URL: https://github.com/freeipa/freeipa/pull/5123
Author: rcritten
Title: #5123: [Backport][ipa-4-8] test_smb: mark test_smb_service_s4u2self as xfail for fed31
Action: opened
PR body:
"""
This PR was opened automatically because PR #5118 was pushed to master and backport to ipa-4-8 is required.
"""
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/5123/head:pr5123
git checkout pr5123
URL: https://github.com/freeipa/freeipa/pull/5111
Author: tiran
Title: #5111: Don't create DS SSCA and self-signed cert
Action: opened
PR body:
"""
Instruct lib389 to not create its self-signed CA and temporary
self-signed certificate. FreeIPA uses local connections and Unix socket
for bootstrapping.
Fixes: https://pagure.io/freeipa/issue/8502
Signed-off-by: Christian Heimes <cheimes(a)redhat.com>
"""
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/5111/head:pr5111
git checkout pr5111
URL: https://github.com/freeipa/freeipa/pull/5118
Author: flo-renaud
Title: #5118: test_smb: mark test_smb_service_s4u2self as xfail for fed31
Action: opened
PR body:
"""
The test test_integration/test_smb.py::TestSMB::test_smb_service_s4u2self
is expected to fail in Fedora <= 31 as it requires krb >= 1.18
that is shipped from fedora 32 only
Mark the test as conditionally failing depending on the fedora version.
Fixes: https://pagure.io/freeipa/issue/8505
"""
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/5118/head:pr5118
git checkout pr5118
URL: https://github.com/freeipa/freeipa/pull/5121
Author: rcritten
Title: #5121: [Backport][ipa-4-8] Duplicate CA CRT: ignore expected cert
Action: opened
PR body:
"""
This PR was opened automatically because PR #5114 was pushed to master and backport to ipa-4-8 is required.
"""
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/5121/head:pr5121
git checkout pr5121
URL: https://github.com/freeipa/freeipa/pull/5114
Author: tiran
Title: #5114: Duplicate CA CRT: ignore expected cert
Action: opened
PR body:
"""
When search for duplicate CA certs ignore the one expected entry.
Related: https://pagure.io/freeipa/issue/7125
Signed-off-by: Christian Heimes <cheimes(a)redhat.com>
"""
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/5114/head:pr5114
git checkout pr5114
URL: https://github.com/freeipa/freeipa/pull/5039
Author: cipherboy
Title: #5039: Add dependency on pki-acme
Action: opened
PR body:
"""
With the merging of #4723, pki-acme should be added as a dependency of
IPA. Note that this is only necessary on PKI >= 10.10 and shouldn't be
backported to RHEL 8.3 as the subpackage doesn't exist there.
Related: https://github.com/dogtagpki/pki/pull/513
`Signed-off-by: Alexander Scheel <ascheel(a)redhat.com>`
"""
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/5039/head:pr5039
git checkout pr5039
URL: https://github.com/freeipa/freeipa/pull/5117
Author: frasertweedale
Title: #5117: spec: require pki-acme if pki-ca >= 10.10
Action: opened
PR body:
"""
We can use conditional dependencies (described at [1]) to require
the pki-acme package if pki-ca >= 10.10.0 (the version at which the
ACME service was separated to a subpackage).
[1] https://rpm.org/user_doc/boolean_dependencies.html
I have tested this with repos having only pki-10.9.x (and therefore
no pki-acme package), and dnf is happy. I have also testing package
installation with pki-10.10 packages installed, but /without/
pki-acme installed. pki-acme was seen as a missing dependency and
installed alongside the freeipa packages. This change seems to
satisfy all the scenarios.
Related: https://github.com/dogtagpki/pki/pull/513
"""
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/5117/head:pr5117
git checkout pr5117
URL: https://github.com/freeipa/freeipa/pull/5120
Author: fcami
Title: #5120: [Test PR] ipatests: enhance TestSubCAkeyReplication
Action: opened
PR body:
"""
enhance the test suite so that it covers:
- deleting subCAs (disabling them first)
- checking what happens when creating a dozen+ subCAs at a time
- adding a subCA that already exists and expect failure
Related: https://pagure.io/freeipa/issue/8488
Signed-off-by: François Cami <fcami(a)redhat.com>
"""
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/5120/head:pr5120
git checkout pr5120
URL: https://github.com/freeipa/freeipa/pull/5116
Author: tiran
Title: #5116: Add timings to install logs
Action: opened
PR body:
"""
The logging manager now adds timings for installation steps to the
installer logs. The information can be extracted and dumped to a CSV
file with a simple grep command:
grep -Po 'TIMING: \K.*' /var/log/ipaserver.log > ipaserver.csv
Signed-off-by: Christian Heimes <cheimes(a)redhat.com>
"""
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/5116/head:pr5116
git checkout pr5116
URL: https://github.com/freeipa/freeipa/pull/5115
Author: fcami
Title: #5115: [Backport][ipa-4-8] dogtaginstance.py: add --debug to pkispawn
Action: opened
PR body:
"""
MANUAL cherry-pick of https://github.com/freeipa/freeipa/pull/5113
Since commits:
dogtagpki/pki@0102d83
dogtagpki/pki@de21755
pkispawn will not honor the pki_log_level configuration item.
All 10.9 Dogtag versions have these commits.
This affects FreeIPA in that it makes debugging Dogtag installation issues next
to impossible.
Adding --debug to the pkispawn CLI is required to revert to the previous
behavior.
Fixes: https://pagure.io/freeipa/issue/8503
"""
To pull the PR as Git branch:
git remote add ghfreeipa https://github.com/freeipa/freeipa
git fetch ghfreeipa pull/5115/head:pr5115
git checkout pr5115