Christian Heimes
6fde06ac30
Fix compiler warning in ipa-pwd-extop
...
cast const error message to non-const char*. I tried to make errMesg a
const char* but it gets passed down to slapi_send_ldap_result() which
accepts a char*.
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-26 10:43:42 +03:00
Christian Heimes
4e30a48d3c
trust-add: Catch correct exception when chown SSSD
...
Commit 72fb4e6 introduced a regression. SSSD_USER.chown() raises
ValueError instead of KeyError when SSSD user does not exist.
Fixes: https://pagure.io/freeipa/issue/8516
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Florence Blanc-Renaud <flo@redhat.com >
2020-09-26 10:41:32 +03:00
Emilio Herrera
4cc9c942d1
Translated using Weblate (Spanish)
...
Currently translated at 60.8% (2845 of 4676 strings)
Translated using Weblate (Spanish)
Currently translated at 60.8% (2844 of 4676 strings)
Co-authored-by: Emilio Herrera <ehespinosa57@gmail.com >
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/es/
Translation: freeipa/master
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-26 10:25:19 +03:00
Oğuz Ersen
0464a5ffff
Translated using Weblate (Turkish)
...
Currently translated at 7.6% (358 of 4676 strings)
Co-authored-by: Oğuz Ersen <oguzersen@protonmail.com >
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/tr/
Translation: freeipa/master
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-26 10:25:19 +03:00
Yuri Chornoivan
abc416407e
Translated using Weblate (Ukrainian)
...
Currently translated at 100.0% (4676 of 4676 strings)
Translated using Weblate (Ukrainian)
Currently translated at 100.0% (4676 of 4676 strings)
Co-authored-by: Yuri Chornoivan <yurchor@ukr.net >
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/uk/
Translation: freeipa/master
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-26 10:25:19 +03:00
Weblate
afa0f5d187
Update translation files
...
Updated by "Update PO files to match POT (msgmerge)" hook in Weblate.
Co-authored-by: Weblate <noreply@weblate.org >
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/
Translation: freeipa/master
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-26 10:25:19 +03:00
Daniel Lara Souza
11828cf87c
Translated using Weblate (Portuguese (Brazil))
...
Currently translated at 3.5% (167 of 4654 strings)
Co-authored-by: Daniel Lara Souza <daniellarasouza@yahoo.com.br >
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/pt_BR/
Translation: freeipa/master
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-26 10:25:19 +03:00
Weblate
90c1a00f04
Update translation files
...
Updated by "Update PO files to match POT (msgmerge)" hook in Weblate.
Co-authored-by: Weblate <noreply@weblate.org >
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/
Translation: freeipa/master
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-26 10:25:19 +03:00
Yuri Chornoivan
a330adae8a
Translated using Weblate (Ukrainian)
...
Currently translated at 100.0% (4654 of 4654 strings)
Translated using Weblate (Ukrainian)
Currently translated at 98.8% (4600 of 4654 strings)
Co-authored-by: Yuri Chornoivan <yurchor@ukr.net >
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/uk/
Translation: freeipa/master
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-26 10:25:19 +03:00
Weblate
89d8518266
Update translation files
...
Updated by "Update PO files to match POT (msgmerge)" hook in Weblate.
Update translation files
Updated by "Update PO files to match POT (msgmerge)" hook in Weblate.
Co-authored-by: Weblate <noreply@weblate.org >
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/
Translation: freeipa/master
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-26 10:25:19 +03:00
Rafael Fontenelle
1eaa5974e4
Translated using Weblate (Portuguese (Brazil))
...
Currently translated at 3.2% (153 of 4654 strings)
Co-authored-by: Rafael Fontenelle <rafaelff@gnome.org >
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/pt_BR/
Translation: freeipa/master
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-26 10:25:19 +03:00
Weblate
a2f7e917a1
Update translation files
...
Updated by "Update PO files to match POT (msgmerge)" hook in Weblate.
Update translation files
Updated by "Update PO files to match POT (msgmerge)" hook in Weblate.
Co-authored-by: Weblate <noreply@weblate.org >
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/
Translation: freeipa/master
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-26 10:25:19 +03:00
Oğuz Ersen
54dff05cd2
Translated using Weblate (Turkish)
...
Currently translated at 7.6% (357 of 4654 strings)
Translation: freeipa/master
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/tr/
Translated using Weblate (Turkish)
Currently translated at 7.3% (342 of 4654 strings)
Translation: freeipa/master
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/tr/
Translated using Weblate (Turkish)
Currently translated at 4.6% (216 of 4654 strings)
Translation: freeipa/master
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/tr/
Translated using Weblate (Turkish)
Currently translated at 0.7% (34 of 4654 strings)
Translation: freeipa/master
Translate-URL: https://translate.fedoraproject.org/projects/freeipa/master/tr/
Added translation using Weblate (Turkish)
Co-authored-by: Oğuz Ersen <oguzersen@protonmail.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-26 10:25:19 +03:00
Christian Heimes
69ebe41525
Fix nsslapd-db-lock tuning of BDB backend
...
nsslapd-db-lock was moved from cn=config,cn=ldbm database,cn=plugins,cn=config
entry to cn=bdb subentry. Manual patching of dse.ldif was no longer
working. Installations with 389-DS 1.4.3 and newer are affected.
Low lock count can affect performance during high load, e.g. mass-import
of users or lots of concurrent connections.
Bump minimal DS version to 1.4.3. Fedora 32 and RHEL 8.3 have 1.4.3.
Fixes: https://pagure.io/freeipa/issue/8515
See: https://pagure.io/freeipa/issue/5914
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Francois Cami <fcami@redhat.com >
2020-09-24 17:03:00 +02:00
Serhii Tsymbaliuk
29b41aef0a
WebUI: Fix jQuery DOM manipulation issues
...
The commit includes the following jQuery patches:
- Manipulation: Make jQuery.htmlPrefilter an identity function
(https://github.com/jquery/jquery/pull/4642 )
- Manipulation: Skip the select wrapper for <option> outside of IE 9
(https://github.com/jquery/jquery/pull/4647 )
In addition there is included a script that helps to patch and build
the new version of jQuery:
$ install/ui/util/make-jquery.js 3.4.1
Ticket: https://pagure.io/freeipa/issue/8507
Signed-off-by: Serhii Tsymbaliuk <stsymbal@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-24 16:21:04 +02:00
Rob Crittenden
b47ddb0186
Reduce the memory requirement from 1.6 to 1.2 GB
...
We know from practical experience in PR-CI and Azure that 1.2
is the absolute minimum necessary for a base installation.
https://pagure.io/freeipa/issue/8404
Signed-off-by: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
2020-09-24 08:20:48 +02:00
Christian Heimes
79b9982b86
Create systemd-resolved configuration on update
...
Create systemd-resolved drop-in and restart the service when the drop-in
config file is missing and /etc/resolv.conf points to stub resolver
config file.
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-23 16:44:26 +02:00
Christian Heimes
d12f1b4b39
Configure systemd-resolved to use IPA's BIND
...
IPA installer now instructs systemd-resolved to use IPA's BIND DNS
server as primary DNS server.
Fixes: https://pagure.io/freeipa/issue/8275
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-23 16:44:26 +02:00
Christian Heimes
528c519cb5
Use new API for auto-forwarders
...
Auto-forwarders and manual configuration now use the new API to get a
list of DNS servers. Manual installer refuses loopback, too.
See: https://pagure.io/freeipa/issue/8275
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-23 16:44:26 +02:00
Christian Heimes
e64f27fdf8
Configure NetworkManager to use systemd-resolved
...
zzz-ipa.conf now enables NetworkManager's systemd-resolved plugin when
systemd-resolved is detected.
See: https://pagure.io/freeipa/issue/8275
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-23 16:44:26 +02:00
Christian Heimes
96edff0b8c
Add helpers for resolve1 and nameservers
...
detect_resolve1_resolv_conf() detects if systemd-resolved is enabled and
manages /etc/resolv.conf.
get_resolve1_nameservers() gets upstream DNS servers from
systemd-resolved's D-Bus interface.
get_dnspython_nameservers() gets upstream DNS servers from
/etc/resolv.conf via dns.python.
get_nameservers() gets a list of unique, non-loopback DNS server IP
addresses.
Also fixes setup.py to include D-Bus for ipalib instead of ipapython.
See: https://pagure.io/freeipa/issue/8275
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-23 16:44:26 +02:00
Zdenek Pytela
7651d335b3
Add ipa_pki_retrieve_key_exec() interface
...
The ipa_pki_retrieve_key_exec() interface is needed to allow other
domains execute ipa-pki-retrieve-key.
Related: https://pagure.io/freeipa/issue/8488
Signed-off-by: Zdenek Pytela <zpytela@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
2020-09-23 15:23:28 +02:00
Christian Heimes
644bd0e46b
Make git a build requirement
...
FreeIPA uses git in its build process. In the past git was automatically
pulled in. On Fedora 33 builds are failing because git is missing.
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
2020-09-23 14:49:56 +02:00
Christian Heimes
80fca8d701
Delay import of psutil to avoid AVC
...
Commit cfad7af35d added a check to ensure a
system has sufficient amount of memory. The feature uses psutil to get
available memory. On import psutil opens files in /proc which can result in
an SELinux violations and Python exception.
PermissionError: [Errno 13] Permission denied: '/proc/stat'
Fixes: https://pagure.io/freeipa/issue/8512
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2020-09-23 14:49:15 +02:00
Rob Crittenden
9f9dcfe88a
Test that ccaches are cleaned up during installation
...
Create a random file and directory in the ccaches directory
prior to installation then confirm that they were removed.
https://pagure.io/freeipa/issue/8248
Signed-off-by: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
2020-09-23 14:48:29 +02:00
Rob Crittenden
cc5d9a8c9d
Clean up entire /run/ipa/ccaches directory not just files
...
If there are any sub-directories in the ccaches directory
then cleaning it up will fail.
Instead remove the whole directory and allow systemd-tmpfiles
to re-create it.
https://pagure.io/freeipa/issue/8248
Signed-off-by: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
2020-09-23 14:48:29 +02:00
François Cami
36c6a2e749
SELinux: do not double-define node_t and pki_tomcat_cert_t
...
node_t and pki_tomcat_cert_t are defined in other modules.
Do not double-define them.
Fixes: https://pagure.io/freeipa/issue/8513
Signed-off-by: François Cami <fcami@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
2020-09-23 14:47:06 +02:00
Rob Crittenden
84bbf68781
Require a matching server package for the selinux subpackage
...
Ensure that the selinux subpackage is upgraded along with the
rest of IPA if it is built.
https://pagure.io/freeipa/issue/8511
Signed-off-by: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Francois Cami <fcami@redhat.com >
2020-09-22 19:30:03 -04:00
François Cami
2f2bce4310
SELinux Policy: Allow tomcat_t to read kerberos keytabs
...
This is required to fix:
avc: denied { search } for pid=1930 comm="ipa-pki-retriev" name="krb5" dev="dm-0" ino=8620822 scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:krb5_keytab_t:s0 tclass=dir permissive=0
Macros suggested by: Ondrej Mosnacek
Fixes: https://pagure.io/freeipa/issue/8488
Signed-off-by: François Cami <fcami@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Ondrej Mosnacek <omosnace@redhat.com >
Reviewed-By: Lukas Vrabec <lvrabec@redhat.com >
Reviewed-By: Zdenek Pytela <zpytela@redhat.com >
Reviewed-By: Thomas Woerner <twoerner@redhat.com >
2020-09-22 18:05:38 +02:00
François Cami
f774642b63
SELinux Policy: make interfaces for kernel modules non-optional
...
Interfaces for kernel modules do not need to be in an optional module.
Also make sure ipa_custodia_t can log.
Suggested by Lukas Vrabec.
Fixes: https://pagure.io/freeipa/issue/8488
Signed-off-by: François Cami <fcami@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Ondrej Mosnacek <omosnace@redhat.com >
Reviewed-By: Lukas Vrabec <lvrabec@redhat.com >
Reviewed-By: Zdenek Pytela <zpytela@redhat.com >
Reviewed-By: Thomas Woerner <twoerner@redhat.com >
2020-09-22 18:05:38 +02:00
François Cami
4b3c4b84d4
SELinux Policy: flag ipa_pki_retrieve_key_exec_t as domain_type
...
Fixes: https://pagure.io/freeipa/issue/8488
Signed-off-by: François Cami <fcami@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Ondrej Mosnacek <omosnace@redhat.com >
Reviewed-By: Lukas Vrabec <lvrabec@redhat.com >
Reviewed-By: Zdenek Pytela <zpytela@redhat.com >
Reviewed-By: Thomas Woerner <twoerner@redhat.com >
2020-09-22 18:05:38 +02:00
François Cami
09816f4dbc
SELinux Policy: ipa_custodia_pki_tomcat_exec_t => ipa_custodia_pki_tomcat_t
...
ipa_custodia_pki_tomcat_exec_t was granted java_exec by mistake ; replace by
ipa_custodia_pki_tomcat_t.
As suggested by Ondrej Mosnáček.
Fixes: https://pagure.io/freeipa/issue/8488
Signed-off-by: François Cami <fcami@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Ondrej Mosnacek <omosnace@redhat.com >
Reviewed-By: Lukas Vrabec <lvrabec@redhat.com >
Reviewed-By: Zdenek Pytela <zpytela@redhat.com >
Reviewed-By: Thomas Woerner <twoerner@redhat.com >
2020-09-22 18:05:38 +02:00
François Cami
820beca4ac
SELinux Policy: ipa_pki_retrieve_key_exec_t => ipa_pki_retrieve_key_t
...
Grant pki_manage_tomcat_etc_rw to ipa_pki_retrieve_key_t instead of
ipa_pki_retrieve_key_exec_t.
As suggested by Ondrej Mosnáček.
Fixes: https://pagure.io/freeipa/issue/8488
Signed-off-by: François Cami <fcami@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Ondrej Mosnacek <omosnace@redhat.com >
Reviewed-By: Lukas Vrabec <lvrabec@redhat.com >
Reviewed-By: Zdenek Pytela <zpytela@redhat.com >
Reviewed-By: Thomas Woerner <twoerner@redhat.com >
2020-09-22 18:05:38 +02:00
François Cami
ea9db4a903
SELinux Policy: let custodia_t map custodia_tmp_t
...
This is used by the JVM perf counters.
Related: https://pagure.io/freeipa/issue/8488
Signed-off-by: François Cami <fcami@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Ondrej Mosnacek <omosnace@redhat.com >
Reviewed-By: Lukas Vrabec <lvrabec@redhat.com >
Reviewed-By: Zdenek Pytela <zpytela@redhat.com >
Reviewed-By: Thomas Woerner <twoerner@redhat.com >
2020-09-22 18:05:38 +02:00
François Cami
7823da0630
SELinux: Add dedicated policy for ipa-pki-retrieve-key
...
Add proper labeling, transition and policy for ipa-pki-retrieve-key.
Make sure tomcat_t can execute ipa-pki-retrieve-key.
Fixes: https://pagure.io/freeipa/issue/8488
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Signed-off-by: François Cami <fcami@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Ondrej Mosnacek <omosnace@redhat.com >
Reviewed-By: Lukas Vrabec <lvrabec@redhat.com >
Reviewed-By: Zdenek Pytela <zpytela@redhat.com >
Reviewed-By: Thomas Woerner <twoerner@redhat.com >
2020-09-22 18:05:38 +02:00
François Cami
dfeea1644a
ipatests: enhance TestSubCAkeyReplication
...
enhance the test suite so that it covers:
- deleting subCAs (disabling them first)
- checking what happens when creating a dozen+ subCAs at a time
- adding a subCA that already exists and expect failure
Related: https://pagure.io/freeipa/issue/8488
Signed-off-by: François Cami <fcami@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Ondrej Mosnacek <omosnace@redhat.com >
Reviewed-By: Lukas Vrabec <lvrabec@redhat.com >
Reviewed-By: Zdenek Pytela <zpytela@redhat.com >
Reviewed-By: Thomas Woerner <twoerner@redhat.com >
2020-09-22 18:05:38 +02:00
Christian Heimes
bc128cae47
Add User and Group to all ipaplatform.constants
...
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
2020-09-22 09:23:18 -04:00
Christian Heimes
b19d20e2db
Use new classes for run_command and Service
...
User and Group now return unmodified instance when they are called with
an instance of themselves: User(user) is user.
run_command() and Service class accept either names or User object.
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
2020-09-22 09:23:18 -04:00
Christian Heimes
72fb4e60c8
Add user and group wrappers
...
New classes for user and group names provide a convenient way to access
the uid and primary gid of a user / gid of a group. The classes also
provide chown() and chgrp() methods to simplify common operations.
The wrappers are subclasses of builtin str type and behave like ordinary
strings with additional features. The pwd and grp structs are retrieved
once and then cached.
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
2020-09-22 09:23:18 -04:00
Christian Heimes
99a40cbbe9
Simplify LDAPUpdater
...
- drop unused dm_password and ldapi arguments
- remove online feature that was never implemented
- allow passing of api object that is used to populate substitution
dictionary
- simplify substitution dictionary updates
- remove unused instances vars
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
2020-09-22 09:21:00 -04:00
Christian Heimes
87cf2a3c78
Add ldap_update() helper to service class
...
The new _ldap_update() helper methods makes it easier to apply LDAP
update files from a service instance.
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
2020-09-22 09:21:00 -04:00
Christian Heimes
3c86baf0ad
Don't create DS SSCA and self-signed cert
...
Instruct lib389 to not create its self-signed CA and temporary
self-signed certificate. FreeIPA uses local connections and Unix socket
for bootstrapping.
Fixes: https://pagure.io/freeipa/issue/8502
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
2020-09-21 18:13:51 -04:00
Florence Blanc-Renaud
8ba15027d4
test_smb: skip test_smb_service_s4u2self for fed31
...
The test test_integration/test_smb.py::TestSMB::test_smb_service_s4u2self
is expected to fail in Fedora <= 31 as it requires krb >= 1.18
that is shipped from fedora 32 only.
Skip the test depending on the fedora version.
Fixes: https://pagure.io/freeipa/issue/8505
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
2020-09-21 18:12:03 -04:00
Christian Heimes
b606fa6cca
Duplicate CA CRT: ignore expected cert
...
When search for duplicate CA certs ignore the one expected entry.
Related: https://pagure.io/freeipa/issue/7125
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Florence Blanc-Renaud <frenaud@redhat.com >
2020-09-18 14:20:08 -04:00
Fraser Tweedale
c0461eb37c
spec: require pki-acme if pki-ca >= 10.10
...
We can use conditional dependencies (described at [1]) to require
the pki-acme package if pki-ca >= 10.10.0 (the version at which the
ACME service was separated to a subpackage).
[1] https://rpm.org/user_doc/boolean_dependencies.html
I have tested this with repos having only pki-10.9.x (and therefore
no pki-acme package), and dnf is happy. I have also testing package
installation with pki-10.10 packages installed, but /without/
pki-acme installed. pki-acme was seen as a missing dependency and
installed alongside the freeipa packages. This change seems to
satisfy all the scenarios.
Related: https://github.com/dogtagpki/pki/pull/513
Reviewed-By: Florence Blanc-Renaud <frenaud@redhat.com >
2020-09-18 14:17:03 -04:00
François Cami
be7bf98b3b
dogtaginstance.py: add --debug to pkispawn
...
Since commits:
https://github.com/dogtagpki/pki/commit/0102d836f4eac0fcea0adddb4c98d5ea05e4e8f6
https://github.com/dogtagpki/pki/commit/de217557a642d799b1c4c390efa55493707c738e
pkispawn will not honor the pki_log_level configuration item.
All 10.9 Dogtag versions have these commits.
This affects FreeIPA in that it makes debugging Dogtag installation issues next
to impossible.
Adding --debug to the pkispawn CLI is required to revert to the previous
behavior.
Fixes: https://pagure.io/freeipa/issue/8503
Signed-off-by: François Cami <fcami@redhat.com >
Reviewed-By: Thomas Woerner <twoerner@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
2020-09-17 15:59:00 +02:00
François Cami
c31bf3d430
ipatests: check that pkispawn log is not empty
...
Since commits:
https://github.com/dogtagpki/pki/commit/0102d836f4eac0fcea0adddb4c98d5ea05e4e8f6
https://github.com/dogtagpki/pki/commit/de217557a642d799b1c4c390efa55493707c738e
pkispawn will not honor the pki_log_level configuration item.
All 10.9 Dogtag versions have these commits.
This affects FreeIPA in that it makes debugging Dogtag installation issues next
to impossible.
Adding --debug to the pkispawn CLI is required to revert to the previous
behavior.
Therefore check that the log is not empty and contains DEBUG+INFO lines.
Fixes: https://pagure.io/freeipa/issue/8503
Signed-off-by: François Cami <fcami@redhat.com >
Reviewed-By: Thomas Woerner <twoerner@redhat.com >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
2020-09-17 15:59:00 +02:00
Armando Neto
26ae95f4b4
ipatests: Add nightly definitions for enforcing mode
...
Duplicates the scenario for nightly_latest.yaml and
nightly_latest_testing.yaml setting `selinux_enforcing` parameter
as True.
Indentation for all definitions have been fixed.
Issue: https://github.com/freeipa/freeipa-pr-ci/issues/391
Signed-off-by: Armando Neto <abiagion@redhat.com >
Reviewed-By: Florence Blanc-Renaud <frenaud@redhat.com >
2020-09-15 09:11:21 -03:00
Christian Heimes
05da1f7f7f
Add krbPrincipalName pres index correctly
...
See: 20b55f4017
See: https://pagure.io/freeipa/issue/8491
Signed-off-by: Christian Heimes <cheimes@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
2020-09-15 08:58:28 +03:00
Alexander Bokovoy
31bc0df6a2
Specify memory limits as strings for docker compose
...
Fixes the following error in Azure Pipelines CI after upgrade of Docker
setup:
[2020-09-14 06:50:07] The Compose file './docker-compose.yml' is invalid because:
[2020-09-14 06:50:07] services.client.mem_limit contains an invalid type, it should be a string
Fixes: https://pagure.io/freeipa/issue/8494
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com >
Reviewed-By: Stanislav Levin <slev@altlinux.org >
Reviewed-By: Christian Heimes <cheimes@redhat.com >
2020-09-14 14:00:20 +03:00