David Kupka
ba16d99f37
schema cache: Do not reset ServerInfo dirty flag
...
Once dirty flag is set to True it must not be set back to False.
Otherwise changes are not written back to file.
https://fedorahosted.org/freeipa/ticket/6048
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2016-08-17 14:16:04 +02:00
David Kupka
229e2a1ed9
compat: Save server's API version in for pre-schema servers
...
When client comunicates with server that doesn't support 'schema'
command it needs to determine its api version to be able to use the
right compat code. Storing information about server version reduces the
need to call 'env' or 'ping' command only to first time the server is
contacted.
https://fedorahosted.org/freeipa/ticket/6069
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2016-08-03 16:32:39 +02:00
David Kupka
e76b0bbbcc
help: Do not create instances to get information about commands and topics
...
Creating instance requires that complete schema for the command is
read from schema cache and passed to constructor. This operation takes
a lot of time. Utilizing class properties and pregenerated help bits
allows to get the necessary information directly from classes reducing
time it takes significantly.
https://fedorahosted.org/freeipa/ticket/6048
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2016-08-03 16:32:39 +02:00
David Kupka
23609d5955
schema: Generate bits for help load them on request
...
Store name, summary, topic_topic and exclude in single entry in cache
for all commands. These data are needed for help and storing and
loading them together allows fast help response.
https://fedorahosted.org/freeipa/ticket/6048
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2016-08-03 16:32:39 +02:00
David Kupka
86977070e1
schema: Introduce schema cache format
...
Information about schema cache format is stored in every cache item.
When schema cache format changes in incompatible way format will be
increased. When format stored in cache doesn't match currently used
format the entry in cache is ignored.
https://fedorahosted.org/freeipa/ticket/6048
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2016-08-03 16:32:39 +02:00
David Kupka
29f7f822ab
frontend: Change doc, summary, topic and NO_CLI to class properties
...
Avoid need to instantiate all commands just to get information for
displaying help.
https://fedorahosted.org/freeipa/ticket/6048
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2016-08-03 16:32:39 +02:00
David Kupka
47a693d174
schema: Speed up schema cache
...
Check presence of schema in cache (and download it if necessary) on
__init__ instead of with each __getitem__ call. Prefill internal
dictionary with empty record for each command to be able to quickly
determine if requested command exist in schema or not. Rest of schema
data are read from cache on first attempt to retrive them.
https://fedorahosted.org/freeipa/ticket/6048
https://fedorahosted.org/freeipa/ticket/6069
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2016-08-03 16:32:39 +02:00
David Kupka
8ab0ad5b9e
vault: Catch correct exception in decrypt
...
ValueError is raised when decryption fails.
https://fedorahosted.org/freeipa/ticket/6160
Reviewed-By: David Kupka <dkupka@redhat.com >
2016-08-03 13:40:34 +02:00
David Kupka
34767ba259
help: Add dnsserver commands to help topic 'dns'
...
https://fedorahosted.org/freeipa/ticket/6069
Reviewed-By: Petr Spacek <pspacek@redhat.com >
2016-07-22 13:52:09 +02:00
David Kupka
92dea9b186
schema: Fix subtopic -> topic mapping
...
https://fedorahosted.org/freeipa/ticket/6069
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2016-07-15 14:02:17 +02:00
David Kupka
d2cb9ed327
Allow unexpiring passwords
...
Treat maxlife=0 in password policy as "never expire". Delete
krbPasswordExpiration in user entry when password should never expire.
https://fedorahosted.org/freeipa/ticket/2795
Reviewed-By: Thierry Bordaz <tbordaz@redhat.com >
Reviewed-By: Pavel Vomacka <pvomacka@redhat.com >
2016-07-01 11:22:02 +02:00
David Kupka
cea1f33606
schema: Perform the check for schema update when force_schema_check is True
...
https://fedorahosted.org/freeipa/ticket/4739
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2016-07-01 10:12:34 +02:00
David Kupka
e5635f7ef4
schema: Decrease schema TTL to one hour
...
Since checking schema is relatively cheap operation (one round-trip with
almost no data) we can do it offten to ensure schema will fetched by
client ASAP after it was updated on server.
https://fedorahosted.org/freeipa/ticket/4739
Reviewed-By: Petr Spacek <pspacek@redhat.com >
2016-07-01 09:22:57 +02:00
David Kupka
573819eb07
test: cert: Reflect change in behavior in tests
...
Command cert-find with parameter sizelimit set to 0 no longer returns 0
certificates but returns all.
More precise ConversionError is returned when parameter is not
convertible to its type.
https://fedorahosted.org/freeipa/ticket/5381
https://fedorahosted.org/freeipa/ticket/4739
Reviewed-By: Petr Spacek <pspacek@redhat.com >
2016-06-29 14:49:08 +02:00
David Kupka
95191e1612
test: automember: Fix expected exception message
...
https://fedorahosted.org/freeipa/ticket/4739
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2016-06-29 10:49:37 +02:00
David Kupka
a636842889
schema: Caching on schema on client
...
Store schema in per user cache. Together with schemas also information
about mapping between server and fingerprint is stored to reduce traffic.
https://fedorahosted.org/freeipa/ticket/4739
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2016-06-28 15:03:42 +02:00
David Kupka
65aa2d48ff
env: Add 'server' variable to api.env
...
https://fedorahosted.org/freeipa/ticket/4739
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2016-06-28 15:03:42 +02:00
David Kupka
a5f48476ad
schema: return fingerprint as unicode text
...
https://fedorahosted.org/freeipa/ticket/4739
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2016-06-21 16:23:43 +02:00
David Kupka
d0e708cba2
schema: Cache schema in api instance
...
To avoid generating schema for every schema command call store schema in
api instance when first generated and reuse it in next calls.
https://fedorahosted.org/freeipa/ticket/4739
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2016-06-21 15:11:19 +02:00
David Kupka
4b97cabb52
schema: Add known_fingerprints option to schema command
...
When client requests schema it can list fingerprints of cached schemas
and server responds with SchemaUpToDate exception specifying fingeprint
of schema to use.
https://fedorahosted.org/freeipa/ticket/4739
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2016-06-21 15:11:19 +02:00
David Kupka
034a111972
schema: Add fingerprint and TTL
...
Calculate fingerprint for schema in deterministic way. Send fingerprint
value together with schema. Send TTL with schema to inform client about
caching interval.
https://fedorahosted.org/freeipa/ticket/4739
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2016-06-21 15:11:19 +02:00
David Kupka
45bb2ad045
Remove unused locking "context manager"
...
Class ods_db_lock is unused since August 2015.
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-06-17 18:27:22 +02:00
David Kupka
9f48c39649
installer: index() raises ValueError
...
Expecting IndexError instead of ValueError led to traceback instead of correctly
reporting the error situation.
https://fedorahosted.org/freeipa/ticket/5945
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2016-06-13 18:04:40 +02:00
David Kupka
54318d1a2c
installer: positional_arguments must be tuple or list of strings
...
Setting string here was causing search for substring instead of search for value
in tuple or list.
https://fedorahosted.org/freeipa/ticket/5945
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2016-06-13 18:04:40 +02:00
David Kupka
da5885b72a
man: Decribe ipa-client-install workaround for broken D-Bus enviroment.
...
https://fedorahosted.org/freeipa/ticket/5694
Reviewed-By: Florence Blanc-Renaud <frenaud@redhat.com >
2016-06-09 13:08:46 +02:00
David Kupka
05878f1153
test: test_cli: Do not expect defaults in kwargs.
...
Client is no longer forwarding in arguments with default values to the server.
https://fedorahosted.org/freeipa/ticket/4739
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-06-06 19:53:59 +02:00
David Kupka
03a697489a
Look up HTTPD_USER's UID and GID during installation.
...
Those values differ among distributions and there is no guarantee that they're
reserved. It's better to look them up based on HTTPD_USER's name.
https://fedorahosted.org/freeipa/ticket/5712
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-03-23 17:15:25 +01:00
David Kupka
4337c4f9c4
httpinstance: add start_tracking_certificates method
...
Configure certmonger to start tracking certificate for httpd.
https://fedorahosted.org/freeipa/ticket/5586
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2016-02-26 08:27:44 +01:00
David Kupka
431a1a0383
dsinstance: add start_tracking_certificates method
...
Configure certmonger to start tracing certificate for DS.
https://fedorahosted.org/freeipa/ticket/5586
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2016-02-26 08:27:44 +01:00
David Kupka
6b4678170e
upgrade: Match whole pre/post command not just basename.
...
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2016-02-26 08:27:44 +01:00
David Kupka
775ee77bcc
CI: Make double circle topology python3 compatible
...
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-02-24 10:37:04 +01:00
David Kupka
a1e582b33c
CI: Add test for double-circle topology generator.
...
Reviewed-By: Milan Kubik <mkubik@redhat.com >
2016-02-23 17:32:36 +01:00
David Kupka
a1d2ce00a6
CI: Add replication test utilizing double-circle topology.
...
Reviewed-By: Milan Kubik <mkubik@redhat.com >
2016-02-23 17:32:36 +01:00
David Kupka
cbd9c3943a
CI: Add double circle topology.
...
Every site consist of at least two replicas and is connected to two other
sites.
Reviewed-By: Milan Kubik <mkubik@redhat.com >
2016-02-23 17:32:36 +01:00
David Kupka
acdabba6ec
CI: add empty topology test for 2-connected topology generator
...
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-02-23 17:30:16 +01:00
David Kupka
616c78b720
CI: Fix pep8 errors in 2-connected topology generator
...
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-02-23 17:30:16 +01:00
David Kupka
2541b5fcbf
CI: Add test for 2-connected topology generator.
...
Reviewed-By: Milan Kubik <mkubik@redhat.com >
2016-02-12 16:57:19 +01:00
David Kupka
c2bbd5dcd8
CI: Add simple replication test in 2-connected topology.
...
Reviewed-By: Milan Kubik <mkubik@redhat.com >
2016-02-12 16:57:19 +01:00
David Kupka
8f6e9113e9
CI: Add '2-connected' topology generator.
...
If number of servers (master+replicas) is equal to 4 + SUM(1, n, 2^n*5) for
any n >= 0:
* every server has replication agreement with 2 - 4 other servers.
* at least two agreements must fail in order to disconnect the topology.
Otherwise there can be server(s) with single agreement on the edge of the
topology.
Reviewed-By: Milan Kubik <mkubik@redhat.com >
2016-02-12 16:57:19 +01:00
David Kupka
bc6543efae
Fix: Use unattended parameter instead of options.unattended
...
Attribute 'unattended' is not always present in 'options' so function
parameter 'unattended' should be used.
https://fedorahosted.org/freeipa/ticket/5563
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-01-11 16:34:31 +01:00
David Kupka
da1b119663
installer: Change reverse zones question to better reflect reality.
...
https://fedorahosted.org/freeipa/ticket/5563
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-01-11 16:34:31 +01:00
David Kupka
f05bea5a12
ipa-replica-prepare: Add '--auto-reverse' and '--allow-zone-overlap' options
...
Opiton should be added to ipa-replica-prepare when it was added to
ipa-{server,replica,dns}-install but was forgotten.
https://fedorahosted.org/freeipa/ticket/5563
Reviewed-By: Martin Basti <mbasti@redhat.com >
2016-01-11 16:34:31 +01:00
David Kupka
8ad39a974f
ipa-dns-install: Do not check for zone overlap when DNS installed.
...
When DNS is already installed somewhere in topology we should not check for
zone overlap because it would always say that we are overlapping our own domain.
ipa-replica-install already does that but ipa-dns-install did not.
https://fedorahosted.org/freeipa/ticket/5564
Reviewed-By: Petr Spacek <pspacek@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
2015-12-22 16:04:14 +01:00
David Kupka
f0703d3c2a
installer: Fix logic of reading option values from cache.
...
Only options explicitly set must be stored before installer exits first step
of external CA setup. When installer continues all stored option values must
be restored.
https://fedorahosted.org/freeipa/ticket/5556
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2015-12-21 18:37:32 +01:00
David Kupka
30fbc7e948
installer: Propagate option values from components instead of copying them.
...
https://fedorahosted.org/freeipa/ticket/5556
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2015-12-21 18:37:32 +01:00
David Kupka
1534061d9b
dns: Add --auto-reverse option.
...
Introducing '--auto-reverse' option. When specified reverse records for
all server's IP addresses are checked and when record nor reverse zone
does not exist reverse zone is created.
Reviewed-By: Petr Spacek <pspacek@redhat.com >
2015-12-14 18:53:53 +01:00
David Kupka
8d19da49c4
dns: Check if domain already exists.
...
Raise an error when the domain already exists. This can be overriden using
--force or --allow-zone-overlap options.
https://fedorahosted.org/freeipa/ticket/3681
Reviewed-By: Petr Spacek <pspacek@redhat.com >
2015-12-14 18:53:53 +01:00
David Kupka
6c107d819c
dns: do not add (forward)zone if it is already resolvable.
...
Check if the zone user wants to add is already resolvable and refuse to
create it if yes. --skip-overlap-check and --force options suppress this check.
https://fedorahosted.org/freeipa/ticket/5087
Reviewed-By: Petr Spacek <pspacek@redhat.com >
2015-12-14 18:53:53 +01:00
David Kupka
8b1002a18c
spec file: Add dbus-python to BuildRequires
...
Commit 8d7f67e introduced the need for dbus-python during build time.
https://fedorahosted.org/freeipa/ticket/5497
2015-12-14 13:38:52 +01:00
David Kupka
8112ac69cc
test: Temporarily increase timeout in vault test.
...
Remove this change when vault is fixed.
Reviewed-By: Martin Basti <mbasti@redhat.com >
2015-12-14 11:52:20 +01:00
David Kupka
b7953cda4f
replica: Fix ipa-replica-install with replica file (domain level 0).
...
Attribute _ca_enabled is set in promote_check() and is not available in
install(). When installing replica in domain level 0 we can determine existence
of CA service based on existence of cacert.p12 file in provided replica-file.
https://fedorahosted.org/freeipa/ticket/5531
Reviewed-By: Oleg Fayans <ofayans@redhat.com >
2015-12-10 07:49:53 +01:00
David Kupka
2c5a662fd8
install: Run all validators at once.
...
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2015-12-08 08:12:22 +01:00
David Kupka
2f51f0dce2
ipa-replica-install support caless install with promotion.
...
https://fedorahosted.org/freeipa/ticket/5441
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2015-12-03 09:32:39 +01:00
David Kupka
2ef1eb0ae7
ipa-otptoken-import: Fix connection to ldap.
...
https://fedorahosted.org/freeipa/ticket/5475
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2015-11-23 15:50:16 +01:00
David Kupka
5f2cfb5aa2
ipa-cacert-renew: Fix connection to ldap.
...
https://fedorahosted.org/freeipa/ticket/5468
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2015-11-23 15:50:16 +01:00
David Kupka
5aa118d149
admintool: Add error message with path to log on failure.
...
Reviewed-By: Tomas Babej <tbabej@redhat.com >
2015-10-15 13:32:13 +02:00
David Kupka
5ff4170ff9
comment: Add Documentation string to deduplicate function
...
Reviewed-By: Tomas Babej <tbabej@redhat.com >
2015-10-13 13:59:30 +02:00
David Kupka
59cc54b6dc
ipactl: Do not start/stop/restart single service multiple times
...
In case multiple services are provided by single system daemon
it is not needed to start/stop/restart it mutiple time.
https://fedorahosted.org/freeipa/ticket/5248
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
2015-08-26 17:43:03 +02:00
David Kupka
02ab34c60b
vault: Limit size of data stored in vault
...
https://fedorahosted.org/freeipa/ticket/5231
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
2015-08-26 16:11:42 +02:00
David Kupka
db88985c0d
Backup/resore authentication control configuration
...
https://fedorahosted.org/freeipa/ticket/5071
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com >
2015-08-19 14:13:00 +02:00
David Kupka
f160aa3d0a
client: Add description of --ip-address and --all-ip-addresses to man page
...
https://fedorahosted.org/freeipa/ticket/4249
Reviewed-By: Martin Basti <mbasti@redhat.com >
2015-08-19 13:11:22 +02:00
David Kupka
8ba1392a39
client: Add support for multiple IP addresses during installation.
...
https://fedorahosted.org/freeipa/ticket/4249
Reviewed-By: Martin Basti <mbasti@redhat.com >
2015-08-18 22:50:18 +02:00
David Kupka
65b8c62207
user-undel: Fix error messages.
...
https://fedorahosted.org/freeipa/ticket/5207
Reviewed-By: Martin Basti <mbasti@redhat.com >
2015-08-18 19:27:01 +02:00
David Kupka
fe91c375d0
dbus: Create empty dbus.Array with specified signature
...
Python DBus binding could fail to guess the type signature from empty list.
This issue was seen but we don't have a reproducer. There is no harm in making
sure that it will not happen.
Reviewed-By: Martin Basti <mbasti@redhat.com >
2015-08-14 12:48:45 +02:00
David Kupka
e384aad729
ipa-client-install: Do not (re)start certmonger and DBus daemons.
...
When DBus is present in the system it is always running.
Starting of certmomger is handled in ipapython/certmonger.py module if
necessary. Restarting is no longer needed since freeipa is not changing
certmonger's files.
https://fedorahosted.org/freeipa/ticket/5095
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2015-07-20 14:28:09 +00:00
David Kupka
2defc486ab
cermonger: Use private unix socket when DBus SystemBus is not available.
...
https://fedorahosted.org/freeipa/ticket/5095
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2015-07-20 14:28:09 +00:00
David Kupka
e5d179b5b9
migration: Use api.env variables.
...
Use api.env.basedn instead of anonymously accessing LDAP to get base DN.
Use api.env.basedn instead of searching filesystem for ldapi socket.
https://fedorahosted.org/freeipa/ticket/4953
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2015-07-17 10:30:42 +02:00
David Kupka
6a91893ff5
ipa-replica-prepare: Do not create DNS zone it automatically.
...
When --ip-address is specified check if relevant DNS zone exists
in IPA managed DNS server, exit with error when not.
https://fedorahosted.org/freeipa/ticket/5014
Reviewed-By: Martin Basti <mbasti@redhat.com >
2015-07-08 00:37:42 +02:00
David Kupka
e3d3938f44
upgrade: Raise error when certmonger is not running.
...
Certmonger should be running (should be started on system boot).
Either user decided to stop it or it crashed. We should just error out and
let user check & fix it.
https://fedorahosted.org/freeipa/ticket/5080
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
2015-06-29 13:46:47 +02:00
David Kupka
4d05b5d18d
Use 389-ds centralized scripts.
...
Directory server is deprecating use of tools in instance specific paths. Instead
tools in bin/sbin path should be used.
https://fedorahosted.org/freeipa/ticket/4051
Reviewed-By: Martin Basti <mbasti@redhat.com >
2015-06-11 13:16:06 +02:00
David Kupka
2acedb2d5d
Move CA installation code into single module.
...
https://fedorahosted.org/freeipa/ticket/4468
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2015-06-08 06:22:54 +00:00
David Kupka
0167919ba8
Do not store state if CA is enabled
...
IPA creates own instance of CA, so there is no need to check if previous
instance was enabled, because there could not be any.
Reviewed-By: Martin Basti <mbasti@redhat.com >
2015-05-19 12:53:58 +00:00
David Kupka
f19f3e5741
Lint: Fix error on pylint-1.3.1 introduced by fix for pylint-1.4.1.
...
Reviewed-By: Martin Basti <mbasti@redhat.com >
2015-04-27 11:02:57 +02:00
David Kupka
9b706e74d5
Make lint work on Fedora 22.
...
pylint added 'confidence' parameter to 'add_message' method of PyLinter.
To be compatible with both, pre- and post- 1.4 IPALinter must accept
the parameter but not pass it over.
Also python3 checker was added and enabled by default. FreeIPA is still
not ready for python3.
Additionally few false-positives was marked.
Reviewed-By: Martin Basti <mbasti@redhat.com >
2015-04-27 11:02:57 +02:00
David Kupka
4a5f5b14c3
Lint: Skip checking of functions stolen by python-nose.
...
python-nose modifies namespaces in a way that confuses pylint. To skip
these PyCheckers' visit_callfunc method must be extended.
Reviewed-By: Martin Basti <mbasti@redhat.com >
2015-04-24 15:57:45 +02:00
David Kupka
b9657975b7
Bump ipa.conf version to 17.
...
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Simo Sorce <ssorce@redhat.com >
2015-03-30 13:06:12 +00:00
David Kupka
5a03462bfc
Use mod_auth_gssapi instead of mod_auth_kerb.
...
https://fedorahosted.org/freeipa/ticket/4190
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Simo Sorce <ssorce@redhat.com >
2015-03-30 13:06:12 +00:00
David Kupka
8c72e2efad
Remove unused part of ipa.conf.
...
Separate configuration of '/var/www/cgi-bin' is no longer needed legacy from
IPA 1.0.
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
Reviewed-By: Simo Sorce <ssorce@redhat.com >
2015-03-30 13:06:12 +00:00
David Kupka
082c55fb9c
Always reload StateFile before getting or modifying the stored values.
...
This change does not solve using multiple instances of StateFile concurently
because there is no use for it in near future. Instead this solves an issue of loosing
records when more instances of StateFile are interleaved in sequential code.
https://fedorahosted.org/freeipa/ticket/4901
Reviewed-By: Martin Basti <mbasti@redhat.com >
2015-03-18 12:42:16 +01:00
David Kupka
4a20115ce8
Restore default.conf and use it to build API.
...
When restoring ipa after uninstallation we need to extract and load
configuration of the restored environment.
https://fedorahosted.org/freeipa/ticket/4896
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2015-03-05 12:17:23 +00:00
David Kupka
aa745b31d3
Use IPA CA certificate when available and ignore NO_TLS_LDAP when not.
...
ipa-client-automount is run after ipa-client-install so the CA certificate
should be available. If the certificate is not available and ipadiscovery.ipacheckldap
returns NO_TLS_LDAP warn user and try to continue.
https://fedorahosted.org/freeipa/ticket/4902
Reviewed-By: Martin Basti <mbasti@redhat.com >
Reviewed-By: Rob Crittenden <rcritten@redhat.com >
2015-03-05 10:59:01 +01:00
David Kupka
3b87302f5a
idviews: Allow setting ssh public key on ipauseroverride-add
...
https://fedorahosted.org/freeipa/ticket/4868
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2015-01-27 16:03:13 +00:00
David Kupka
b6c58ff238
Abort backup restoration on not matching host.
...
When restoring backup on master other than it was created there is high risk
of unexpected and hard-to-debug behavior. Refuse such restore.
https://fedorahosted.org/freeipa/ticket/4823
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2015-01-13 15:01:31 +00:00
David Kupka
b0f412177f
Remove ipanttrustauthincoming/ipanttrustauthoutgoing from ipa trust-add output.
...
https://fedorahosted.org/freeipa/ticket/4787
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
2015-01-13 15:33:55 +01:00
David Kupka
3c69435c1b
Always add /etc/hosts record when DNS is being configured.
...
This was done previosly but accidentally removed when later with patch for
ticket #3575 .
https://fedorahosted.org/freeipa/ticket/4817
Reviewed-By: Martin Basti <mbasti@redhat.com >
2014-12-18 13:09:58 +01:00
David Kupka
3a6d714bb2
Use singular in help metavars + update man pages.
...
https://fedorahosted.org/freeipa/ticket/4695
Reviewed-By: Martin Basti <mbasti@redhat.com >
2014-11-26 14:33:23 +01:00
David Kupka
56ca47d535
Fix error message for nonexistent members and add tests.
...
https://fedorahosted.org/freeipa/ticket/4643
Reviewed-By: Tomas Babej <tbabej@redhat.com >
2014-11-24 16:04:57 +01:00
David Kupka
373bbee4e3
ipa-restore: Check if directory is provided + better errors.
...
https://fedorahosted.org/freeipa/ticket/4683
Reviewed-By: Tomas Babej <tbabej@redhat.com >
2014-11-21 15:19:56 +01:00
David Kupka
35dad9684b
Fix --{user,group}-ignore-attribute in migration plugin.
...
Ignore case in attribute names.
https://fedorahosted.org/freeipa/ticket/4620
Reviewed-By: Martin Basti <mbasti@redhat.com >
2014-11-20 16:49:13 +01:00
David Kupka
b032debd23
Produce better error in group-add command.
...
https://fedorahosted.org/freeipa/ticket/4611
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2014-11-13 13:07:22 +00:00
David Kupka
e28eb13907
Remove service file even if it isn't link.
...
(Link to) service file from /etc/systemd/system/ must be removed before masking
systemd service.
https://fedorahosted.org/freeipa/ticket/4658
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2014-11-13 13:53:23 +01:00
David Kupka
82c3c2b242
Remove unneeded internal methods. Move code to public methods.
...
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2014-11-11 09:18:30 +01:00
David Kupka
9335552418
Stop dirsrv last in ipactl stop.
...
Other services may depend on directory server.
https://fedorahosted.org/freeipa/ticket/4632
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2014-11-06 10:43:11 +01:00
David Kupka
364d466fd7
Respect UID and GID soft static allocation.
...
https://fedoraproject.org/wiki/Packaging:UsersAndGroups?rd=Packaging/UsersAndGroups#Soft_static_allocation
https://fedorahosted.org/freeipa/ticket/4585
Reviewed-By: Martin Basti <mbasti@redhat.com >
2014-11-05 15:22:51 +01:00
David Kupka
3f9d1a71f1
Fix typo causing certmonger is provided with wrong path to ipa-submit.
...
Using strip() instead split() caused that only first character of path was specified.
Also using shlex for more robust parsing.
https://fedorahosted.org/freeipa/ticket/4624
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2014-10-16 09:49:46 +02:00
David Kupka
47731f4584
Fix printing of reverse zones in ipa-dns-install.
...
This was forgotten in patch for ticket
https://fedorahosted.org/freeipa/ticket/3575
Reviewed-By: Martin Basti <mbasti@redhat.com >
2014-10-16 08:02:02 +02:00
David Kupka
c44f4dcbea
Stop dogtag when updating its configuration in ipa-upgradeconfig.
...
Modifying CS.cfg when dogtag is running may (and does) result in corrupting
this file.
https://fedorahosted.org/freeipa/ticket/4569
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2014-10-15 09:12:11 +02:00
David Kupka
c8f7cb0163
Set IPA CA for freeipa certificates.
...
In previous versions (before moving certmonger.py to DBus) it was set and some
tools and modules depends on it. For example: ipa-getcert uses this to filter
freeipa certificates.
https://fedorahosted.org/freeipa/ticket/4618
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2014-10-14 10:55:29 +02:00
David Kupka
35c7bd05af
Check that port 8443 is available when installing PKI.
...
https://fedorahosted.org/freeipa/ticket/4564
Reviewed-By: Martin Kosek <mkosek@redhat.com >
2014-10-10 11:57:44 +02:00
David Kupka
f36794e811
Fix example usage in ipa man page.
...
https://fedorahosted.org/freeipa/ticket/4587
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-10-08 09:52:08 +02:00