Jan Cholasta
83f6ddb473
makeapi: use the same formatting for int and long values
...
This prevents validation failures on architectures where integer is less
than 32 bits.
https://fedorahosted.org/freeipa/ticket/5894
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-05-19 16:43:58 +02:00
Jan Cholasta
5452006498
build: fix client-only build
...
https://fedorahosted.org/freeipa/ticket/5889
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-05-19 15:52:06 +02:00
Jan Cholasta
1276083d95
spec file: bump minimum required pki-core version
...
Require pki-core >= 10.2.6-19, which contains fixes for the following PKI
tickets:
* https://fedorahosted.org/pki/ticket/2022
* https://fedorahosted.org/pki/ticket/2247
* https://fedorahosted.org/pki/ticket/2255
https://fedorahosted.org/freeipa/ticket/5602
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2016-05-19 13:38:04 +02:00
Jan Cholasta
54a59475f3
certdb: never use the -r option of certutil
...
The -r option makes certutil output certificates in DER. If there are
multiple certificates sharing the same nickname, certutil will output
them concatenated into a single blob. The blob is not a valid DER
anymore and causes failures further in the code.
Use the -a option instead to output the certificates in PEM and convert
them to DER on demand.
https://fedorahosted.org/freeipa/ticket/5117
https://fedorahosted.org/freeipa/ticket/5720
Reviewed-By: David Kupka <dkupka@redhat.com >
2016-03-16 09:35:44 +01:00
Jan Cholasta
3c57c305ad
ipalib: add convenient Command method for adding messages
...
Call the add_message() method of Command from anywhere in the implementation
of a command to add a message to the result of the command.
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-03-03 10:06:18 +01:00
Jan Cholasta
e5520dc347
ipalib: provide per-call command context
...
Add context which is valid for the duration of command call. The context
is accessible using the `context` attribute of Command and Object plugins.
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-03-03 10:06:18 +01:00
Jan Cholasta
11592dde1b
client: stop using /etc/pki/nssdb
...
Don't put any IPA certificates to /etc/pki/nssdb - IPA itself uses
/etc/ipa/nssdb and IPA CA certificates are provided to the system using
p11-kit. Remove leftovers on upgrade.
https://fedorahosted.org/freeipa/ticket/5592
Reviewed-By: David Kupka <dkupka@redhat.com >
2016-02-24 10:53:28 +01:00
Jan Cholasta
ef91346407
cacert install: fix trust chain validation
...
https://fedorahosted.org/freeipa/ticket/5612
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2016-02-24 09:22:59 +01:00
Jan Cholasta
b3411dc985
replica promotion: fix AVC denials in remote connection check
...
Also move com.redhat.idm.trust-fetch-domains to /usr/libexec/ipa/oddjob.
https://fedorahosted.org/freeipa/ticket/5550
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2016-02-11 18:40:39 +01:00
Jan Cholasta
465ce82a4d
replica install: validate DS and HTTP server certificates
...
Validate the DS and HTTP certificates from the replica info file early in
ipa-replica-install to prevent crashes later.
https://fedorahosted.org/freeipa/ticket/5598
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2016-02-01 14:41:02 +01:00
Jan Cholasta
eaafeddf76
cert renewal: import all external CA certs on IPA CA cert renewal
...
Import all external CA certs to the Dogtag NSS database on IPA CA cert
renewal. This fixes Dogtag not being able to connect to DS which uses 3rd
party server cert after ipa-certupdate.
https://fedorahosted.org/freeipa/ticket/5595
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2016-01-27 14:38:10 +01:00
Jan Cholasta
6896035af2
spec file: package python-ipalib as noarch
...
https://fedorahosted.org/freeipa/ticket/5596
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2016-01-25 12:30:03 +01:00
Jan Cholasta
b808376e2f
ipapython: use python-cryptography instead of libcrypto in p11helper
...
Replace CFFI calls to libcrypto with equivalent python-cryptography code.
https://fedorahosted.org/freeipa/ticket/5596
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-01-21 10:21:32 +01:00
Jan Cholasta
500ee7e2b1
ipapython: port p11helper C code to Python
...
This replaces the binary _ipap11helper module with cffi-based Python code.
https://fedorahosted.org/freeipa/ticket/5596
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-01-21 10:21:32 +01:00
Jan Cholasta
7e56b4bbd7
ipapython: remove default_encoding_utf8
...
Replace the "import default_encoding_utf8" in ipalib/cli.py with equivalent
Python code.
https://fedorahosted.org/freeipa/ticket/5596
Reviewed-By: Tomas Babej <tbabej@redhat.com >
2016-01-15 13:39:52 +01:00
Jan Cholasta
6b2b173a4d
ipalib: assume version 2.0 when skip_version_check is enabled
...
https://fedorahosted.org/freeipa/ticket/5601
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-01-12 16:37:29 +01:00
Jan Cholasta
c265e8736e
ipautil: remove unused import causing cyclic import in tests
...
https://fedorahosted.org/freeipa/ticket/5551
2015-12-15 15:37:10 +01:00
Jan Cholasta
110e3dfc54
replica promotion: let ipa-client-install validate enrollment options
...
ipa-client-install output is redirected to standard output, so let it print
its own error message for missing options.
https://fedorahosted.org/freeipa/ticket/5542
Reviewed-By: Tomas Babej <tbabej@redhat.com >
2015-12-14 15:38:32 +01:00
Jan Cholasta
c856401478
server install: redirect ipa-client-install output to standard output
...
https://fedorahosted.org/freeipa/ticket/5527
Reviewed-By: Tomas Babej <tbabej@redhat.com >
2015-12-14 14:46:45 +01:00
Jan Cholasta
f49cdfe392
ipautil: allow redirecting command output to standard output in run()
...
https://fedorahosted.org/freeipa/ticket/5527
Reviewed-By: Tomas Babej <tbabej@redhat.com >
2015-12-14 14:46:45 +01:00
Jan Cholasta
b248dfda39
ca install: use host credentials in domain level 1
...
https://fedorahosted.org/freeipa/ticket/5399
Reviewed-By: Martin Basti <mbasti@redhat.com >
2015-12-14 14:40:17 +01:00
Jan Cholasta
6ea868e172
aci: merge domain and CA suffix replication agreement ACIs
...
Merge the two identical sets of replication agreement permission ACIs for
the domain and CA suffixes into a single set suitable for replication
agreements for both suffixes. This makes the replication agreement
permissions behave correctly during CA replica install, so that any
non-admin user with the proper permissions (such as members of the
ipaservers host group) can set up replication for the CA suffix.
https://fedorahosted.org/freeipa/ticket/5399
Reviewed-By: Martin Basti <mbasti@redhat.com >
2015-12-14 14:40:17 +01:00
Jan Cholasta
d68613194b
replica promotion: notify user about ignoring client enrollment options
...
When IPA client is already installed, notify the user that the enrollment
options are ignored in ipa-replica-install.
https://fedorahosted.org/freeipa/ticket/5530
Reviewed-By: Tomas Babej <tbabej@redhat.com >
2015-12-14 14:23:37 +01:00
Jan Cholasta
14a44ea47b
replica promotion: use host credentials for connection check
...
https://fedorahosted.org/freeipa/ticket/5497
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
Reviewed-By: Tomas Babej <tbabej@redhat.com >
2015-12-11 18:44:13 +01:00
Jan Cholasta
8d7f67e08c
replica install: add remote connection check over API
...
Add server_conncheck command which calls ipa-replica-conncheck --replica
over oddjob.
https://fedorahosted.org/freeipa/ticket/5497
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
Reviewed-By: Tomas Babej <tbabej@redhat.com >
2015-12-11 18:44:13 +01:00
Jan Cholasta
00f591d4e9
build: put oddjob scripts into separate directory
...
https://fedorahosted.org/freeipa/ticket/5497
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
Reviewed-By: Tomas Babej <tbabej@redhat.com >
2015-12-11 18:44:13 +01:00
Jan Cholasta
e9baafb08f
spec file: put Python modules into standalone packages
...
Make the following changes in packaging:
* freeipa-server - split off python2-ipaserver and freeipa-server-common,
* freeipa-server-dns - build as noarch,
* freeipa-client - split off python2-ipaclient and freeipa-client-common,
* freeipa-admintools - build as noarch,
* freeipa-python - split into python2-ipalib and freeipa-common, provide
freeipa-python-compat for upgrades,
* freeipa-tests - rename to python2-ipatests and build as noarch.
Bump version to 4.2.91.
https://fedorahosted.org/freeipa/ticket/3197
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
2015-12-11 15:17:41 +01:00
Jan Cholasta
f50b4647ba
spec file: remove config files from freeipa-python
...
/etc/ipa/dnssec is now owned by freeipa-server. The remaining files are now
owned by freeipa-client.
https://fedorahosted.org/freeipa/ticket/3197
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
2015-12-11 15:17:41 +01:00
Jan Cholasta
ccb2f52313
server uninstall: ignore --ignore-topology-disconnect in domain level 0
...
Topology disconnect is always ignored in domain level 0, so the option can
be safely ignored.
https://fedorahosted.org/freeipa/ticket/5409
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-12-11 07:18:44 +01:00
Jan Cholasta
b4a78db4e7
replica promotion: check domain level before ipaservers membership
...
Check domain level before checking ipaservers membership to prevent
"not found" error when attempting replica promotion in domain level 0.
https://fedorahosted.org/freeipa/ticket/5401
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-12-11 07:11:46 +01:00
Jan Cholasta
8f36a5bd68
replica install: add ipaservers if it does not exist
...
This prevents crash when adding the host entry to ipaservers when
installing replica of a 4.2 or older server.
https://fedorahosted.org/freeipa/ticket/3416
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-12-11 07:11:46 +01:00
Jan Cholasta
faf6085564
replica promotion: allow OTP bulk client enrollment
...
https://fedorahosted.org/freeipa/ticket/5498
Reviewed-By: Martin Basti <mbasti@redhat.com >
2015-12-09 10:16:32 +01:00
Jan Cholasta
01ddf51df7
custodia: do not modify memberPrincipal on key update
...
https://fedorahosted.org/freeipa/ticket/5401
Reviewed-By: Martin Basti <mbasti@redhat.com >
Reviewed-By: Simo Sorce <ssorce@redhat.com >
2015-12-07 08:14:13 +01:00
Jan Cholasta
42544484dc
replica promotion: automatically add the local host to ipaservers
...
If the user is authorized to modify members of the ipaservers host group,
add the local host to ipaservers automatically.
https://fedorahosted.org/freeipa/ticket/5401
Reviewed-By: Martin Basti <mbasti@redhat.com >
Reviewed-By: Simo Sorce <ssorce@redhat.com >
2015-12-07 08:14:13 +01:00
Jan Cholasta
c2af409517
replica promotion: use host credentials when setting up replication
...
Use the local host credentials rather than the user credentials when
setting up replication. The host must be a member of the ipaservers host
group. The user credentials are still required for connection check.
https://fedorahosted.org/freeipa/ticket/5401
Reviewed-By: Martin Basti <mbasti@redhat.com >
Reviewed-By: Simo Sorce <ssorce@redhat.com >
2015-12-07 08:14:13 +01:00
Jan Cholasta
662158b781
ipautil: use file in a temporary dir as ccache in private_ccache
...
python-gssapi chokes on empty ccache files, so instead of creating an empty
temporary ccache file in private_ccache, create a temporary directory and
use a non-existent file in that directory as the ccache.
https://fedorahosted.org/freeipa/ticket/5401
Reviewed-By: Martin Basti <mbasti@redhat.com >
Reviewed-By: Simo Sorce <ssorce@redhat.com >
2015-12-07 08:14:13 +01:00
Jan Cholasta
e137f305ed
aci: allow members of ipaservers to set up replication
...
Add ACIs which allow the members of the ipaservers host group to set up
replication. This allows IPA hosts to perform replica promotion on
themselves.
A number of checks which need read access to certain LDAP entries is done
during replica promotion. Add ACIs to allow these checks to be done using
any valid IPA host credentials.
https://fedorahosted.org/freeipa/ticket/5401
Reviewed-By: Martin Basti <mbasti@redhat.com >
Reviewed-By: Simo Sorce <ssorce@redhat.com >
2015-12-07 08:14:13 +01:00
Jan Cholasta
7b9a97383c
aci: replace per-server ACIs with ipaserver-based ACIs
...
https://fedorahosted.org/freeipa/ticket/3416
Reviewed-By: Martin Basti <mbasti@redhat.com >
Reviewed-By: Simo Sorce <ssorce@redhat.com >
2015-12-07 08:13:23 +01:00
Jan Cholasta
a8d7ce5cf1
aci: add IPA servers host group 'ipaservers'
...
https://fedorahosted.org/freeipa/ticket/3416
Reviewed-By: Martin Basti <mbasti@redhat.com >
Reviewed-By: Simo Sorce <ssorce@redhat.com >
2015-12-07 08:13:23 +01:00
Jan Cholasta
4d24d8b26c
topology: replace "suffices" with "suffixes"
...
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-12-01 09:30:21 +01:00
Jan Cholasta
46ae52569a
server: use topologysuffix name in iparepltopomanagedsuffix
...
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-12-01 09:30:21 +01:00
Jan Cholasta
aeffe2da42
install: drop support for Dogtag 9
...
Dogtag 9 CA and CA DS install and uninstall code was removed. Existing
Dogtag 9 CA and CA DS instances are disabled on upgrade.
Creating a replica of a Dogtag 9 IPA master is still supported.
https://fedorahosted.org/freeipa/ticket/5197
Reviewed-By: David Kupka <dkupka@redhat.com >
2015-11-25 09:12:25 +01:00
Jan Cholasta
2d041daf17
client install: do not corrupt OpenSSH config with Match sections
...
https://fedorahosted.org/freeipa/ticket/5461
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-11-20 12:29:04 +01:00
Jan Cholasta
f3076c6ab3
cert renewal: make renewal of ipaCert atomic
...
This prevents errors when renewing other certificates during the renewal of
ipaCert.
https://fedorahosted.org/freeipa/ticket/5436
Reviewed-By: David Kupka <dkupka@redhat.com >
2015-11-19 13:06:12 +01:00
Jan Cholasta
164fb7b1d1
install: export KRA agent PEM file in ipa-kra-install
...
https://fedorahosted.org/freeipa/ticket/5462
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-11-19 11:17:49 +01:00
Jan Cholasta
6a55174bb6
install: fix command line option validation
...
The code which calls the validators was accidentally removed, re-add it.
https://fedorahosted.org/freeipa/ticket/5386
https://fedorahosted.org/freeipa/ticket/5391
https://fedorahosted.org/freeipa/ticket/5392
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-11-05 10:33:01 +01:00
Jan Cholasta
2f3450249d
vault: fix private service vault creation
...
https://fedorahosted.org/freeipa/ticket/5361
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
2015-10-13 14:34:00 +02:00
Jan Cholasta
61bdbd6e47
upgrade: make sure ldap2 is connected in export_kra_agent_pem
...
https://fedorahosted.org/freeipa/ticket/5360
Reviewed-By: Ales 'alich' Marecek <amarecek@redhat.com >
2015-10-12 15:51:14 +02:00
Jan Cholasta
275e1482de
schema: do not derive ipaVaultPublicKey from ipaPublicKey
...
This is a workaround for DS bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1267782
https://fedorahosted.org/freeipa/ticket/5359
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2015-10-12 15:48:42 +02:00
Jan Cholasta
4b381b1503
vault: select a server with KRA for vault operations
...
This uses the same mechanism which is used for the CA.
https://fedorahosted.org/freeipa/ticket/5302
Reviewed-By: Martin Basti <mbasti@redhat.com >
2015-10-08 13:42:58 +02:00
Jan Cholasta
b035a2a114
install: always export KRA agent PEM file
...
Export the file even when KRA is not installed locally so that vault commands
work on all IPA replicas.
https://fedorahosted.org/freeipa/ticket/5302
Reviewed-By: Martin Basti <mbasti@redhat.com >
2015-10-08 13:42:58 +02:00
Jan Cholasta
110e85cc74
install: fix KRA agent PEM file permissions
...
This fixes CVE-2015-5284.
https://fedorahosted.org/freeipa/ticket/5347
Reviewed-By: Martin Basti <mbasti@redhat.com >
2015-10-08 13:41:08 +02:00
Jan Cholasta
6067824be4
install: fix ipa-server-install fail on missing --forwarder
...
https://fedorahosted.org/freeipa/ticket/4517
Reviewed-By: Martin Basti <mbasti@redhat.com >
2015-10-01 14:59:41 +02:00
Jan Cholasta
c388dbd4de
install: fix invocation of KRAInstance.create_instance()
...
Reviewed-By: Simo Sorce <ssorce@redhat.com >
2015-10-01 07:42:33 +02:00
Jan Cholasta
4c39561261
install: fix kdcproxy user home directory
...
https://fedorahosted.org/freeipa/ticket/5314
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-09-23 16:29:49 +02:00
Jan Cholasta
859590337a
platform: add option to create home directory when adding user
...
https://fedorahosted.org/freeipa/ticket/5314
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-09-23 16:29:49 +02:00
Jan Cholasta
0de8603183
install: create kdcproxy user during server install
...
This change makes kdcproxy user creation consistent with DS and CA user
creation. Before, the user was created in the spec file, in %pre scriptlet
of freeipa-server.
https://fedorahosted.org/freeipa/ticket/5314
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-09-22 16:34:51 +02:00
Jan Cholasta
86edd6abeb
install: Move unattended option to the general help section
...
https://fedorahosted.org/freeipa/ticket/4517
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-09-22 12:09:22 +02:00
Jan Cholasta
bed64a888a
install: Add common base class for server and replica install
...
https://fedorahosted.org/freeipa/ticket/4517
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-09-22 12:09:22 +02:00
Jan Cholasta
39f6f637a7
install: Support overriding knobs in subclasses
...
https://fedorahosted.org/freeipa/ticket/4517
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-09-22 12:09:22 +02:00
Jan Cholasta
5137478fb8
install: support KRA update
...
https://fedorahosted.org/freeipa/ticket/5250
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
2015-09-17 14:55:54 +02:00
Jan Cholasta
0dfcf1d9db
vault: add permissions and administrator privilege
...
https://fedorahosted.org/freeipa/ticket/5250
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
2015-09-17 14:55:54 +02:00
Jan Cholasta
d3503043c4
vault: update access control
...
Do not allow vault and container owners to manage owners. Allow adding vaults
and containers only if owner is set to the current user.
https://fedorahosted.org/freeipa/ticket/5250
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
2015-09-17 14:55:54 +02:00
Jan Cholasta
5cf46b8936
vault: set owner to current user on container creation
...
This reverts commit 419754b1c1 .
https://fedorahosted.org/freeipa/ticket/5250
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
2015-09-17 14:55:54 +02:00
Jan Cholasta
2964b019d9
baseldap: make subtree deletion optional in LDAPDelete
...
https://fedorahosted.org/freeipa/ticket/5250
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
2015-09-17 14:55:54 +02:00
Jan Cholasta
33aba6f35e
Use byte literals where appropriate
...
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2015-09-17 11:08:43 +02:00
Jan Cholasta
ba5201979d
Use bytes instead of str where appropriate
...
Under Python 2, "str" and "bytes" are synonyms.
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2015-09-17 11:08:43 +02:00
Jan Cholasta
23507e6124
Alias "unicode" to "str" under Python 3
...
The six way of doing this is to replace all occurences of "unicode"
with "six.text_type". However, "unicode" is non-ambiguous and
(arguably) easier to read. Also, using it makes the patches smaller,
which should help with backporting.
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2015-09-17 11:08:43 +02:00
Jan Cholasta
60dd90cf77
config: allow user/host attributes with tagging options
...
https://fedorahosted.org/freeipa/ticket/5295
Reviewed-By: David Kupka <dkupka@redhat.com >
2015-09-16 15:01:34 +02:00
Jan Cholasta
cc53526fd2
Decode script arguments using file system encoding
...
This mimics Python 3's behavior, where sys.argv is automatically decoded
using file system encoding, as returned by sys.getfilesystemencoding(). This
includes reimplementation of os.fsdecode() from Python 3.
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2015-09-07 08:00:11 +02:00
Jan Cholasta
cf9bf9dcaf
Use six.python_2_unicode_compatible
...
Rename __unicode__ to __str__ in classes which define it and use the
six.python_2_unicode_compatible decorator on them to make them compatible with
both Python 2 and 3.
Additional changes were required for the ipapython.dnsutil.DNSName class,
because it defined both __str__ and __unicode__.
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2015-09-07 08:00:11 +02:00
Jan Cholasta
ebdfa4380b
Use six.with_metaclass to specify metaclasses
...
Metaclass specification is incompatible between Python 2 and 3. Use the
six.with_metaclass helper to specify metaclasses.
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2015-09-07 08:00:11 +02:00
Jan Cholasta
198908ec78
ldap: Make ldap2 connection management thread-safe again
...
This fixes the connection code in LDAPClient to not store the LDAP connection
in an attribute of the object, which in combination with ldap2's per-thread
connections lead to race conditions resulting in connection failures. ldap2
code was updated accordingly.
https://fedorahosted.org/freeipa/ticket/5268
Reviewed-By: Tomas Babej <tbabej@redhat.com >
2015-09-04 13:31:46 +02:00
Jan Cholasta
0914cb663e
install: Fix SASL mappings not added in ipa-server-install
...
Reviewed-By: David Kupka <dkupka@redhat.com >
Reviewed-By: Simo Sorce <ssorce@redhat.com >
2015-08-27 16:05:11 +02:00
Jan Cholasta
e9a76c3d12
cert renewal: Automatically update KRA agent PEM file
...
https://fedorahosted.org/freeipa/ticket/5253
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2015-08-27 15:53:42 +02:00
Jan Cholasta
43ee695195
cert renewal: Include KRA users in Dogtag LDAP update
...
https://fedorahosted.org/freeipa/ticket/5253
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2015-08-27 15:53:42 +02:00
Jan Cholasta
aebb72e1fb
spec file: Add Requires(post) on selinux-policy
...
This prevents ipa-server-upgrade failures on SELinux AVCs because of old
selinux-policy version.
https://fedorahosted.org/freeipa/ticket/5256
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
Reviewed-By: Martin Kosek <mkosek@redhat.com >
2015-08-26 08:19:32 +02:00
Jan Cholasta
01dd951ddc
vault: Add container information to vault command results
...
https://fedorahosted.org/freeipa/ticket/5150
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
2015-08-19 10:39:25 +02:00
Jan Cholasta
29cee7a4bc
vault: Fix vault-find with criteria
...
https://fedorahosted.org/freeipa/ticket/5212
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
2015-08-19 10:28:27 +02:00
Jan Cholasta
ff1e66375c
install: Fix replica install with custom certificates
...
https://fedorahosted.org/freeipa/ticket/5226
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-08-18 16:24:19 +02:00
Jan Cholasta
d9e9e5088f
vault: Fix param labels in output of vault owner commands
...
https://fedorahosted.org/freeipa/ticket/5214
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
2015-08-18 11:17:29 +02:00
Jan Cholasta
d2da0d89d1
baseldap: Allow overriding member param label in LDAPModMember
...
https://fedorahosted.org/freeipa/ticket/5214
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
2015-08-18 11:17:29 +02:00
Jan Cholasta
391ccabb9f
ULC: Prevent preserved users from being assigned membership
...
https://fedorahosted.org/freeipa/ticket/5170
Reviewed-By: David Kupka <dkupka@redhat.com >
2015-08-13 16:41:03 +02:00
Jan Cholasta
a651be3eec
install: Fix server and replica install options
...
https://fedorahosted.org/freeipa/ticket/5184
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-08-12 16:42:01 +02:00
Jan Cholasta
d6e701a793
spec file: Update minimum required version of krb5
...
Automatically require the krb5 version used at build time.
https://fedorahosted.org/freeipa/ticket/5132
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2015-07-15 11:02:32 +00:00
Jan Cholasta
ba31b41569
spec file: Move /etc/ipa/kdcproxy to the server subpackage
...
The directory was in the python subpackage, but that broke client-only
build. We don't want the directory to be installed on clients anyway,
since it is part of a server-side feature.
Reviewed-By: Christian Heimes <cheimes@redhat.com >
2015-07-15 10:46:18 +00:00
Jan Cholasta
7c0e7f7e3c
spec file: Update minimal versions of required packages
...
https://fedorahosted.org/freeipa/ticket/5103
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2015-07-08 16:08:06 +02:00
Jan Cholasta
232458a222
ipalib: Fix skip_version_check option
...
This reverts commit ea7f392bb9 .
The option can be either set in IPA config file or specified as
'ipa -e skip_version_check=1 [COMMAND]'.
https://fedorahosted.org/freeipa/ticket/4768
Reviewed-By: Martin Basti <mbasti@redhat.com >
2015-07-08 12:36:19 +00:00
Jan Cholasta
e43296ba9a
replica prepare: Do not use entry after disconnecting from LDAP
...
https://fedorahosted.org/freeipa/ticket/3090
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-07-01 13:05:30 +00:00
Jan Cholasta
5b39bc1003
plugable: Remove unused call method of Plugin
...
https://fedorahosted.org/freeipa/ticket/3090
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-07-01 13:05:30 +00:00
Jan Cholasta
2b12bca660
plugable: Specify plugin base classes and modules using API properties
...
https://fedorahosted.org/freeipa/ticket/3090
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-07-01 13:05:30 +00:00
Jan Cholasta
4b277d0477
plugable: Change is_production_mode to method of API
...
https://fedorahosted.org/freeipa/ticket/3090
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-07-01 13:05:30 +00:00
Jan Cholasta
1a21fd971c
plugable: Remove SetProxy, DictProxy and MagicDict
...
https://fedorahosted.org/freeipa/ticket/3090
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-07-01 13:05:30 +00:00
Jan Cholasta
e9c9e3f009
ipaplatform: Do not use MagicDict for KnownServices
...
https://fedorahosted.org/freeipa/ticket/3090
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-07-01 13:05:30 +00:00
Jan Cholasta
b1fc875c3a
plugable: Lock API on finalization rather than on initialization
...
https://fedorahosted.org/freeipa/ticket/3090
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-07-01 13:05:30 +00:00
Jan Cholasta
860088208b
plugable: Do not use DictProxy for API
...
https://fedorahosted.org/freeipa/ticket/3090
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-07-01 13:05:30 +00:00
Jan Cholasta
e39fe4ed31
plugable: Pass API to plugins on initialization rather than using set_api
...
https://fedorahosted.org/freeipa/ticket/3090
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-07-01 13:05:30 +00:00
Jan Cholasta
2d1515323a
plugable: Load plugins only from modules imported by API
...
Previously all plugin modules imported from anywhere were added to the API.
https://fedorahosted.org/freeipa/ticket/3090
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-07-01 13:05:30 +00:00
Jan Cholasta
481f8ddaa3
plugable: Specify plugins to import in API by module names
...
This change removes the automatic plugins sub-package magic and allows
specifying modules in addition to packages.
https://fedorahosted.org/freeipa/ticket/3090
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-07-01 13:05:30 +00:00
Jan Cholasta
7715d5bb04
ipalib: Move find_modules_in_dir from util to plugable
...
https://fedorahosted.org/freeipa/ticket/3090
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-07-01 13:05:30 +00:00