share/ipa/html/ffconfig_page.js
2009-02-02 13:50:53 -05:00
%{_usr}/share/ipa/html/ssbrowser.html
2011-01-25 14:44:42 -05:00
%{_usr}/share/ipa/html/browserconfig.html
2009-02-02 13:50:53 -05:00
%{_usr}/share/ipa/html/unauthorized.html
2010-01-12 16:40:09 +01:00
%dir %{_usr}/share/ipa/migration
%{_usr}/share/ipa/migration/error.html
%{_usr}/share/ipa/migration/index.html
%{_usr}/share/ipa/migration/invalid.html
%{_usr}/share/ipa/migration/migration.py*
2011-01-19 12:26:14 -05:00
%dir %{_usr}/share/ipa/ui
%{_usr}/share/ipa/ui/index.html
2012-06-08 16:38:17 +02:00
%{_usr}/share/ipa/ui/reset_password.html
2011-08-02 12:42:42 -05:00
%{_usr}/share/ipa/ui/*.ico
2011-01-19 12:26:14 -05:00
%{_usr}/share/ipa/ui/*.css
%{_usr}/share/ipa/ui/*.js
2013-12-04 16:15:20 +01:00
%dir %{_usr}/share/ipa/ui/css
2013-10-10 13:41:31 +02:00
%{_usr}/share/ipa/ui/css/*.css
2013-11-27 13:20:22 +00:00
%dir %{_usr}/share/ipa/ui/js
2012-11-23 17:19:37 +01:00
%dir %{_usr}/share/ipa/ui/js/dojo
%{_usr}/share/ipa/ui/js/dojo/dojo.js
%dir %{_usr}/share/ipa/ui/js/libs
%{_usr}/share/ipa/ui/js/libs/*.js
%dir %{_usr}/share/ipa/ui/js/freeipa
%{_usr}/share/ipa/ui/js/freeipa/app.js
2013-03-20 17:28:17 +01:00
%dir %{_usr}/share/ipa/ui/js/plugins
2011-10-26 16:06:17 -05:00
%dir %{_usr}/share/ipa/ui/images
2013-11-13 16:02:48 +01:00
%{_usr}/share/ipa/ui/images/*.jpg
2011-10-26 16:06:17 -05:00
%{_usr}/share/ipa/ui/images/*.png
%{_usr}/share/ipa/ui/images/*.gif
2013-04-23 19:54:21 +02:00
%dir %{_usr}/share/ipa/wsgi
%{_usr}/share/ipa/wsgi/plugins.py*
%dir %{_sysconfdir}/ipa
2009-02-02 13:50:53 -05:00
%dir %{_sysconfdir}/ipa/html
2012-10-01 17:36:42 +02:00
%config(noreplace) %{_sysconfdir}/ipa/html/ffconfig.js
%config(noreplace) %{_sysconfdir}/ipa/html/ffconfig_page.js
2009-02-02 13:50:53 -05:00
%config(noreplace) %{_sysconfdir}/ipa/html/ssbrowser.html
%config(noreplace) %{_sysconfdir}/ipa/html/unauthorized.html
2011-01-25 14:44:42 -05:00
%config(noreplace) %{_sysconfdir}/ipa/html/browserconfig.html
2009-09-16 13:04:14 -04:00
%ghost %attr(0644,root,apache) %config(noreplace) %{_sysconfdir}/httpd/conf.d/ipa-rewrite.conf
%ghost %attr(0644,root,apache) %config(noreplace) %{_sysconfdir}/httpd/conf.d/ipa.conf
2011-08-17 15:36:18 -04:00
%ghost %attr(0644,root,apache) %config(noreplace) %{_sysconfdir}/httpd/conf.d/ipa-pki-proxy.conf
2009-02-02 13:50:53 -05:00
%{_usr}/share/ipa/ipa.conf
%{_usr}/share/ipa/ipa-rewrite.conf
2011-08-17 15:36:18 -04:00
%{_usr}/share/ipa/ipa-pki-proxy.conf
2012-01-31 18:32:47 +01:00
%ghost %attr(0644,root,apache) %config(noreplace) %{_usr}/share/ipa/html/ca.crt
%ghost %attr(0644,root,apache) %{_usr}/share/ipa/html/configure.jar
2012-10-04 17:08:17 +02:00
%ghost %attr(0644,root,apache) %{_usr}/share/ipa/html/kerberosauth.xpi
2012-01-31 18:32:47 +01:00
%ghost %attr(0644,root,apache) %{_usr}/share/ipa/html/krb.con
2012-10-04 17:08:17 +02:00
%ghost %attr(0644,root,apache) %{_usr}/share/ipa/html/krb.js
2012-01-31 18:32:47 +01:00
%ghost %attr(0644,root,apache) %{_usr}/share/ipa/html/krb5.ini
%ghost %attr(0644,root,apache) %{_usr}/share/ipa/html/krbrealm.con
%ghost %attr(0644,root,apache) %{_usr}/share/ipa/html/preferences.html
2009-02-02 13:50:53 -05:00
%dir %{_usr}/share/ipa/updates/
%{_usr}/share/ipa/updates/*
%attr(755,root,root) %{plugin_dir}/libipa_pwd_extop.so
2009-09-14 17:04:08 -04:00
%attr(755,root,root) %{plugin_dir}/libipa_enrollment_extop.so
2009-02-02 13:50:53 -05:00
%attr(755,root,root) %{plugin_dir}/libipa_winsync.so
2010-06-24 10:31:52 -04:00
%attr(755,root,root) %{plugin_dir}/libipa_repl_version.so
2010-10-15 10:49:29 -04:00
%attr(755,root,root) %{plugin_dir}/libipa_uuid.so
2010-10-19 17:11:31 -04:00
%attr(755,root,root) %{plugin_dir}/libipa_modrdn.so
2011-01-18 14:58:58 -05:00
%attr(755,root,root) %{plugin_dir}/libipa_lockout.so
2011-11-09 19:03:48 -05:00
%attr(755,root,root) %{plugin_dir}/libipa_cldap.so
2013-03-08 18:54:58 +01:00
%attr(755,root,root) %{plugin_dir}/libipa_dns.so
2012-06-18 21:25:31 +02:00
%attr(755,root,root) %{plugin_dir}/libipa_range_check.so
2013-12-16 16:19:08 -05:00
%attr(755,root,root) %{plugin_dir}/libipa_otp_lasttoken.so
2009-02-02 13:50:53 -05:00
%dir %{_localstatedir}/lib/ipa
2013-04-16 09:44:28 +02:00
%attr(700,root,root) %dir %{_localstatedir}/lib/ipa/backup
2009-02-02 13:50:53 -05:00
%attr(700,root,root) %dir %{_localstatedir}/lib/ipa/sysrestore
2012-06-08 08:31:37 +02:00
%attr(700,root,root) %dir %{_localstatedir}/lib/ipa/sysupgrade
2012-10-08 15:58:48 +02:00
%attr(755,root,root) %dir %{_localstatedir}/lib/ipa/pki-ca
2013-07-16 12:10:54 +02:00
%ghost %{_localstatedir}/lib/ipa/pki-ca/publish
2011-05-19 16:24:57 -04:00
%attr(755,root,root) %{_libdir}/krb5/plugins/kdb/ipadb.so
2011-05-22 19:17:07 +02:00
%{_mandir}/man1/ipa-replica-conncheck.1.gz
2009-02-02 13:50:53 -05:00
%{_mandir}/man1/ipa-replica-install.1.gz
%{_mandir}/man1/ipa-replica-manage.1.gz
2011-07-14 23:35:01 -04:00
%{_mandir}/man1/ipa-csreplica-manage.1.gz
2009-02-02 13:50:53 -05:00
%{_mandir}/man1/ipa-replica-prepare.1.gz
%{_mandir}/man1/ipa-server-certinstall.1.gz
%{_mandir}/man1/ipa-server-install.1.gz
2011-01-10 10:37:45 -05:00
%{_mandir}/man1/ipa-dns-install.1.gz
2011-06-17 16:47:39 -04:00
%{_mandir}/man1/ipa-ca-install.1.gz
2011-02-11 14:05:20 -05:00
%{_mandir}/man1/ipa-compat-manage.1.gz
%{_mandir}/man1/ipa-nis-manage.1.gz
2011-09-20 09:13:42 -07:00
%{_mandir}/man1/ipa-managed-entries.1.gz
2011-02-11 14:05:20 -05:00
%{_mandir}/man1/ipa-ldap-updater.1.gz
2009-02-02 13:50:53 -05:00
%{_mandir}/man8/ipactl.8.gz
2012-01-20 13:30:25 -05:00
%{_mandir}/man8/ipa-upgradeconfig.8.gz
2013-03-13 09:36:41 -04:00
%{_mandir}/man1/ipa-backup.1.gz
%{_mandir}/man1/ipa-restore.1.gz
2013-06-10 14:43:24 +02:00
%{_mandir}/man1/ipa-advise.1.gz
2009-02-02 13:50:53 -05:00
2012-02-28 13:24:41 +02:00
%files server-trust-ad
2012-06-12 15:58:50 +03:00
%{_sbindir}/ipa-adtrust-install
2011-11-30 13:29:10 +01:00
%attr(755,root,root) %{plugin_dir}/libipa_extdom_extop.so
2012-02-28 13:24:41 +02:00
%{_usr}/share/ipa/smb.conf.empty
2012-06-12 15:58:50 +03:00
%attr(755,root,root) %{_libdir}/samba/pdb/ipasam.so
2012-06-21 12:54:34 +02:00
%attr(755,root,root) %{plugin_dir}/libipa_sidgen.so
%attr(755,root,root) %{plugin_dir}/libipa_sidgen_task.so
2012-06-12 15:58:50 +03:00
%{_mandir}/man1/ipa-adtrust-install.1.gz
%{python_sitelib}/ipaserver/dcerpc*
%{python_sitelib}/ipaserver/install/adtrustinstance*
2012-10-10 09:46:08 +03:00
%ghost %{_libdir}/krb5/plugins/libkrb5/winbind_krb5_locator.so
2013-12-03 09:14:00 -07:00
%files server-foreman-smartproxy
%doc COPYING README smartproxy/ipa-smartproxy-apache.conf
%dir %{_usr}/share/ipa/smartproxy
%{_usr}/share/ipa/smartproxy/ipa-smartproxy.py*
%{_mandir}/man1/ipa-smartproxy.1.gz
%{_mandir}/man5/ipa-smartproxy.conf.5.gz
%config(noreplace) %{_sysconfdir}/ipa/ipa-smartproxy.conf
2013-08-13 10:56:26 +02:00
%endif # ONLY_CLIENT
2009-02-02 13:50:53 -05:00
%files client
2011-01-25 11:03:40 -05:00
%defattr(-,root,root,-)
2010-12-09 13:59:11 +01:00
%doc COPYING README Contributors.txt
2009-02-02 13:50:53 -05:00
%{_sbindir}/ipa-client-install
2012-05-29 14:20:38 -04:00
%{_sbindir}/ipa-client-automount
2009-02-02 13:50:53 -05:00
%{_sbindir}/ipa-getkeytab
2009-12-04 16:29:09 -05:00
%{_sbindir}/ipa-rmkeytab
2009-09-14 17:04:08 -04:00
%{_sbindir}/ipa-join
2009-02-02 13:50:53 -05:00
%dir %{_usr}/share/ipa
%dir %{_localstatedir}/lib/ipa-client
%dir %{_localstatedir}/lib/ipa-client/sysrestore
%dir %{python_sitelib}/ipaclient
%{python_sitelib}/ipaclient/*.py*
%{_mandir}/man1/ipa-getkeytab.1.gz
2009-12-04 16:29:09 -05:00
%{_mandir}/man1/ipa-rmkeytab.1.gz
2009-02-02 13:50:53 -05:00
%{_mandir}/man1/ipa-client-install.1.gz
2012-05-29 14:20:38 -04:00
%{_mandir}/man1/ipa-client-automount.1.gz
2009-10-08 11:10:21 -04:00
%{_mandir}/man1/ipa-join.1.gz
2011-02-23 11:55:32 -05:00
%{_mandir}/man5/default.conf.5.gz
2009-02-02 13:50:53 -05:00
2009-10-12 16:00:00 -04:00
%if ! %{ONLY_CLIENT}
2009-02-02 13:50:53 -05:00
%files admintools
%defattr(-,root,root,-)
2011-01-25 11:03:40 -05:00
%doc COPYING README Contributors.txt
2009-02-04 10:50:52 -05:00
%{_bindir}/ipa
2011-01-27 17:02:24 -05:00
%config %{_sysconfdir}/bash_completion.d
2010-03-29 14:25:57 +02:00
%{_mandir}/man1/ipa.1.gz
2013-08-13 10:56:26 +02:00
%endif # ONLY_CLIENT
2009-02-02 13:50:53 -05:00
2010-02-09 13:14:25 -05:00
%files python -f %{gettext_domain}.lang
2009-02-02 13:50:53 -05:00
%defattr(-,root,root,-)
2011-01-25 11:03:40 -05:00
%doc COPYING README Contributors.txt
2009-02-05 15:03:08 -05:00
%dir %{python_sitelib}/ipapython
2011-09-13 00:01:23 +03:00
%dir %{python_sitelib}/ipapython/platform
2012-12-05 14:58:06 +02:00
%dir %{python_sitelib}/ipapython/platform/base
%dir %{python_sitelib}/ipapython/platform/fedora16
%dir %{python_sitelib}/ipapython/platform/fedora18
2013-11-11 13:02:40 +01:00
%dir %{python_sitelib}/ipapython/platform/fedora19
2012-12-05 14:58:06 +02:00
%dir %{python_sitelib}/ipapython/platform/redhat
2009-02-05 15:03:08 -05:00
%{python_sitelib}/ipapython/*.py*
2011-09-13 00:01:23 +03:00
%{python_sitelib}/ipapython/platform/*.py*
2012-12-05 14:58:06 +02:00
%{python_sitelib}/ipapython/platform/base/*.py*
%{python_sitelib}/ipapython/platform/fedora16/*.py*
%{python_sitelib}/ipapython/platform/fedora18/*.py*
2013-11-11 13:02:40 +01:00
%{python_sitelib}/ipapython/platform/fedora19/*.py*
2012-12-05 14:58:06 +02:00
%{python_sitelib}/ipapython/platform/redhat/*.py*
2011-01-05 15:51:56 -05:00
%dir %{python_sitelib}/ipalib
2009-05-21 15:25:57 -04:00
%{python_sitelib}/ipalib/*
2013-08-13 10:59:57 +02:00
%attr(0644,root,root) %{python_sitearch}/default_encoding_utf8.so
2009-02-05 15:03:08 -05:00
%{python_sitelib}/ipapython-*.egg-info
2009-10-12 16:00:00 -04:00
%{python_sitelib}/freeipa-*.egg-info
2010-10-06 13:41:26 -04:00
%{python_sitearch}/python_default_encoding-*.egg-info
2013-04-22 11:22:42 +02:00
%dir %attr(0755,root,root) %{_sysconfdir}/ipa/
2011-01-27 17:02:24 -05:00
%ghost %attr(0644,root,apache) %config(noreplace) %{_sysconfdir}/ipa/default.conf
2012-01-31 18:32:47 +01:00
%ghost %attr(0644,root,apache) %config(noreplace) %{_sysconfdir}/ipa/ca.crt
2009-02-02 13:50:53 -05:00
2013-05-21 13:40:27 +02:00
%if ! %{ONLY_CLIENT}
%files tests -f tests-python.list
%defattr(-,root,root,-)
%doc COPYING README Contributors.txt
%dir %{python_sitelib}/ipatests
%dir %{python_sitelib}/ipatests/test_cmdline
%dir %{python_sitelib}/ipatests/test_install
%dir %{python_sitelib}/ipatests/test_ipalib
%dir %{python_sitelib}/ipatests/test_ipapython
%dir %{python_sitelib}/ipatests/test_ipaserver
2012-04-20 07:03:16 -04:00
%dir %{python_sitelib}/ipatests/test_ipaserver/test_install
2013-05-21 13:40:27 +02:00
%dir %{python_sitelib}/ipatests/test_pkcs10
2013-05-24 13:48:53 +02:00
%dir %{python_sitelib}/ipatests/test_webui
2013-05-21 13:40:27 +02:00
%dir %{python_sitelib}/ipatests/test_xmlrpc
2013-05-22 11:08:10 +02:00
%{_bindir}/ipa-run-tests
2013-05-24 19:55:21 +02:00
%{_bindir}/ipa-test-config
2013-06-27 10:47:58 +02:00
%{_bindir}/ipa-test-task
2013-05-21 13:40:27 +02:00
%{python_sitelib}/ipatests-*.egg-info
2013-08-13 18:32:36 +02:00
%{_mandir}/man1/ipa-run-tests.1.gz
%{_mandir}/man1/ipa-test-config.1.gz
%{_mandir}/man1/ipa-test-task.1.gz
2013-08-13 10:56:26 +02:00
%endif # ONLY_CLIENT
2013-05-21 13:40:27 +02:00
2009-02-02 13:50:53 -05:00
%changelog
2013-11-26 13:06:07 +01:00
* Tue Nov 26 2013 Petr Viktorin<pviktori@redhat.com> - __VERSION__-__RELEASE__
- Remove changelog. The history is kept in Git, downstreams have own logs.
# note, this entry is here to placate tools that expect a non-empty changelog