[Freeipa-devel] [PATCH 0045] Enforce host existence only where needed in ipa-replica-manage

Tomas Babej tbabej at redhat.com
Tue Apr 30 12:32:30 UTC 2013


On 04/11/2013 09:57 PM, Rob Crittenden wrote:
> Tomas Babej wrote:
>> Hi,
>>
>> In ipa-replica-manage commands, we enforce that hostnames we work
>> with are resolvable. However, this caused errors while deleting
>> or disconnecting a ipa / winsync replica, if that replica was down
>> and authoritative server for itself.
>>
>> https://fedorahosted.org/freeipa/ticket/3524
>>
>> Tomas
>
> I'm not sure this is going to do the right thing either. A lot of 
> these commands take the an argument as the remote master to run things 
> on, so we'd really only be validating one of the names. Not sure how 
> that helps us.
>
Actually, the patch tried to adress that. I carefully reviewed the 
effort, now we should be consistent in validating all the names.

> What if we honor the --force flag for DNS lookup failures instead? Or, 
> since that could override it and do other things, a --no-lookup flag 
> perhaps?
>
> rob

I added a --no-lookup flag for ipa-replica-manage that disables host 
existence check.

Sending both patches rebased.

Tomas
-------------- next part --------------
A non-text attachment was scrubbed...
Name: freeipa-tbabej-0046-2-Handle-connection-timeout-in-ipa-replica-manage.patch
Type: text/x-patch
Size: 2037 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/freeipa-devel/attachments/20130430/15052ab4/attachment.bin>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: freeipa-tbabej-0045-2-Enforce-host-existence-only-where-needed-in-ipa-repl.patch
Type: text/x-patch
Size: 10114 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/freeipa-devel/attachments/20130430/15052ab4/attachment-0001.bin>


More information about the Freeipa-devel mailing list