<feed xmlns='http://www.w3.org/2005/Atom'>
<title>freeipa.git/ipalib/plugins, branch master</title>
<subtitle>Unnamed repository; edit this file 'description' to name the repository.</subtitle>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/mkosek/public_git/freeipa.git/'/>
<entry>
<title>trustdomain-find: report status of the (sub)domain</title>
<updated>2014-01-15T15:19:26+00:00</updated>
<author>
<name>Alexander Bokovoy</name>
<email>abokovoy@redhat.com</email>
</author>
<published>2014-01-15T13:42:10+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/mkosek/public_git/freeipa.git/commit/?id=0cad0fa1116cf3d23a6a44225d05e4956e3c4d95'/>
<id>0cad0fa1116cf3d23a6a44225d05e4956e3c4d95</id>
<content type='text'>
Show status of each enumerated domain

trustdomain-find shows list of domains associated with the trust.
Each domain except the trust forest root can be enabled or disabled
with the help of trustdomain-enable and trustdomain-disable commands.

https://fedorahosted.org/freeipa/ticket/4096
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Show status of each enumerated domain

trustdomain-find shows list of domains associated with the trust.
Each domain except the trust forest root can be enabled or disabled
with the help of trustdomain-enable and trustdomain-disable commands.

https://fedorahosted.org/freeipa/ticket/4096
</pre>
</div>
</content>
</entry>
<entry>
<title>trust-fetch-domains: create ranges for new child domains</title>
<updated>2014-01-15T14:43:40+00:00</updated>
<author>
<name>Alexander Bokovoy</name>
<email>abokovoy@redhat.com</email>
</author>
<published>2014-01-14T11:55:56+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/mkosek/public_git/freeipa.git/commit/?id=0e2cda9da79b58fc67434d262155e86b718125e4'/>
<id>0e2cda9da79b58fc67434d262155e86b718125e4</id>
<content type='text'>
When trust is added, we do create ranges for discovered child domains.
However, this functionality was not available through
'trust-fetch-domains' command.

Additionally, make sure non-existing trust will report proper error in
trust-fetch-domains.

https://fedorahosted.org/freeipa/ticket/4111
https://fedorahosted.org/freeipa/ticket/4104
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
When trust is added, we do create ranges for discovered child domains.
However, this functionality was not available through
'trust-fetch-domains' command.

Additionally, make sure non-existing trust will report proper error in
trust-fetch-domains.

https://fedorahosted.org/freeipa/ticket/4111
https://fedorahosted.org/freeipa/ticket/4104
</pre>
</div>
</content>
</entry>
<entry>
<title>Add missing example to sudorule</title>
<updated>2014-01-15T10:01:36+00:00</updated>
<author>
<name>Martin Kosek</name>
<email>mkosek@redhat.com</email>
</author>
<published>2014-01-15T08:31:37+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/mkosek/public_git/freeipa.git/commit/?id=7cc8c3b14b8155fe8d688ea93fd1cf375b2f7f1e'/>
<id>7cc8c3b14b8155fe8d688ea93fd1cf375b2f7f1e</id>
<content type='text'>
https://fedorahosted.org/freeipa/ticket/4090
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
https://fedorahosted.org/freeipa/ticket/4090
</pre>
</div>
</content>
</entry>
<entry>
<title>Change the way we determine if the host has a password set.</title>
<updated>2014-01-15T09:02:49+00:00</updated>
<author>
<name>Rob Crittenden</name>
<email>rcritten@redhat.com</email>
</author>
<published>2014-01-14T19:23:47+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/mkosek/public_git/freeipa.git/commit/?id=0070c0fedab5386b313908762c6b6ab2c1577489'/>
<id>0070c0fedab5386b313908762c6b6ab2c1577489</id>
<content type='text'>
When creating a host with a password we don't set a Kerberos
principal or add the Kerberos objectclasses. Those get added when the
host is enrolled. If one passed in --password= (so no password) then
we incorrectly thought the user was in fact setting a password, so the
principal and objectclasses weren't updated.

https://fedorahosted.org/freeipa/ticket/4102
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
When creating a host with a password we don't set a Kerberos
principal or add the Kerberos objectclasses. Those get added when the
host is enrolled. If one passed in --password= (so no password) then
we incorrectly thought the user was in fact setting a password, so the
principal and objectclasses weren't updated.

https://fedorahosted.org/freeipa/ticket/4102
</pre>
</div>
</content>
</entry>
<entry>
<title>Use old entry state in LDAPClient.update_entry.</title>
<updated>2014-01-10T13:41:39+00:00</updated>
<author>
<name>Jan Cholasta</name>
<email>jcholast@redhat.com</email>
</author>
<published>2013-12-10T10:13:48+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/mkosek/public_git/freeipa.git/commit/?id=24d85f15ee886d8704438045cb0e3568f59a831a'/>
<id>24d85f15ee886d8704438045cb0e3568f59a831a</id>
<content type='text'>
https://fedorahosted.org/freeipa/ticket/3488
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
https://fedorahosted.org/freeipa/ticket/3488
</pre>
</div>
</content>
</entry>
<entry>
<title>hbactest does not work for external users</title>
<updated>2014-01-10T11:55:44+00:00</updated>
<author>
<name>Martin Kosek</name>
<email>mkosek@redhat.com</email>
</author>
<published>2014-01-10T11:41:29+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/mkosek/public_git/freeipa.git/commit/?id=faa820f39e2f632d5333ea6124c9cb190e69f728'/>
<id>faa820f39e2f632d5333ea6124c9cb190e69f728</id>
<content type='text'>
Original patch for ticket #3803 implemented support to resolve SIDs
through SSSD. However, it also broke hbactest for external users. The
result of the updated external member group search must be local
non-external groups, not the external ones. Otherwise the rule is not
matched.

https://fedorahosted.org/freeipa/ticket/3803
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Original patch for ticket #3803 implemented support to resolve SIDs
through SSSD. However, it also broke hbactest for external users. The
result of the updated external member group search must be local
non-external groups, not the external ones. Otherwise the rule is not
matched.

https://fedorahosted.org/freeipa/ticket/3803
</pre>
</div>
</content>
</entry>
<entry>
<title>Allow anonymous and all permissions</title>
<updated>2014-01-07T08:56:41+00:00</updated>
<author>
<name>Petr Viktorin</name>
<email>pviktori@redhat.com</email>
</author>
<published>2013-10-29T16:01:07+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/mkosek/public_git/freeipa.git/commit/?id=4a64a1f18bd51c65bf34a13fd7541e1d6b4b75fd'/>
<id>4a64a1f18bd51c65bf34a13fd7541e1d6b4b75fd</id>
<content type='text'>
Disallow adding permissions with non-default bindtype to privileges

Ticket: https://fedorahosted.org/freeipa/ticket/4032
Design: http://www.freeipa.org/page/V3/Anonymous_and_All_permissions
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Disallow adding permissions with non-default bindtype to privileges

Ticket: https://fedorahosted.org/freeipa/ticket/4032
Design: http://www.freeipa.org/page/V3/Anonymous_and_All_permissions
</pre>
</div>
</content>
</entry>
<entry>
<title>Use new registration API in the privilege plugin</title>
<updated>2014-01-07T08:56:36+00:00</updated>
<author>
<name>Petr Viktorin</name>
<email>pviktori@redhat.com</email>
</author>
<published>2013-10-29T15:28:17+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/mkosek/public_git/freeipa.git/commit/?id=d7f5d58d352f31df144de15976bd06c5aa822210'/>
<id>d7f5d58d352f31df144de15976bd06c5aa822210</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Add OTP support to ipalib CLI</title>
<updated>2013-12-18T08:58:59+00:00</updated>
<author>
<name>Nathaniel McCallum</name>
<email>npmccallum@redhat.com</email>
</author>
<published>2013-10-01T18:26:38+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/mkosek/public_git/freeipa.git/commit/?id=397b2876e2f9bf1c5b3ad3e2874a92715ccda599'/>
<id>397b2876e2f9bf1c5b3ad3e2874a92715ccda599</id>
<content type='text'>
https://fedorahosted.org/freeipa/ticket/3368
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
https://fedorahosted.org/freeipa/ticket/3368
</pre>
</div>
</content>
</entry>
<entry>
<title>permission_find: Do not fail for ipasearchrecordslimit=-1</title>
<updated>2013-12-17T11:29:56+00:00</updated>
<author>
<name>Petr Viktorin</name>
<email>pviktori@redhat.com</email>
</author>
<published>2013-12-16T15:11:33+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/mkosek/public_git/freeipa.git/commit/?id=1a9beac1bebc7d9b0207053a7eb6d775cae590d1'/>
<id>1a9beac1bebc7d9b0207053a7eb6d775cae590d1</id>
<content type='text'>
ipasearchrecordslimit can be -1, which means unlimited.
The permission_find post_callback failed in this case in legacy
permission handling.
Do not fail in this case.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
ipasearchrecordslimit can be -1, which means unlimited.
The permission_find post_callback failed in this case in legacy
permission handling.
Do not fail in this case.
</pre>
</div>
</content>
</entry>
</feed>
