Tomas Babej
4190b1a47c
Revert "Server Upgrade: respect --test option in plugins"
...
This reverts commit c95c4849ae .
2015-03-19 12:48:06 +01:00
Tomas Babej
93f3bb3ddd
idviews: Use case-insensitive detection of Default Trust View
...
The usage of lowercased varsion of 'Default Trust View' can no
longer be used to bypass the validation.
https://fedorahosted.org/freeipa/ticket/4915
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2015-02-23 17:51:21 +01:00
Tomas Babej
72af5fd975
ipalib: Make sure correct attribute name is referenced for fax
...
Fixes the invalid attribute name reference in the
'System: Read User Addressbook Attributes' permission.
https://fedorahosted.org/freeipa/ticket/4883
Reviewed-By: Martin Kosek <mkosek@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2015-02-19 18:36:16 +01:00
Tomas Babej
a34ff7f6c1
ipatests: Add coverage for adding and removing sshpubkeys in ID overrides
...
Adds xmlrpc tests for:
- Adding a user ID override with sshpubkey
- Modifying a user ID override to contain sshpubkey
- Removing a sshpubkey value from a user ID override
https://fedorahosted.org/freeipa/ticket/4868
Reviewed-By: Martin Kosek <mkosek@redhat.com >
2015-02-19 17:03:06 +01:00
Tomas Babej
f30865c5f0
ipapython: Fix incorrect python shebangs
...
Make sure shebangs explicitly reference python2.
Reviewed-By: Martin Basti <mbasti@redhat.com >
2015-01-26 13:03:24 +01:00
Tomas Babej
f83b4fe330
ipatests: Fix incorrect assumptions in idviews tests
...
https://fedorahosted.org/freeipa/ticket/4839
Reviewed-By: David Kupka <dkupka@redhat.com >
2015-01-26 13:01:33 +01:00
Tomas Babej
3341d31ec7
ipatests: Fix old command references in the ID views tests
...
Make sure only new API command versions are referenced.
https://fedorahosted.org/freeipa/ticket/4839
Reviewed-By: David Kupka <dkupka@redhat.com >
2015-01-26 13:01:33 +01:00
Tomas Babej
a294f10d06
ipatests: Add coverage for referential integrity plugin applied on ipaAssignedIDView
...
This adds a test case which makes sure that referential integrity
plugin does not leave any trailing references for ipaAssignedIDView
attribute on hosts, if the ID view being referenced has been deleted.
https://fedorahosted.org/freeipa/ticket/4839
Reviewed-By: David Kupka <dkupka@redhat.com >
2015-01-26 13:01:33 +01:00
Tomas Babej
5416652f6f
ipatests: Make descriptions sorted according to the order of the tests
...
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2015-01-14 11:55:01 +01:00
Tomas Babej
f07607b7cb
spec: Add BuildRequires for python-pytest plugins
...
Reviewed-By: Tomas Babej <tbabej@redhat.com >
2015-01-14 11:40:28 +01:00
Tomas Babej
e11e8235ac
baseldap: Handle missing parent objects properly in *-find commands
...
The find_entries function in ipaldap does not differentiate between
a LDAP search that returns error code 32 (No such object) and LDAP
search returning error code 0 (Success), but returning no results.
In both cases errors.NotFound is raised. In turn, LDAPSearch
commands interpret NotFound exception as no results.
To differentiate between the cases, a new error EmptyResult
was added, which inherits from NotFound to preserve the compatibility
with the new code.
This error is raised by ipaldap.find_entries in case it is performing
a search with and the target dn does not exist.
https://fedorahosted.org/freeipa/ticket/4659
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2015-01-13 16:16:14 +00:00
Tomas Babej
b7e58ce746
ipatests: Refactor and fix docstrings in integration pytest plugin
...
https://fedorahosted.org/freeipa/ticket/4809
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-12-16 12:20:44 +01:00
Tomas Babej
ad01a6b5c5
ipatests: Set the correct number of required clients for IntegrationTest
...
Remove the copy-pate error that used number of required replicas instead.
https://fedorahosted.org/freeipa/ticket/4809
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-12-16 12:20:44 +01:00
Tomas Babej
3507bcd3df
ipatests: Invoke class install methods properly with respect to pytest-multihost
...
Multihost object was is not passed to the install method in the super construction.
This fixes setup errors in AD Trust, Forced client reenrollment, CALess and Sudo
tests.
https://fedorahosted.org/freeipa/ticket/4809
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-12-16 12:20:44 +01:00
Tomas Babej
c5c9d49706
idviews: Ignore host or hostgroup options set to None
...
Since passing --hosts= or --hostsgroups= to idview-apply or unapply
commands does not make sense, ignore it.
https://fedorahosted.org/freeipa/ticket/4806
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
2014-12-12 17:04:21 +01:00
Tomas Babej
fdd7b79eea
idviews: Complain if host is already assigned the ID View in idview-apply
...
When running a idview-apply command, the hosts that were already assigned
the desired view were silently ignored. Make sure such hosts show up in
the list of failed hosts.
https://fedorahosted.org/freeipa/ticket/4743
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
2014-12-12 16:43:23 +01:00
Tomas Babej
3e406f9924
ipatests: Increase required version for pytest-multihost plugin
...
Reviewed-By: Tomas Babej <tbabej@redhat.com >
2014-12-11 07:33:03 +01:00
Tomas Babej
d0a781b9c6
hosts: Display assigned ID view by default in host-find and show commands
...
Makes ipaassignedidview a default attribute and takes care about the
conversion from the DN to the proper ID view name.
https://fedorahosted.org/freeipa/ticket/4774
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2014-12-05 15:55:38 +01:00
Tomas Babej
faec4ef9de
certs: Fix incorrect flag handling in load_cacert
...
For CA certificates that are not certificates of IPA CA, we incorrectly
set the trust flags to ",,", regardless what the actual trust_flags
parameter was passed.
Make the load_cacert method respect trust_flags and make it a required
argument.
https://fedorahosted.org/freeipa/ticket/4779
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2014-12-02 14:44:42 +00:00
Tomas Babej
792ff0c0c4
Re-initialize NSS database after otptoken plugin tests
...
OTP token tests do not properly reinitialize the NSS db, thus
making subsequent xmlrpc tests fail on SSL cert validation.
Make sure NSS db is re-initalized in the teardown method.
https://fedorahosted.org/freeipa/ticket/4748
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-11-26 13:06:35 +01:00
Tomas Babej
b168a7f2d1
specfile: Add BuildRequires for pki-base 10.2.1-0
...
https://fedorahosted.org/freeipa/ticket/4688
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-11-07 12:29:33 +01:00
Tomas Babej
b6b19e0cb8
spec: Bump SSSD requires to 1.12.2
...
https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Martin Kosek <mkosek@redhat.com >
2014-10-21 10:34:03 +02:00
Tomas Babej
1cc11ebf53
Bump 4.2 development version to 4.1.99
...
Reviewed-By: Martin Kosek <mkosek@redhat.com >
2014-10-20 13:39:51 +02:00
Tomas Babej
00457a9c10
idviews: Fix typo in upgrade handling of the Default Trust View
...
Fixed missing comma. Also removes leading spaces from the ldif,
since this is not stripped by the updater.
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2014-09-30 11:49:53 +02:00
Tomas Babej
2a230b6cc1
idviews: Create Default Trust View for upgraded servers
...
For upgraded servers with enabled AD trust support, we want to
ensure that Default Trust View entry is created.
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
51816930a6
idviews: Make sure only regular IPA objects are allowed to be overriden
...
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
902655da59
idviews: Display the list of hosts when using --all
...
Enumerating hosts is a potentially expensive operation (uses paged
search to list all the hosts the ID view applies to). Show the list
of the hosts only if explicitly asked for (or asked for --all).
Do not display with --raw, since this attribute does not exist in
LDAP.
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
47268575c9
idviews: Catch errors on unsuccessful AD object lookup when resolving object name to anchor
...
When resolving non-existent objects, domain validator will raise ValidationError. We need
to anticipate and properly handle this case.
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
dbf8d97ecf
idviews: Make sure the dict.get method is not abused for MUST attributes
...
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
13089eae52
idviews: Handle Default Trust View properly in the framework
...
Make sure that:
1.) IPA users cannot be added to the Default Trust View
2.) Default Trust View cannot be deleted or renamed
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
b9425751b4
idviews: Add Default Trust View as part of adtrustinstall
...
Add a Default Trust View, which is used by SSSD as default mapping for AD users.
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
2131187ea9
idviews: Make description optional for the ID View object
...
Description of any object should not be required.
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
1d6f591cc5
idviews: Fix casing of ID Views to be consistent
...
Replace all occurences of "ID view(s)" with "ID View(s)".
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
bba3769196
idviews: Update the referential plugin config to watch for ipaAssignedIDView
...
We need the referential plugin config to watch for changes in the ID view
objects, since hosts refer to them in ipaAssignedIDView attribute.
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
277b762d36
idviews: Add ipaOriginalUid
...
For slapi-nis plugin, we need to cache the original uid value of the user in the override
object.
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
8fb0e3a2b4
ipatests: Add xmlrpc tests for idviews plugin
...
Add coverage for the ID views and ID overrides.
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
3ff410d3a7
idviews: Resolve anchors to object names in idview-show
...
When running idview-show, users will expect a proper object name instead of a object anchor.
Make sure the anchors are resolved to the object names unless --raw option was passed.
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
c1f51cff02
idviews: Raise NotFound errors if object to override could not be found
...
If the object user wishes to override cannot be found, we should properly raise a
NotFound error.
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
961790e20a
idviews: Change format of IPA anchor to include domain
...
The old format of the IPA anchor, :IPA:<object_uuid> does not contain for the actual domain
of the object. Once IPA-IPA trusts are introduced, we will need this information to be kept
to be able to resolve the anchor.
Change the IPA anchor format to :IPA:<domain>:<object_uuid>
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
c6d50c456f
idviews: Alter idoverride methods to work with splitted objects
...
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
cbf1ad84f1
idviews: Split the idoverride commands into iduseroverride and idgroupoverride
...
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
b4a13aeea8
idviews: Split the idoverride object into iduseroverride and idgroupoverride
...
To be able to better deal with the conflicting user / group names, we split the
idoverride objects in the two types. This simplifies the implementation greatly,
as we no longer need to set proper objectclasses on each idoverride-mod operation.
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
d03b09beb4
idviews: Support specifying object names instead of raw anchors only
...
Improve usability of the ID overrides by allowing user to specify the common name of
the object he wishes to override. This is subsequently converted to the ipaOverrideAnchor,
which serves as a stable reference for the object.
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
6a798f144f
trusts: Add conversion from SID to object name
...
Since SID is often used as a unique identifier for AD objects, we need to convert
a SID to actual object name in the AD.
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
186c161ef5
idviews: Extend idview-show command to display assigned idoverrides and hosts
...
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
f3576bd94b
idviews: Add ipa idview-apply and idview-unapply commands
...
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
6e94d23a92
hostgroup: Selected PEP8 fixes for the hostgroup plugin
...
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
ce42bf282f
hostgroup: Remove redundant and star imports
...
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
936eaada89
hostgroup: Add helper that returns all members of a hostgroup
...
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
377ab0c4a6
idvies: Add managed permissions for idview and idoverride objects
...
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
b65b74890b
idviews: Create basic idview plugin structure
...
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
f48a7bb730
ipalib: PEP8 fixes for host plugin
...
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
3e2e5a4d28
ipalib: Remove redundant and star imports from host plugin
...
Also fixes incorrect error catching for UnicodeDecodeError.
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
be36525dc5
idviews: Add ipaAssignedIDVIew reference to the host object
...
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
6b14030e90
idviews: Create container for ID views under cn=accounts
...
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
16f3786d25
idviews: Add necessary schema for the ID views
...
Part of: https://fedorahosted.org/freeipa/ticket/3979
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
Reviewed-By: Petr Vobornik <pvoborni@redhat.com >
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-09-30 10:42:06 +02:00
Tomas Babej
d83af7d38d
baseldap: Properly handle the case of renaming object to the same name
...
When renaming a object to the same name, errors.EmptyModList is raised.
This is not properly handled, and can cause other modifications in the
LDAPUpdate command to be ignored.
https://fedorahosted.org/freeipa/ticket/4548
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2014-09-29 15:24:58 +02:00
Tomas Babej
1c022646d2
Set the default attributes for RootDSE
...
With 389 DS 1.3.3 upwards we can leverage the nsslapd-return-default-opattr
attribute to enumerate the list of attributes that should be returned
even if not specified explicitly. Use the behaviour to get the same attributes
returned from searches on rootDSE as in 1.3.1.
https://fedorahosted.org/freeipa/ticket/4288
Reviewed-By: Martin Kosek <mkosek@redhat.com >
2014-09-24 10:02:44 +02:00
Tomas Babej
1f8f762b84
ipalib: host_del: Extend LDAPDelete's takes_options instead of overriding
...
The host-del command did not accept --continue option, since the
takes_options was overriden and did not take the options from LDAPDelete.
Fix the behaviour.
https://fedorahosted.org/freeipa/ticket/4473
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2014-09-17 09:36:27 +02:00
Tomas Babej
fd26560a16
ipa-client-install: Do not add already configured sources to nsswitch.conf entries
...
Makes sure that any new sources added are not already present
in the entry.
https://fedorahosted.org/freeipa/ticket/4508
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-09-04 13:39:13 +02:00
Tomas Babej
6bb4eea348
ipatests: test_trust: Add test to cover lookup of trusdomains
...
Adds an integration tests that checks that all trustdomains are
able to be found by trustdomain-find command right after the
trust has been established.
Also moves some code to allow easier adding common test cases for
both POSIX and non-POSIX test classes.
https://fedorahosted.org/freeipa/ticket/4208
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-08-07 12:49:47 +02:00
Tomas Babej
e74307caa6
ipalib: idrange: Make non-implemented range types fail the validation
...
The ipa-ipa-trust and ipa-ad-winsync ID Range types were allowed to
pass the validation tests, however, they are not implemented nor
checked by the 389 server plugin.
https://fedorahosted.org/freeipa/ticket/4323
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2014-07-28 12:18:23 +02:00
Tomas Babej
3812ca03f2
baseldap: Remove redundant search from LDAPAddReverseMember and LDAPRemoveReverseMember
...
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2014-07-23 15:12:30 +02:00
Tomas Babej
b7a1401e9d
trusts: Make cn=adtrust agents sysaccount nestedgroup
...
Since recent permissions work references this entry, we need to be
able to have memberOf attributes created on this entry. Hence we
need to include the nestedgroup objectclass.
https://fedorahosted.org/freeipa/ticket/4433
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2014-07-18 10:08:04 +02:00
Tomas Babej
4254423f83
ipatests: tasks: Fix dns configuration for trusts
...
Properly configure forwarders to the AD zone with respect to
newly created ipa dnsforwardzone commands.
https://fedorahosted.org/freeipa/ticket/4401
Reviewed-By: Petr Spacek <pspacek@redhat.com >
2014-07-15 09:53:27 +02:00
Tomas Babej
e672a39637
trusts: Validate missing trust secret properly
...
Detect the situation if the user passes empty trust secret and
error out properly.
https://fedorahosted.org/freeipa/ticket/4266
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2014-07-14 16:04:58 +02:00
Tomas Babej
9bf29c270d
ipalib: Use DateTime parameter class for OTP token timestamp attributes
...
For ipatokennotbefore and ipatokennotafter attributes use DateTime
parameter class instead of Str, since these are represented as
LDAP Generalized Time in LDAP.
Reviewed-By: Jan Cholasta <jcholast@redhat.com >
2014-07-04 08:17:37 +02:00
Tomas Babej
a5bb758978
ipaldap: Override conversion of nsds5replicalast{update,init}{start,end}
...
The replication related attributes with generalized time syntax have
special behaviour implemented in 389, as follows:
In case they are explicitly requested for and not set, 0 is returned.
However, 0 is not a valid value for LDAP Generalized time. Thus
we need to add these attributes to the _SYNTAX_OVERRIDE dictionary,
overriding their conversion to datetime and converting them to
string instead, which perserves the old behaviour expected by the
replication codebase.
https://fedorahosted.org/freeipa/ticket/4350
Reviewed-By: Martin Kosek <mkosek@redhat.com >
2014-07-02 16:12:05 +02:00
Tomas Babej
ffab09a7ef
ipa-client-install: Restart nisdomain service instead of starting
...
To ensure new NIS domain name is loaded after ipa-client-install
even in case when nisdomainname service is already running, we
need to restart the service rather than starting it.
https://fedorahosted.org/freeipa/ticket/4393
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-06-30 13:58:29 +02:00
Tomas Babej
e5e42fc83a
ipaplatform: Move paths from installers to paths module
...
Part of: https://fedorahosted.org/freeipa/ticket/4052
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-26 09:22:21 +02:00
Tomas Babej
c8511d3b3b
ipaplatform: Fix misspelled path constant
...
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-25 21:07:07 +02:00
Tomas Babej
697387328b
ipaplatform: Fix build warnings
...
The newly created ipaplatform subdirectories base and fedora were
mentioned multiple times in the specfile, which produced build
warnings.
Part of: https://fedorahosted.org/freeipa/ticket/4052
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-25 21:07:07 +02:00
Tomas Babej
2a3c746dca
ipaplatform: Drop the base authconfig class
...
As authconfig is a distro-specific tool there is no incentive for
implying that other platforms should implement any authconfig
implementation of their own.
Part of: https://fedorahosted.org/freeipa/ticket/4052
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-25 21:07:07 +02:00
Tomas Babej
e099ad4583
ipaplatform: Document the platform tasks API
...
Part of: https://fedorahosted.org/freeipa/ticket/4052
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-25 21:07:06 +02:00
Tomas Babej
af4518b728
sudorule: Refactor add and remove external_post_callback
...
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-25 20:14:53 +02:00
Tomas Babej
e7969f5af5
ipatests: test_sudo: Expect root listed out if no RunAsUser available
...
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-25 20:14:52 +02:00
Tomas Babej
701f1fc8ba
ipatests: test_sudo: Do not expect enumeration of runasuser groups
...
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-25 20:14:52 +02:00
Tomas Babej
e0fd2695ca
ipatests: test_sudo: Fix assertions not assuming runasgroupcat set to ALL
...
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-25 20:14:52 +02:00
Tomas Babej
ec2050b7df
ipatests: test_sudo: Add coverage for category ALL validation
...
Makes sure sudorules behave correctly both when adding new entries
with corresponding category set to ALL, and when setting the
category to all when corresponding entries exist.
The only exception of deny commands with cmdcategory ALL is
covered as well.
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-25 20:14:52 +02:00
Tomas Babej
c50d190549
ipatests: test_sudo: Add coverage for external entries
...
Covers functionality of external entries for:
* users
* runAsUsers
* groups of RunAsUsers
* runAsGroups
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-25 20:14:52 +02:00
Tomas Babej
d537da8b8a
ipatests: test_sudo: Add tests for allowing hosts via hostmasks
...
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-25 20:14:51 +02:00
Tomas Babej
b1275c5b1c
sudorule: Enforce category ALL checks on dirsrv level
...
https://fedorahosted.org/freeipa/ticket/4341
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-25 20:14:51 +02:00
Tomas Babej
a1d6c9ab6b
sudorule: Fix the order of the parameters to have less chaotic output
...
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-25 20:14:51 +02:00
Tomas Babej
9bb88a15e0
sudorule: Make sure all the relevant attributes are checked when setting category to ALL
...
https://fedorahosted.org/freeipa/ticket/4341
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-25 20:14:51 +02:00
Tomas Babej
af2eb4d695
sudorule: Allow adding deny commands when command category set to ALL
...
https://fedorahosted.org/freeipa/ticket/4340
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-25 20:14:50 +02:00
Tomas Babej
c7da22c1e6
sudorule: Include externalhost and ipasudorunasextgroup in the list of default attributes
...
The following attributes were missing from the list of default attributes:
* externalhost
* ipasudorunasextuser
* ipasudorunasextgroup
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-25 20:14:50 +02:00
Tomas Babej
3a56b155e8
sudorule: Make sure sudoRunAsGroup is dereferencing the correct attribute
...
Makes sure we dereference the correct attribute. Also adds object class
checking.
https://fedorahosted.org/freeipa/ticket/4324
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-25 20:14:50 +02:00
Tomas Babej
9304b649a3
sudorule: Allow using external groups as groups of runAsUsers
...
Adds a new attribute ipaSudoRunAsExtUserGroup and corresponding hooks
sudorule plugin.
https://fedorahosted.org/freeipa/ticket/4263
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-25 20:14:49 +02:00
Tomas Babej
a228d7a3cb
sudorule: Allow using hostmasks for setting allowed hosts
...
Adds a new --hostmasks option to sudorule-add-host and sudorule-remove-host
commands, which allows setting a range of hosts specified by a hostmask.
https://fedorahosted.org/freeipa/ticket/4274
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-25 20:14:49 +02:00
Tomas Babej
5a1207cb6e
sudorule: PEP8 fixes in sudorule.py
...
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-25 20:14:49 +02:00
Tomas Babej
c2e6b74029
trusts: Allow reading system trust accounts by adtrust agents
...
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-06-25 15:01:52 +02:00
Tomas Babej
8f9838c7ef
trusts: Add more read attributes
...
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-06-25 15:01:52 +02:00
Tomas Babej
ef5309d376
trusts: Allow reading ipaNTSecurityIdentifier in user and group objects
...
https://fedorahosted.org/freeipa/ticket/4385
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com >
2014-06-23 15:27:33 +02:00
Tomas Babej
637ef11109
sudorule: Allow unsetting sudoorder
...
After setting sudoorder, you are unable to unset it, since the
check for uniqueness of order of sudorules is applied incorrectly.
Fix the behaviour and cover it in the test suite.
https://fedorahosted.org/freeipa/ticket/4360
Reviewed-By: Martin Kosek <mkosek@redhat.com >
2014-06-18 12:59:25 +02:00
Tomas Babej
3b4ab8b4f2
ipaplatform: Move hardcoded paths from Fedora platform files to path namespace
...
Part of: https://fedorahosted.org/freeipa/ticket/4052
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-16 19:48:21 +02:00
Tomas Babej
8a5e2a8166
ipaplatform: Contain all the tasks in the TaskNamespace
...
https://fedorahosted.org/freeipa/ticket/4052
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-16 19:48:21 +02:00
Tomas Babej
f0d0640a46
ipaplatform: Pylint fixes
...
https://fedorahosted.org/freeipa/ticket/4052
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-16 19:48:21 +02:00
Tomas Babej
c8aa00806b
ipaplatform: Link to platform module during build time
...
https://fedorahosted.org/freeipa/ticket/4052
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-16 19:48:21 +02:00
Tomas Babej
6906eed27e
ipaplatform: Let fedora path module use PathNamespace class
...
https://fedorahosted.org/freeipa/ticket/4052
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-16 19:48:20 +02:00
Tomas Babej
3bb9e1bbd5
ipaplatform: Change makefiles to accomodate for new platform package
...
https://fedorahosted.org/freeipa/ticket/4052
Reviewed-By: Petr Viktorin <pviktori@redhat.com >
2014-06-16 19:48:20 +02:00