Commit Graph

7489 Commits

Author SHA1 Message Date
Timo Aaltonen
f51172de38 push to trusty 2014-08-06 12:19:31 +03:00
Timo Aaltonen
a579731747 release to utopic 2014-08-05 19:00:54 +03:00
Timo Aaltonen
b511b286a5 add-debian-platform.diff: Let testing chronyd always return false, since the package already conflicts with ntp so can't be installed/enabled at the same time. 2014-08-05 18:27:20 +03:00
Timo Aaltonen
8bce40d258 fix-ntp-paths.diff: Don't use fedora paths for ntpd options. (LP: #1309655) 2014-08-05 18:24:18 +03:00
Timo Aaltonen
d6c82e1baa release to trusty 2014-04-10 11:58:13 +03:00
Timo Aaltonen
0151cc8e41 Merge branch 'master' into ubuntu 2014-04-10 11:57:38 +03:00
Timo Aaltonen
35665bb738 fix a typo in auth.py 2014-04-10 11:57:19 +03:00
Timo Aaltonen
6d1db97cfd update use-new-nssdb.diff 2014-04-10 11:33:13 +03:00
Timo Aaltonen
81869f54eb fix auth module some more 2014-04-10 11:01:35 +03:00
Timo Aaltonen
0cad65e728 add etc/ipa to freeipa-client.dirs 2014-04-04 12:20:17 +03:00
Timo Aaltonen
c2cc0d9687 update the changelog 2014-04-04 12:05:28 +03:00
Timo Aaltonen
4271e4f9e8 Merge branch 'debian-unstable' into ubuntu 2014-04-04 11:46:42 +03:00
Timo Aaltonen
aba9456fa1 add fix-pykerberos-api.diff 2014-04-04 11:18:28 +03:00
Timo Aaltonen
7938cb1287 enable auth module now that it's fixed 2014-04-04 11:07:13 +03:00
Timo Aaltonen
f897fe6dbe control: Add python-dnspython and python-ldap to python-freeipa Depends. 2014-04-04 10:31:06 +03:00
Timo Aaltonen
433db4d2eb fix build-depend on libxmlrpc-core-c3-dev 2014-03-19 18:59:26 +02:00
Timo Aaltonen
f2d92541ac add a patch from upstream to fix ftbfs 2014-03-11 23:46:29 +02:00
Timo Aaltonen
01df214998 add libkrad-dev to build-depends 2014-03-11 17:45:33 +02:00
Timo Aaltonen
924bbdaa63 Merge branch 'debian-unstable' into ubuntu 2014-03-11 17:22:34 +02:00
Timo Aaltonen
4d57140a6d disable auth setup, doesn't work yet 2014-03-11 17:22:18 +02:00
Timo Aaltonen
e631345f07 add keyutils to python-freeipa depends. 2014-03-11 14:06:44 +02:00
Timo Aaltonen
530b64ec56 don't install an empty default.conf 2014-03-11 12:09:30 +02:00
Timo Aaltonen
24f69d1f68 use-new-nssdb.diff: Use sqlite-based nssdb's instead of old. 2014-03-11 11:48:23 +02:00
Timo Aaltonen
55012dacb5 fix python includes in platform 2014-03-01 01:13:00 +02:00
Timo Aaltonen
aa69aa3d22 release to trusty 2014-02-18 21:24:59 +02:00
Timo Aaltonen
396f04e5a5 Merge branch 'debian-unstable' into ubuntu
Conflicts:
	debian/changelog
	debian/control
2014-02-18 16:26:19 +02:00
Timo Aaltonen
dd379e8d5d update/drop patches 2014-02-18 16:16:28 +02:00
Timo Aaltonen
9ab7db1821 bump the version 2014-02-18 16:11:22 +02:00
Timo Aaltonen
d6a2f9b537 Merge branch 'upstream-unstable' into debian-unstable 2014-02-18 16:10:52 +02:00
Martin Kosek
e183f2f243 Become IPA 3.3.4 2014-01-28 12:06:55 +01:00
Martin Basti
00a4ad2c34 Added warning if cert '/etc/ipa/ca.crt' exists
https://fedorahosted.org/freeipa/ticket/3944
2014-01-27 15:21:59 +01:00
Timo Aaltonen
98dcd6fd2d add freeipa-server-trust-ad and freeipa-tests packages, modify -server & -admintools installs, drop tomcat6 from depends 2014-01-24 17:36:54 +02:00
Martin Kosek
2fbb14d3c0 ntpconf: remove redundant comment
https://fedorahosted.org/freeipa/ticket/4094
2014-01-24 14:40:29 +01:00
Jan Cholasta
a744b5e53b Fix ntpd config on clients.
https://fedorahosted.org/freeipa/ticket/4094
2014-01-24 13:01:40 +01:00
Sumit Bose
17d6f27da3 CLDAP: add unit tests for make_netbios_name 2014-01-23 18:14:29 +01:00
Sumit Bose
c57ff0a9aa CLDAP: generate NetBIOS name like ipa-adtrust-install does
Fixes  https://fedorahosted.org/freeipa/ticket/4116
2014-01-23 18:14:29 +01:00
Alexander Bokovoy
897e1415ce ipasam: delete trusted child domains before removing the trust
LDAP protocol doesn't allow deleting non-leaf entries. One needs to
remove all leaves first before removing the tree node.

https://fedorahosted.org/freeipa/ticket/4126
2014-01-21 12:32:02 +01:00
Petr Vobornik
bf440ba479 Trust domains Web UI
Add Web UI counterpart of following CLI commands:

* trust-fetch-domains Refresh list of the domains associated with the trust
* trustdomain-del Remove infromation about the domain associated with the trust.
* trustdomain-disable Disable use of IPA resources by the domain of the trust
* trustdomain-enable Allow use of IPA resources by the domain of the trust
* trustdomain-find Search domains of the trust

https://fedorahosted.org/freeipa/ticket/4119
2014-01-21 12:25:01 +01:00
Martin Kosek
014ccb13b6 Hide trust-resolve command
We do not need to expose a public FreeIPA specific interface to resolve
SIDs to names. The interface is only used internally to resolve SIDs
when external group members are listed. Additionally, the command interface
is not prepared for regular user and can give rather confusing results.

Hide it from CLI. The API itself is still accessible and compatible with
older clients.

https://fedorahosted.org/freeipa/ticket/4113
2014-01-20 18:24:16 +01:00
Tomas Babej
cfaaeb9dad ipatests: Check for legacy_client attribute presence if unapplying fixes
When legacy client tests fail during IPA installation, the legacy
client test produces an additional misleading error
(the real cause is reported as well). This happens due the fact
that we try to cleanup host that was not yet defined. We need to
check for this attribute being defined before unapplying fixes there.

https://fedorahosted.org/freeipa/ticket/4124
2014-01-20 15:35:43 +01:00
Tomas Babej
dc1a1189e1 ipatests: Remove sudo calls from tasks
Sudo calls are not necessary since we log in as a root. Additionally,
sudo requires tty in default configuration, which is not acquired
when using OpenSSH transport.

https://fedorahosted.org/freeipa/ticket/4125
2014-01-20 15:32:46 +01:00
Alexander Bokovoy
4679a3b8d3 ipa-adtrust-install: configure host netbios name by default
Ensure we set host netbios name by default in smb.conf

https://fedorahosted.org/freeipa/ticket/4116
2014-01-20 10:35:13 +01:00
Petr Vobornik
1f6322f109 Remove SID resolve call from Web UI
- it's called in group-show

https://bugzilla.redhat.com/show_bug.cgi?id=1054391
https://fedorahosted.org/freeipa/ticket/4123
2014-01-20 09:50:56 +01:00
Alexander Bokovoy
da5545d781 group-show: resolve external members of the groups
Perform SID to name conversion for existing external members of the
groups if trust is configured.

https://bugzilla.redhat.com/show_bug.cgi?id=1054391
https://fedorahosted.org/freeipa/ticket/4123
2014-01-20 09:49:03 +01:00
Jan Cholasta
876a00a8da Increase service startup timeout default.
https://fedorahosted.org/freeipa/ticket/4078
2014-01-17 10:12:13 +01:00
Martin Kosek
f9ee6add28 Remove missing VERSION warning in dnsrecord-mod
dnsrecord-mod may call dnsrecord-delentry command when all records
are deleted. However, the version was not passwd to delentry and
it resulted in a warning.

https://fedorahosted.org/freeipa/ticket/4120
2014-01-17 09:30:00 +01:00
Petr Viktorin
90b31e99fe cli.print_attribute: Convert values to strings
When output_for_cli was called directly, rather than for values
received through XML or JSON API, joining multiple values failed
on non-strings such as DN objects.

Convert output to strings before printing it out.
2014-01-17 09:58:18 +02:00
Simo Sorce
50a6430dbd Stop adding a default password policy reference
Both the password plugin and the kdb driver code automatically fall
back to the default password policy.
so stop adding an explicit reference to user objects and instead rely on the
fallback.
This way users created via the framework and users created via winsync plugin
behave the same way wrt password policies and no surprises will happen.

Also in case we need to change the default password policy DN this will allow
just code changes instead of having to change each user entry created, and
distinguish between the default policy and explicit admin changes.

Related: https://fedorahosted.org/freeipa/ticket/4085

Patch backported/updated by Martin Kosek to accomodate different ipatests
structure in ipa-3-3 branch.
2014-01-16 09:10:16 +01:00
Simo Sorce
cd3715a013 Harmonize policy discovery to kdb driver
The KDB driver does not walk the tree back like the original password plugin.
Also we do not store the default policy in the base DN as we used to do in the
past anymore.
So doing a full subtree search and walking back the tree is just a waste of
time.
Instead hardcode the default policy like we do in the kdb driver.

Fixes: https://fedorahosted.org/freeipa/ticket/4085
2014-01-16 09:01:20 +01:00
Jan Cholasta
8e874b1ede Do not start the service in stopped_service if it was not running before.
This fixes a possible NSS database corruption in renew_ca_cert.
2014-01-15 17:44:15 +01:00