Stanislav Laznicka
6c74bd2bcc
Removed unused method parameter from migrate-ds
...
An extra parameter on client side command override of migrate-ds output
was causing errors.
https://fedorahosted.org/freeipa/ticket/6034
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2016-07-13 18:40:22 +02:00
Stanislav Laznicka
235b19ba7f
service: Added permissions for auth. indicators read/modify
...
Added permissions for Kerberos authentication indicators reading and
modifying to service objects.
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
2016-06-30 16:44:56 +02:00
Stanislav Laznicka
97db87b383
host: Added permissions for auth. indicators read/modify
...
Added permissions for Kerberos authentication indicators reading and
modifying to host objects.
https://fedorahosted.org/freeipa/ticket/433
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
2016-06-30 16:44:56 +02:00
Stanislav Laznicka
f3858be6e3
Fix wrong imports in copy-schema-to-ca.py
...
Some imports were not possible in old versions of IPA. This caused
import exceptions on the script start.
https://fedorahosted.org/freeipa/ticket/6003
Reviewed-By: Petr Spacek <pspacek@redhat.com >
2016-06-30 14:28:14 +02:00
Stanislav Laznicka
427bbf6c0d
The LDAP*ReverseMember shouldn't imply --all is always specified
...
The LDAP*ReverseMember methods would always return the whole LDAP
object even though --all is not specified.
Also had to fix some tests as objectClass will not be returned by
default now.
https://fedorahosted.org/freeipa/ticket/5892
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2016-06-29 10:44:30 +02:00
Stanislav Laznicka
30d054a573
Revert "Removed dead code from LDAP{Remove,Add}ReverseMember"
...
While the code was really dead, it should serve a purpose elsewhere.
This reverts commit c56d65b064 .
https://fedorahosted.org/freeipa/ticket/5892
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2016-06-29 10:44:30 +02:00
Stanislav Laznicka
e136db0192
Add missing nsSystemIndex attributes
...
https://fedorahosted.org/freeipa/ticket/5947
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-06-27 10:49:51 +02:00
Stanislav Laznicka
13328bc751
topo segment-add: validate that both masters support target suffix
...
This patch removes the ability to add segment between hosts where
either does not support the requested suffix.
https://fedorahosted.org/freeipa/ticket/5967
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
2016-06-24 13:32:02 +02:00
Stanislav Laznicka
5b5258b010
Fix topologysuffix-verify failing connections
...
topologysuffix-verify would have checked connectivity even between hosts that
are not managed by the given suffix.
https://fedorahosted.org/freeipa/ticket/5967
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
2016-06-24 13:32:02 +02:00
Stanislav Laznicka
0db48e4d04
Fix to ipa-ca-install asking for host principal password
...
With a ca_cert_file specified in options, the nss_db was used before the
certificates from the file were added to it, which caused an exception
that led to fallback to ssh which is broken.
https://fedorahosted.org/freeipa/ticket/5965
Reviewed-By: Martin Basti <mbasti@redhat.com >
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2016-06-23 12:26:20 +02:00
Stanislav Laznicka
9a8c5c9dfd
host/service-show/find shouldn't fail on invalid certificate
...
host/service-show/find methods would have failed if the first
certificate they had in userCertificate attribute were invalid.
Expected behavior is that they just show the rest of the reqested
attributes.
https://fedorahosted.org/freeipa/ticket/5797
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-06-22 17:43:14 +02:00
Stanislav Laznicka
8e3b7b24c1
Increase nsslapd-db-locks to 50000
...
Sometimes the lock table would run out of available locks. This should
improve the lock table default configuration.
https://fedorahosted.org/freeipa/ticket/5914
Reviewed-By: Martin Basti <mbasti@redhat.com >
Reviewed-By: Thierry Bordaz <tbordaz@redhat.com >
2016-06-15 18:14:02 +02:00
Stanislav Laznicka
fb4e19713d
Fixes CA always being presented as running
...
Even after manually stopping the pki-tomcatd service instance the
service's is_running() method would still return True.
https://fedorahosted.org/freeipa/ticket/5898
Reviewed-By: Martin Basti <mbasti@redhat.com >
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2016-06-15 18:11:28 +02:00
Stanislav Laznicka
c56d65b064
Removed dead code from LDAP{Remove,Add}ReverseMember
...
https://fedorahosted.org/freeipa/ticket/5892
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-06-06 18:26:14 +02:00
Stanislav Laznicka
2026677635
Added krb5.conf.d/ to included dirs in krb5.conf
...
The include of /etc/krb5.conf.d/ is required for crypto-policies to work properly
https://fedorahosted.org/freeipa/ticket/5912
Reviewed-By: Martin Basti <mbasti@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2016-06-05 09:47:13 +02:00
Stanislav Laznicka
0492ab9c0a
Remove dangling RUVs even if replicas are offline
...
Previously, an offline replica would mean the RUVs cannot
be removed otherwise the task would be hanging in the DS.
This is fixed in 389-ds 1.3.5.
https://fedorahosted.org/freeipa/ticket/5396
Reviewed-By: Martin Basti <mbasti@redhat.com >
Reviewed-By: Ludwig Krispenz <lkrispen@redhat.com >
2016-06-03 15:22:00 +02:00
Stanislav Laznicka
72f5c52d8c
fixes premature sys.exit in ipa-replica-manage del
...
Deletion of a replica would fail should there
be no RUVs on the server.
Also removed some dead code in del_master_managed which might
cause premature exit if RuntimeError occurs.
https://fedorahosted.org/freeipa/ticket/5307
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-06-03 14:48:19 +02:00
Stanislav Laznicka
e9f0e9d8fa
Decreased timeout for IO blocking for DS
...
Should fix the DS from going unresponsive in some cases
https://fedorahosted.org/freeipa/ticket/5383
Reviewed-By: Thierry Bordaz <tbordaz@redhat.com >
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-06-02 20:20:28 +02:00
Stanislav Laznicka
f0160a2ed2
Added <my_hostname>=<IPA REALM> mapping to krb5.conf
...
https://fedorahosted.org/freeipa/ticket/5903
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-06-02 20:09:36 +02:00
Stanislav Laznicka
12d8a0cf22
Increased mod_wsgi socket-timeout
...
Longer-running CLI commands sometimes fail with "gateway time out" although
the task still runs and finishes on server, not notifying the CLI back.
Increasing socket-timeout should solve this.
https://fedorahosted.org/freeipa/ticket/5833
Reviewed-By: Martin Basti <mbasti@redhat.com >
Reviewed-By: Petr Spacek <pspacek@redhat.com >
2016-06-02 19:26:32 +02:00
Stanislav Laznicka
3076cb9dcc
Deprecated the domain-level option in ipa-server-install
...
https://fedorahosted.org/freeipa/ticket/5907
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-06-02 19:04:18 +02:00
Stanislav Laznicka
1ce63e6193
Added some attributes to Modify Users permission
...
Added 'employeenumber', 'departmentnumber' and 'mail' to Modify Users
permission
https://fedorahosted.org/freeipa/ticket/5911#comment:2
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-05-29 14:13:12 +02:00
Stanislav Laznicka
c91d809933
Added pyusb as a dependency
...
https://fedorahosted.org/freeipa/ticket/5886
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-05-28 16:19:46 +02:00
Stanislav Laznicka
7098d98100
Fix to clean-dangling-ruv for single CA topologies
...
clean-dangling-ruv would fail in topologies with only one CA or
when only one IPA server is present
https://fedorahosted.org/freeipa/ticket/5840
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-05-10 17:31:25 +02:00
Stanislav Laznicka
c34af691de
Moved password check from clean_dangling_ruv
...
The proper password check is now done elsewhere
https://fedorahosted.org/freeipa/ticket/4987
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-04-28 17:32:14 +02:00
Stanislav Laznicka
ee05442e5d
abort-clean/list/clean-ruv now work for both suffixes
...
The rid passed to abort-clean-ruv and clean-ruv is now searched
for in both ipaca and domain trees as well as list-ruv now
displays both RUVs and CS-RUVs
https://fedorahosted.org/freeipa/ticket/4987
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-04-28 17:32:14 +02:00
Stanislav Laznicka
d2bb8b7bb1
ipa-replica-manage refactoring
...
get_ruv does not call sys.exit anymore, instead it raises RuntimeError
for better error handling
Also removed duplicit code from abort_clean_ruv
https://fedorahosted.org/freeipa/ticket/4987
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-04-28 17:32:14 +02:00
Stanislav Laznicka
37865aa1d7
replica-manage: fail nicely when DM psswd required
...
Some commands do not allow anonymous bind and would fail with
misleading message.
https://fedorahosted.org/freeipa/ticket/4987
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-04-28 17:32:14 +02:00
Stanislav Laznicka
d7efd8a33a
Fixes minor issues
...
Fixes issues discovered by Coverity
plugins/baseldap.py: possible undefined value in return
certmonger.py: possible dereference of None value
i18n.py: fixed always True bug (+ cosmetic change)
https://fedorahosted.org/freeipa/ticket/5661
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-02-24 09:21:30 +01:00
Stanislav Laznicka
9757384c7c
Cosmetic changes to the code
...
Fixes some Coverity issues
ipadiscovery.py: added assert should universe break
plugins/dns.py: removed dead code
dnssec/ldapkeydb.py: attribute assert in the proper object
test_automount_plugin.py: fixed possible close() on None
xmlrpc_test.py: Coverity does not like accessing None.__class__
https://fedorahosted.org/freeipa/ticket/5661
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-02-24 09:21:30 +01:00
Stanislav Laznicka
c8eabaff9e
Automatically detect and remove dangling RUVs
...
https://fedorahosted.org/freeipa/ticket/5411
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-02-02 12:22:37 +01:00
Stanislav Laznicka
bb7887140d
Listing and cleaning RUV extended for CA suffix
...
https://fedorahosted.org/freeipa/ticket/5411
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-02-02 12:22:37 +01:00
Stanislav Laznicka
498471e4ae
Removed duplicate domain name validating function
...
Reviewed-By: Martin Basti <mbasti@redhat.com >
2015-12-02 17:26:56 +01:00
Stanislav Laznicka
9d562038ad
Fixes disappearing automember expressions
...
https://fedorahosted.org/freeipa/ticket/5353
Reviewed-By: Tomas Babej <tbabej@redhat.com >
2015-10-14 12:31:51 +02:00
Stanislav Laznicka
592e437fc7
ipa-client-install: warn when IP used in --server
...
ipa-client-install fails when an IP address is passed
to ipa-join instead of a FQDN
https://fedorahosted.org/freeipa/ticket/4932
Reviewed-By: Martin Basti <mbasti@redhat.com >
2015-08-14 11:03:04 +02:00