[Freeipa-devel] [PATCH] 068 Connection check program for replica installation

Martin Kosek mkosek at redhat.com
Tue May 24 08:14:44 UTC 2011


On Mon, 2011-05-23 at 16:41 -0400, Rob Crittenden wrote:
> Martin Kosek wrote:
> > This is a first version of connection checking program for replica
> > installation. See patch for program purpose description. Currently,
> > there is no man pages for the program.
> >
> > Note to Simo and Rob: I use password for logging as admin. Btw would it
> > be safe to have an admin keytab in the replica file? Replica file
> > contents are lying freely in /tmp after the replica installation.
> >
> > Martin
> 
> nack, you aren't including the new binary in the spec.

Oh, thanks for this one.

> 
> You should also:
> 
> - set KRB5CCNAME to a temporary ccache and remove that when the install 
> exists (successful or not)

Done.

> - remove the temporary krb5.conf you create

Done.

> - be a bit more explicit what we are doing, at least more than "Run 
> connection check to master".

Actually, I am if you run the new script separately. I removed "--quiet"
parameter passed to the script in ipa-replica-install so that it is more
verbose. Plus, I improved texts sent to the user.

> - yes, we should remove the replica file contents

I enhanced ipa-replica-install to do that.

Martin

-------------- next part --------------
A non-text attachment was scrubbed...
Name: freeipa-mkosek-068-2-connection-check-program-for-replica-installation.patch
Type: text/x-patch
Size: 24325 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/freeipa-devel/attachments/20110524/9f4d4fd0/attachment.bin>


More information about the Freeipa-devel mailing list