Re: F43 Change Proposal: 389_Directory_Server_3.2.0 (self-contained)

2025-06-26 Thread Alexander Bokovoy
-NAME We cannot really automate it as export of the database will require enough space to handle it. You can adjust optiosn to bdb2mdb subcommand to specify a temporary location for that but the command needs to be run by the administrators manually. -- / Alexander Bokovoy Sr. Principal Sof

Re: F43 Change Proposal: 389_Directory_Server_3.2.0 (self-contained)

2025-06-24 Thread Alexander Bokovoy
ng back at this thread, I see this: On 6/24/25 6:03 AM, Alexander Bokovoy wrote: On Аўт, 24 чэр 2025, Tomasz Torcz wrote: Some FreeIPA installations (like mine) were created long before F40 and upgraded over the years. Yes, you need to follow major RHEL IdM upgrade procedure that all RHEL u

Re: F43 Change Proposal: 389_Directory_Server_3.2.0 (self-contained)

2025-06-24 Thread Alexander Bokovoy
for non-disruptive operation. It is meant to read-only processing of existing BDB content to produce an LDIF text file to load after the backend replacement. The backend replacement also means that the database is not accessible until the change has been completed. -- / Alexander Bokovoy Sr. Principal

Re: F43 Change Proposal: 389_Directory_Server_3.2.0 (self-contained)

2025-06-24 Thread Alexander Bokovoy
On Аўт, 24 чэр 2025, Tomasz Torcz wrote: On Tue, Jun 24, 2025 at 02:03:09PM +0300, Alexander Bokovoy wrote: On Аўт, 24 чэр 2025, Tomasz Torcz wrote: > On Tue, Jun 24, 2025 at 10:40:55AM +0100, Aoife Moloney via devel-announce wrote: > > == Upgrade/compatibility impact == > > * D

Re: F43 Change Proposal: 389_Directory_Server_3.2.0 (self-contained)

2025-06-24 Thread Alexander Bokovoy
-implement nsslapd-backend-implement: bdb For new deployment you'd get 'mdb'. https://www.port389.org/docs/389ds/howto/howto-use-lmdb.html describes somewhat tersely what you can do in-place. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engi

Re: Reducing reliance on "legacy" user-group store(s) like /etc/{passwd,group}

2025-05-29 Thread Alexander Bokovoy
On Срд, 28 мая 2025, Lennart Poettering wrote: On Mi, 28.05.25 16:51, Alexander Bokovoy (aboko...@redhat.com) wrote: > > socket(AF_UNIX, SOCK_STREAM|SOCK_CLOEXEC|SOCK_NONBLOCK, 0) = 4 > > connect(4, {sa_family=AF_UNIX, sun_path="/run/systemd/userdb/io.systemd.DynamicUser"

Re: Reducing reliance on "legacy" user-group store(s) like /etc/{passwd,group}

2025-05-28 Thread Alexander Bokovoy
On Срд, 28 мая 2025, Lennart Poettering wrote: On Mi, 28.05.25 12:34, Alexander Bokovoy (aboko...@redhat.com) wrote: > a group record it will combine a specific userdb group record from one > backend with the results of a matching GetMemberships() of *all* > backends and return th

Re: Reducing reliance on "legacy" user-group store(s) like /etc/{passwd,group}

2025-05-28 Thread Alexander Bokovoy
On Срд, 28 мая 2025, Lennart Poettering wrote: On Mi, 28.05.25 09:43, Alexander Bokovoy (aboko...@redhat.com) wrote: On Аўт, 27 мая 2025, Lennart Poettering wrote: > On Di, 27.05.25 14:32, Neal Gompa (ngomp...@gmail.com) wrote: > > > The usage of the systemd user management su

Re: Reducing reliance on "legacy" user-group store(s) like /etc/{passwd,group}

2025-05-27 Thread Alexander Bokovoy
0077(admin), 1792600060(ca-kerberos-services-acl-users) abokovoy@emca:~$ userdbctl groups-of-user abokovoy No memberships. I promised you to open a bug for systemd upstream and I've been meaning to provide you an easy reproducer. Haven't done that yet, sorry. -- / Alexander Bokovoy Sr. Princip

Re: F43 change Proposal: Disabling support of building OpenSSL engines (system-wide)

2025-02-25 Thread Alexander Bokovoy
On Аўт, 25 лют 2025, Dmitry Belyavskiy wrote: On Tue, Feb 25, 2025 at 12:04 PM Peter Boy Uni wrote: > Am 25.02.2025 um 09:09 schrieb Alexander Bokovoy : >> ... >> == Detailed Description == >> We are going to build OpenSSL without engine support. Engines are not &

Re: F43 change Proposal: Disabling support of building OpenSSL engines (system-wide)

2025-02-25 Thread Alexander Bokovoy
s/list/devel-annou...@lists.fedoraproject.org Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland -- ___

Re: Intent to orphan evolution-mapi and openchange packages for f43

2025-02-10 Thread Alexander Bokovoy
Agreed. However, before you do that, we have to rebuild them one last time to avoid blocking Samba update to 4.22.0-0.1rc1. Could you please rebuild them in f43-build-side-105065 and f42-build-side-105181? -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management En

Re: [rfc] mass package change to introduce sysusers.d configs

2025-01-25 Thread Alexander Bokovoy
On Суб, 25 сту 2025, Richard W.M. Jones wrote: On Sat, Jan 25, 2025 at 11:06:43AM +0200, Alexander Bokovoy wrote: On Суб, 25 сту 2025, Zbigniew Jędrzejewski-Szmek wrote: >On Fri, Jan 24, 2025 at 01:25:18PM -0300, Rafael Jeffman wrote: >>Some of these packages might have the same

Re: [rfc] mass package change to introduce sysusers.d configs

2025-01-25 Thread Alexander Bokovoy
On Суб, 25 сту 2025, Zbigniew Jędrzejewski-Szmek wrote: On Sat, Jan 25, 2025 at 11:06:43AM +0200, Alexander Bokovoy wrote: On Суб, 25 сту 2025, Zbigniew Jędrzejewski-Szmek wrote: > - if the user shall be shared, let on of the packages define the user > and have the other packa

Re: [rfc] mass package change to introduce sysusers.d configs

2025-01-25 Thread Alexander Bokovoy
idelines List Archives: https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engine

Re: Unresponsive packager: pvoborni

2025-01-13 Thread Alexander Bokovoy
On Пан, 13 сту 2025, Pierre-Yves Chibon wrote: On Mon, Jan 13, 2025 at 11:41:07AM +0200, Alexander Bokovoy wrote: On Пан, 13 сту 2025, Pierre-Yves Chibon wrote: > Good Morning Everyone, > > We have been emailing daily the following user to notify that the email they > have set in

Re: Unresponsive packager: pvoborni

2025-01-13 Thread Alexander Bokovoy
;main admins', so we aren't going to lose those packages. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland -- ___ devel mailing list -- devel@lists.fedoraproject.org To u

Re: strawman proposal: homed directories for users

2024-10-10 Thread Alexander Bokovoy
nduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org Do not reply to spam, report it: https://pagure.io/fedora-infr

Re: strawman proposal: homed directories for users

2024-10-07 Thread Alexander Bokovoy
On Пан, 07 кас 2024, Zdenek Pytela wrote: On Mon, Oct 7, 2024 at 12:36 PM Alexander Bokovoy wrote: On Няд, 06 кас 2024, Zbigniew Jędrzejewski-Szmek wrote: >On Sat, Oct 05, 2024 at 10:53:16AM +0300, Alexander Bokovoy wrote: >> Can we move systemd-homed configuration and activa

Re: strawman proposal: homed directories for users

2024-10-07 Thread Alexander Bokovoy
On Няд, 06 кас 2024, Zbigniew Jędrzejewski-Szmek wrote: On Sat, Oct 05, 2024 at 10:53:16AM +0300, Alexander Bokovoy wrote: Can we move systemd-homed configuration and activation into something that could be explicitly enabled by the administrators? Whether this is done during installation or

Re: strawman proposal: homed directories for users

2024-10-05 Thread Alexander Bokovoy
arallel discussion by Neal). I also see it as a sole contributor to SELinux AVCs in OpenQA tests we run for FreeIPA use cases. It would be best to have it explicitly enabled by admins, similarly how authselect handles various authentication methods. -- / Alexander Bokovoy Sr. Principal Softwar

License change for iboauth2

2024-08-24 Thread Alexander Bokovoy
Hi, liboauth2 2.0.0 has changed license from AGPL-3.0-only to Apache-2.0. This is now reflected in Rawhide and will be reflected in F41. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland

Re: corporatemarketingguide

2024-07-18 Thread Alexander Bokovoy
ng in search engines so we see a lot of SEO spam trying to boost their own sites' standing against search engines. [cut off quotes to avoid referring to the SEO links] -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limite

Re: 2FA policy for provenpackagers is now active

2024-06-27 Thread Alexander Bokovoy
On Пан, 24 чэр 2024, Alexander Bokovoy wrote: On Няд, 23 чэр 2024, Neal Gompa wrote: On Sun, Jun 23, 2024 at 11:59 AM Miroslav Suchý wrote: Dne 23. 06. 24 v 11:50 dop. Leigh Scott napsal(a): it has made kerberos login much harder Can you elaborate? I use Kerberos login without a problem

Re: 2FA policy for provenpackagers is now active

2024-06-25 Thread Alexander Bokovoy
events you from using 'classic OTP codes' either. It is what enabled now as 'OTP' and there is no way to find out whether you are using a hardware token or a software one for TOTP/HOTP. So this is not changing at all. -- / Alexander Bokovoy Sr. Principal Software Engineer Securit

Re: Following up on: Three steps we could take to make supply chain attacks a bit harder

2024-06-24 Thread Alexander Bokovoy
interesting?  Should I continue working on it? Yes, it is definitely an interesting test. Thank you for investing your time and resources into this. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland -- _

Re: 2FA policy for provenpackagers is now active

2024-06-24 Thread Alexander Bokovoy
be able to handle FIDO2 passkey authentication as well. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland -- ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscri

Re: 2FA policy for provenpackagers is now active

2024-06-24 Thread Alexander Bokovoy
ros as well. In practice I have to re-login manually to Fedora services once a week, pretty much. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland -- ___ devel mailin

Re: 2FA policy for provenpackagers is now active

2024-06-24 Thread Alexander Bokovoy
s/kerberos-parameters/kerberos-parameters.xhtml#pre-authentication [3] https://sssd.io/design-pages/passkey_kerberos.html [4] https://freeipa.readthedocs.io/en/latest/designs/external-idp/external-idp.html [5] https://freeipa.readthedocs.io/en/latest/designs/passkeys.html -- / Alexander

Re: 2FA policy for provenpackagers is now active

2024-06-24 Thread Alexander Bokovoy
On Пан, 24 чэр 2024, Vitaly Zaitsev via devel wrote: On 24/06/2024 10:45, Alexander Bokovoy wrote: Can you point me to a discussion where it says it is impossible to implement that in GOA? FAS (kinit) should request the OTP code in a separate prompt. This is not how it works in Kerberos

Re: 2FA policy for provenpackagers is now active

2024-06-24 Thread Alexander Bokovoy
ould change now? I have a work in progress branch https://gitlab.gnome.org/abbra/gnome-online-accounts/-/tree/add-fast-channel-wrap?ref_type=heads that attempts to implement use of Anonymous PKINIT for the FAST channel in GOA. I am talking to Ray Strode to get this further upstream. -- / Alexander Boko

Re: New Fedora Planet

2024-05-20 Thread Alexander Bokovoy
d=True) and that should be enough. Overall, this looks like a two-line change across two projects. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland -- ___ devel m

Re: F41 Change Proposal: Pytest 8 (self-contained)

2024-04-07 Thread Alexander Bokovoy
ytest plugins (multihost, sourceorder), also add our own extensions. I filed an upstream issue to track Pytest 8: https://pagure.io/freeipa/issue/9571 -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Fi

Re: Three steps we could take to make supply chain attacks a bit harder

2024-03-31 Thread Alexander Bokovoy
ady implement support for all these methods in a proper way, we might reuse those to improve Fedora user experience. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland -- ___

Re: F41 Change Proposal: Disable openSSL Engine Support (system-wide)

2024-03-20 Thread Alexander Bokovoy
bmit support for provider vs engine to Linux kernel upstream). - signing of shim, grub2, fwupd, and the kernel in the build system - mokutil mokutil does not use ENGINE_* APIs at all. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineerin

Re: F40 Change Proposal: 389_Directory_Server_3.0.0 (System-Wide)

2023-11-27 Thread Alexander Bokovoy
st_guidelines List Archives: https://lists.fedoraproject.org/archives/list/devel-annou...@lists.fedoraproject.org Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management E

Re: How to handle updates with large python dependency chains?

2023-05-02 Thread Alexander Bokovoy
min4-7.0/builds/ -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org

Re: Orphaning despite having maintainers?

2023-04-27 Thread Alexander Bokovoy
On to, 27 huhti 2023, Alexander Bokovoy wrote: On ke, 26 huhti 2023, Gary Buhrmaster wrote: On Wed, Apr 26, 2023 at 9:04 AM Alexander Bokovoy wrote: Hi, This morning I woke up to find that packages I maintain were orphaned out of blue. Nobody contacted the maintainers, nobody raised any

Re: Orphaning despite having maintainers?

2023-04-27 Thread Alexander Bokovoy
On to, 27 huhti 2023, Miro Hrončok wrote: On 27. 04. 23 12:19, Alexander Bokovoy wrote: The graph in the packager dashboard is showing that resteasy directly depends on java-1.8.0-openjdk which is not true. resteasy (maintained by: cfu, cipherboy, ckelley, edewata, jmagne, mfargett, mharmsen

Re: Orphaning despite having maintainers?

2023-04-27 Thread Alexander Bokovoy
On to, 27 huhti 2023, Stephen Smoogen wrote: On Wed, 26 Apr 2023 at 22:32, Alexander Bokovoy wrote: On ke, 26 huhti 2023, Kevin Fenzi wrote: >On Wed, Apr 26, 2023 at 07:23:10PM +0100, Chris Kelley wrote: >> One thing I still don't understand is why all of our java packages

Re: Orphaning despite having maintainers?

2023-04-26 Thread Alexander Bokovoy
= Install 19 Packages Total download size: 1.6 M Installed size: 2.4 M Is this ok [y/N]: -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland ___ de

Re: Orphaning despite having maintainers?

2023-04-26 Thread Alexander Bokovoy
On ke, 26 huhti 2023, Gary Buhrmaster wrote: On Wed, Apr 26, 2023 at 9:04 AM Alexander Bokovoy wrote: Hi, This morning I woke up to find that packages I maintain were orphaned out of blue. Nobody contacted the maintainers, nobody raised any tickets to releng, as far as I can see. Yet, releng

Orphaning despite having maintainers?

2023-04-26 Thread Alexander Bokovoy
raised the issue https://pagure.io/releng/issue/11406 -- if you also experienced a similar orphaning, please add your data. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland

Re: It’s time to transform the Fedora devel list into something new

2023-04-20 Thread Alexander Bokovoy
tails for what the thread claims to happen or never got any follow-up on the thread to my comments. This is an experience I want to avoid. If this is what Matthew is proposing a Fedora development discussions to be, then sorry, this is not an improvement. -- / Alexander Bokovoy Sr. Principal

Re: Certbot 2.2.0 Update

2023-03-21 Thread Alexander Bokovoy
y how the tests will behave against 2.2.0. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send

Re: Regular crash of the internal DirectoryServer389 replication

2022-11-18 Thread Alexander Bokovoy
ocs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_

Re: FontAwesome 6

2022-11-05 Thread Alexander Bokovoy
are/pki/acme/webapps/acme/css/assets/fonts/webfonts/fa-solid-900.woff dogtag-pki-acme-11.1.0-1.fc36.noarch # rpm -qf /usr/share/pki/common-ui/fonts/fontawesome-webfont.woff dogtag-pki-theme-11.1.0-1.fc36.noarch -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management

Re: Inactive packagers to be removed after the F37 release

2022-10-28 Thread Alexander Bokovoy
rt, there are now two articles: Part 1, where I am talking about Fedora infrastructure aspects: https://vda.li/en/posts/2022/10/28/FreeIPA-Authentication-Improvements-and-Fedora-Infra/ Part 2, where FreeIPA-specific improvements and details discussed: https://vda.li/en/posts/2022/10/28/FreeIPA-Authen

Re: Inactive packagers to be removed after the F37 release

2022-09-16 Thread Alexander Bokovoy
On to, 15 syys 2022, Kevin Fenzi wrote: On Thu, Sep 15, 2022 at 09:26:36AM +0300, Alexander Bokovoy wrote: Proven packagers seem to be a fair category to address. Also packagers responsible for security-related bits of the distribution. Compilers? Well, as others noted in this thread, any

Re: Inactive packagers to be removed after the F37 release

2022-09-14 Thread Alexander Bokovoy
On ke, 14 syys 2022, Kevin Fenzi wrote: On Wed, Sep 14, 2022 at 05:47:46PM +0300, Alexander Bokovoy wrote: On ke, 14 syys 2022, Stephen Smoogen wrote: > On Wed, 14 Sept 2022 at 05:28, Alexander Bokovoy > wrote: > > > > > Sadly, it cannot be just 'any' certif

Re: Inactive packagers to be removed after the F37 release

2022-09-14 Thread Alexander Bokovoy
On ke, 14 syys 2022, Stephen Smoogen wrote: On Wed, 14 Sept 2022 at 05:28, Alexander Bokovoy wrote: Sadly, it cannot be just 'any' certificate, it has to be issued by a certificate authority that is trusted by the KDC as well. For example, by FreeIPA CA which is already ran by

Re: Inactive packagers to be removed after the F37 release

2022-09-14 Thread Alexander Bokovoy
.org Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland ___ devel mailing list -- devel@lists.

Re: Inactive packagers to be removed after the F37 release

2022-09-06 Thread Alexander Bokovoy
2 virtual authenticator -- see [2] for example of integrating with QEMU. This is far from being complete and user-friendly. [1] https://www.token2.eu/shop/product/token2-t2f2-fido2-and-u2f-security-key [2] https://github.com/google/OpenSK/issues/485 -- / Alexander Bokovoy Sr.

Re: Inactive packagers to be removed after the F37 release

2022-09-05 Thread Alexander Bokovoy
On ma, 05 syys 2022, Vitaly Zaitsev via devel wrote: On 05/09/2022 17:05, Alexander Bokovoy wrote: The site blocks access from outside of Russia. Yes, you need RU proxy to read the original documents. But you can use your favorite search engine to find "FSB notification" articles i

Re: Inactive packagers to be removed after the F37 release

2022-09-05 Thread Alexander Bokovoy
oogle Translate): - http://clsz.fsb.ru/clsz/in-out.htm - http://clsz.fsb.ru/clsz/notif.htm The site blocks access from outside of Russia. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland __

Re: Inactive packagers to be removed after the F37 release

2022-09-04 Thread Alexander Bokovoy
deployed or going to be eventually deployed in a containerized way, then probably focusing on another feature rich open source IdP could be a better option. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland __

Re: Thoughts welcome: interface between automated test gating and the "critical path"

2022-08-30 Thread Alexander Bokovoy
On ti, 30 elo 2022, Adam Williamson wrote: On Tue, 2022-08-30 at 09:39 +0300, Alexander Bokovoy wrote: On ma, 29 elo 2022, Adam Williamson wrote: > On Tue, 2022-08-30 at 00:32 -0400, DJ Delorie wrote: > > It sounds to me like the problem is "how do we best use the available >

Re: Thoughts welcome: interface between automated test gating and the "critical path"

2022-08-29 Thread Alexander Bokovoy
er earlier but don't discourage maintainers from participating in a joint development. Perhaps, The Fedora Packager Dashboard could be extended to pick up results of tests relevant to your packages and display them together? This way FreeIPA maintainers can see an overview of all tests related

Re: Users with commit rights in src.fp.o but no more in packager group

2022-08-25 Thread Alexander Bokovoy
*not* require the account to be listed in maintainers or to have commit rights. Same for ipa-maint account. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland ___ devel mailing

Re: liburing update

2022-08-23 Thread Alexander Bokovoy
7:1 end of changes of 'liburing.so.2.0.0'=== I guess we can ignore the added functions as those should always be safe. The changed function __io_uring_get_cqe is documented in the header as: /* * Helper for the peek/wait single cqe functions. Export

slapi-nis license change

2022-08-20 Thread Alexander Bokovoy
server which moved to GPLv3-or-later already for some years. The relicensing was agreed with Red Hat legal for quite some time already, since Red Hat is the only copyright owner. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited

Re: F37 proposal: BIND 9.18 (Self-Contained Change proposal)

2022-07-16 Thread Alexander Bokovoy
oject.org/archives/list/devel@lists.fedoraproject.org > Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure > -- -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland ___

Re: Landing a larger-than-release change (distrusting SHA-1 signatures)

2022-03-09 Thread Alexander Bokovoy
On ke, 09 maalis 2022, Daniel P. Berrangé wrote: On Wed, Mar 09, 2022 at 02:32:48PM +0200, Alexander Bokovoy wrote: On ke, 09 maalis 2022, Daniel P. Berrangé wrote: > On Wed, Mar 09, 2022 at 10:46:21AM +0100, Alexander Sosedkin wrote: > > On Wed, Mar 9, 2022 at 10:20 AM Daniel P.

Re: Landing a larger-than-release change (distrusting SHA-1 signatures)

2022-03-09 Thread Alexander Bokovoy
lly, Kerberos is one of those protocols and MIT Kerberos is one of those implementations which currently forced to use SHA-1 due to interoperability issues and also due to compliance with RFCs. In the context of Fedora development, for example, use of Anonymous PKINIT requires usage of SHA-1 in PKINIT p

Re: Preventing account takeovers through expired domains

2022-02-21 Thread Alexander Bokovoy
onduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure -- / Alexander Bokovo

Re: Package notes issues with python wheel building

2022-02-02 Thread Alexander Bokovoy
https://bugzilla.redhat.com/show_bug.cgi?id=2048909 I guess we need to fix krb5 this way too. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland ___ devel mailing list -- devel@lists.fedoraproject.o

Re: Orphaned packages looking for new maintainers​​​

2021-12-22 Thread Alexander Bokovoy
On ke, 22 joulu 2021, Alexander Bokovoy wrote: On ke, 22 joulu 2021, Mat Booth wrote: On Tue, 21 Dec 2021 at 14:35, Alexander Bokovoy wrote: I picked up wsdl4j to prevent actions which would lead to tomcat, Dogtag, and FreeIPA being orphaned over Christmas break. Have you tried building

Re: Orphaned packages looking for new maintainers​​​

2021-12-22 Thread Alexander Bokovoy
On ke, 22 joulu 2021, Mat Booth wrote: On Tue, 21 Dec 2021 at 14:35, Alexander Bokovoy wrote: I picked up wsdl4j to prevent actions which would lead to tomcat, Dogtag, and FreeIPA being orphaned over Christmas break. Have you tried building tomcat without wsdl? I can't see where i

Re: Orphaned packages looking for new maintainers​​​

2021-12-21 Thread Alexander Bokovoy
On ti, 21 joulu 2021, Miro Hrončok wrote: On 21. 12. 21 15:33, Alexander Bokovoy wrote: wsdl4j   akurtakov, mizdebsk, orphan   2 weeks ago I picked up wsdl4j to prevent actions which would lead to tomcat, Dogtag, and FreeIPA being orphaned over Christmas break

Re: Orphaned packages looking for new maintainers​​​

2021-12-21 Thread Alexander Bokovoy
ripts/find_unblocked_orphans.py -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to dev

Re: F36 Change: Make Rescue Mode Work With Locked Root (System-Wide Change proposal)

2021-12-08 Thread Alexander Bokovoy
we have group merging in effect in glibc, please do not treat a user present in wheel group but missing in /etc/shadow as something extra-ordinary. It is a normal situation when you have users in the centralized identity store like FreeIPA or Samba AD. -- / Alexander Bokovoy Sr. Principal Software

Re: F36 Change: Retire the NIS(+) user-space utility programs (System-Wide Change proposal)

2021-10-21 Thread Alexander Bokovoy
uct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure -- / Alexander Bokovoy Sr. Principal Softwa

Re: [RFC] Remove supoort for NIS(+) from PAM

2021-10-07 Thread Alexander Bokovoy
as. Ipsilon would be the server-side aspect of it, we don't have any client-side integration (sssd, gdm/sddm, etc.) We are working on that part for SSSD and FreeIPA. Not production ready yet but aim to have something testable later this year. In a prototype we have it is possible to authenticate

Re: [RFC] Remove supoort for NIS(+) from PAM

2021-10-07 Thread Alexander Bokovoy
nfigurations is even less secure than relying on NTLM in SMB protocol. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland ___ devel mailing list -- devel@lists.fedoraproject.org To uns

Re: [RFC] Remove supoort for NIS(+) from PAM

2021-10-06 Thread Alexander Bokovoy
provides NIS support. It is going to be supported in RHEL 9 and I'd like to keep NIS part supported in Fedora as well for some time. This only requires existence of libnsl2. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finl

Re: Fedora-Rawhide-20211001.n.0 compose check report

2021-10-02 Thread Alexander Bokovoy
understanding is that this is an intermediate step which should have better be done in a sidetag. So we can expect broken FreeIPA in Rawhide until this issue is solved by Dogtag team. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited

Re: [RFC] Remove supoort for NIS(+) from PAM

2021-10-01 Thread Alexander Bokovoy
idering to remove it completely in future as well. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send

Re: [Heads-up] Introduction of OpenSSL 3.0.0 in F36

2021-09-17 Thread Alexander Bokovoy
tracker: https://pagure.io/fedora-ci/general/issues """ How on earth are we supposed to figure out what annocheck doesn't like? There's 185328 bytes of "Standard Output" that follows… Zbyszek ___________ devel mailing list -- devel@lists.fedor

Re: Python libraries problem with F34

2021-07-05 Thread Alexander Bokovoy
to use pip, make sure you are doing so within a virtual environment, e.g. with venv or similar constructs. This ensures whatever was installed is self-consistent with regards to the source where it came from. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Managemen

Re: F35 Change: Python Packaging Guidelines overhaul (System-Wide Change proposal)

2021-06-15 Thread Alexander Bokovoy
On ti, 15 kesä 2021, Petr Viktorin wrote: On 14. 06. 21 20:09, Alexander Bokovoy wrote: On ma, 14 kesä 2021, Ben Cotton wrote: [...] PyPI Parity Machine-readable metadata (''distribution'' names in dist-info directories on disk and the corresponding python3.Xdi

Re: [HEADS UP] Fedora 35 Python 3.10 rebuilds have started in a side tag

2021-06-14 Thread Alexander Bokovoy
On ma, 14 kesä 2021, Adam Williamson wrote: On Mon, 2021-06-14 at 15:40 +0300, Alexander Bokovoy wrote: > > The fact that this blocks FreeIPA was indeed only discovered by chance > while the side tag rebuild was already in progress (and about to be > merged). I wonder haw can we

Re: F35 Change: Python Packaging Guidelines overhaul (System-Wide Change proposal)

2021-06-14 Thread Alexander Bokovoy
g practices and better integrate with the wider Python ecosystem (specifically, the Python Package Index). -- Ben Cotton He / Him / His Fedora Program Manager Red Hat TZ=America/Indiana/Indianapolis ___ devel mailing list -- devel@lists.fedoraproject.org

Re: F35 Change: Python Packaging Guidelines overhaul (System-Wide Change proposal)

2021-06-14 Thread Alexander Bokovoy
esting at the Bodhi update time for a reason. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-

Re: [HEADS UP] Fedora 35 Python 3.10 rebuilds have started in a side tag

2021-06-14 Thread Alexander Bokovoy
On ma, 14 kesä 2021, Miro Hrončok wrote: On 14. 06. 21 13:40, Alexander Bokovoy wrote: On ma, 14 kesä 2021, Victor Stinner wrote: Congrats, that's amazing! :-) Let's fix remaining broken packages! Right now the biggest broken package to us (FreeIPA) is mod_wsgi which relied on Py

Re: [HEADS UP] Fedora 35 Python 3.10 rebuilds have started in a side tag

2021-06-14 Thread Alexander Bokovoy
___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/

Re: Tomcat Package Changes in Rawhide

2021-06-07 Thread Alexander Bokovoy
whide would be in Rawhide compose, that test should succeed. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland ___ devel mailing list -- devel@lists.fedoraproject.org To unsu

Re: The Javapocalypse is Monday

2021-06-05 Thread Alexander Bokovoy
edora, that makes a need for unified delivery approach prioritized and any deviations are much harder to handle. [1] https://github.com/dogtagpki/pki/issues/3553 [2] https://fedoraproject.org/wiki/KojiMavenSupport [3] https://fedoraproject.org/wiki/Talk:KojiMavenSupport -- / Alexander Bokovoy Sr. Pr

Re: Kerberos and Fedora's 2FA UX

2021-04-24 Thread Alexander Bokovoy
On la, 24 huhti 2021, Kevin Fenzi wrote: On Sat, Apr 24, 2021 at 12:12:19PM +0300, Alexander Bokovoy wrote: On Пт, 23 апр 2021, Kevin Fenzi wrote: > On Fri, Apr 23, 2021 at 07:40:14AM +0200, Miroslav Suchý wrote: > > I have been using 2FA with the new Fedora Account system and

Re: Kerberos and Fedora's 2FA UX

2021-04-24 Thread Alexander Bokovoy
am typically issuing Fedora tickets for a week-long period, so I only need to run the kinit sequence once a week and then SSSD/GNOME Accounts tools are refreshing it every 8 hours automatically. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red

Re: Fedora Account Migration & Production Deployment Update: COMPLETE!

2021-04-02 Thread Alexander Bokovoy
On to, 01 huhti 2021, Kevin Fenzi wrote: On Thu, Apr 01, 2021 at 01:50:40PM +0300, Alexander Bokovoy wrote: This split of fields in FreeIPA Web UI exists since FreeIPA 4.0 which was part of early RHEL 7 deliveries (the code for separate OTP field was added in 2014). There is nothing specific

Re: Fedora Account Migration & Production Deployment Update: COMPLETE!

2021-04-01 Thread Alexander Bokovoy
On ti, 30 maalis 2021, Kevin Fenzi wrote: On Tue, Mar 30, 2021 at 09:30:33AM +0300, Alexander Bokovoy wrote: Could you please explain where you want to do it? Noggin (Fedora Accounts app) does handle the login itself, not FreeIPA. In the context of what Fedora contributors interact with

Re: Disable bodhi auto-update creation on rawhide?

2021-03-30 Thread Alexander Bokovoy
you'd need to create a bodhi update yourself for this side-tag. This gives you back all the control but with an overhead of a side-tag. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limite

Re: Fedora Account Migration & Production Deployment Update: COMPLETE!

2021-03-29 Thread Alexander Bokovoy
method that would still be secure against others. In FreeIPA nobody, including administrators, is able to discover the user's password from a hashed form. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland ___

Re: Proposal to fail builds if RPATH is found in Fedora 35

2021-03-26 Thread Alexander Bokovoy
Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org Do not reply to spam on the list, report it: https://pagure

Re: Is Pagure openid login broken?

2021-03-25 Thread Alexander Bokovoy
ose it's still a bug so thanks for filing one. If I understand it correctly, you caught a state in the middle of upgrades. Ipsilon IdP was actually reconfigured to use FreeIPA-provided data and some of attribute mappings did change which required modifications. -- / Alexander Bokovoy Sr.

Re: Non-responsive maintainer: kir

2021-03-16 Thread Alexander Bokovoy
account is mandatory per: https://fedoraproject.org/wiki/Join_the_package_collection_maintainers#Create_a_Bugzilla_Account kir is maintainer of rpms/runc Does anyone know how to contact kir? Yes, I asked Kir to respond. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity

Re: systemd-resolved fallback DNS servers: usability vs. GDPR

2021-03-02 Thread Alexander Bokovoy
On ti, 02 maalis 2021, Zbigniew Jędrzejewski-Szmek wrote: On Tue, Mar 02, 2021 at 11:29:21AM +0200, Alexander Bokovoy wrote: On ma, 01 maalis 2021, Lennart Poettering wrote: >On Fr, 26.02.21 21:01, Alexander Bokovoy (aboko...@redhat.com) wrote: > >>> 1. Dots (".") fo

Re: systemd-resolved fallback DNS servers: usability vs. GDPR

2021-03-02 Thread Alexander Bokovoy
On ti, 02 maalis 2021, Ed Greshko wrote: On 02/03/2021 06:03, Lennart Poettering wrote: On Fr, 26.02.21 21:01, Alexander Bokovoy (aboko...@redhat.com) wrote: Digital Ocean updates pushed with cloud-init use. Cloud-init does not have any native support for systemd-resolved. It means it writes

Re: systemd-resolved fallback DNS servers: usability vs. GDPR

2021-03-02 Thread Alexander Bokovoy
On ma, 01 maalis 2021, Lennart Poettering wrote: On Fr, 26.02.21 21:01, Alexander Bokovoy (aboko...@redhat.com) wrote: > 1. Dots (".") for separating IPV4 address bytes > 2. Colons (":") for separating IPv6 address parts, as well as separating > port numbers fro

Re: systemd-resolved fallback DNS servers: usability vs. GDPR

2021-02-26 Thread Alexander Bokovoy
On pe, 26 helmi 2021, Lennart Poettering wrote: On Mi, 24.02.21 22:08, Alexander Bokovoy (aboko...@redhat.com) wrote: I think one of the issues reported in the discussion you mention was that systemd-resolved considered invalid a DNS= line where addresses were separated by a comma rather than

  1   2   3   >