<html>
<head>
<meta content="text/html; charset=windows-1252"
http-equiv="Content-Type">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<br>
<br>
<div class="moz-cite-prefix">On 09/24/2015 02:49 PM, Milan Kubík
wrote:<br>
</div>
<blockquote cite="mid:5603F13E.4060805@redhat.com" type="cite">Hi
all,
<br>
<br>
an update for CA ACL tests!
<br>
<br>
I, with help from M. Babinsky, managed to find a way how to change
the identity during acceptance cest run, which allows
<br>
to test CA ACLs (and perhaps other areas with some form of access
controll).
<br>
<br>
This allowed me to write a test for CA ACLs and certificate
profiles that checks if the ACL/profile is being used and
enforced.
<br>
The first several tests are based on Fraser's blogpost using SMIME
profile [1].
<br>
<br>
The master and ipa-4-2 branches diverged a bit, so I had to change
two commits when rebasing to ipa-4-2 branch.
<br>
<br>
Commits should be applied in the order (including rebased patches
I sent in an earlier email):
<br>
<br>
master:
<br>
* 12 - 17
<br>
<br>
ipa-4-2:
<br>
* 18, 13 - 15, 19, 17
<br>
<br>
For convenience:
<br>
patches on top of master:
<a class="moz-txt-link-freetext" href="https://github.com/apophys/freeipa/tree/acl-profile-functional">https://github.com/apophys/freeipa/tree/acl-profile-functional</a>
<br>
patches on top of ipa-4-2:
<a class="moz-txt-link-freetext" href="https://github.com/apophys/freeipa/tree/acl-42">https://github.com/apophys/freeipa/tree/acl-42</a>
<br>
<br>
<br>
[1]:
<a class="moz-txt-link-freetext" href="https://blog-ftweedal.rhcloud.com/2015/08/user-certificates-and-custom-profiles-with-freeipa-4-2/">https://blog-ftweedal.rhcloud.com/2015/08/user-certificates-and-custom-profiles-with-freeipa-4-2/</a><br>
<br>
Cheers,
<br>
Milan
<br>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<br>
</blockquote>
<br>
NACK<br>
<br>
0)<br>
rpm file does not contain test_xmlrpc/data directory, please modify
setup.py.in.<br>
<br>
1)<br>
Code contains to much todo for my taste.<br>
<br>
2)<br>
Please do not use filter function, use dict comprehension.<br>
<br>
</body>
</html>