This is the first time code has been released since I joined the project. While it ai’n’t done yet, I’m still proud of how far we’ve come. Below is the release from the FreeIPA devel list.
DNS Use cases in FreeIPA
The below is my notes on how DNS is used. This document is neither accurate nor authoritative, just meandering. You’ve been warned.
RFI: SPEGNO multiple requests
From what we are seeing and what I’ve read, the browser seems to send a JSON request with no Auth info, and then the whole SPEGNO handshake takes place, turning what should be a single request response into (at a minimum) two. It seems to me that we should be able to avoid that after the initial auth has taken place.
Is there any way to cache SPEGNO information such that successive JSON RPC calls provide the needed information automatically, instead of requiring multiple round trips per request?
Any Fedora people worked with this stuff and know how to optimize it? Do I need to revert to a Cookie based approach?
I don’t want Star Wars 3-D
I want, instead, the series that I was promised as a pre-teen boy back when the original movie came out. The series I never got. Let’s review:
Preparing patches for submission to the FreeIPA mailing list
Here’s a little ditty I wrote to get patches in the format we use for the FreeIPA mailing list:
Debugging with lite-server.py in FreeIPA
Kerberos doesn’t tell you who you are. Seems like a funny thing, but when you use Kerberos Auth on the web, the browser has not way of telling you “this is the principal that you are using.” For the UI in FreeIPA, I need to display just thins information. To find it, I have to look to the server to tell me.
Thus begins my study of FreeIPA plugins. I wrote a simple plugin, the whoami plugin, that did just what I needed. I returned the Principal in the summary, and all was good.
Now I need more. I need to know the role groups of which the current user is a member. This information is on the user object already. So, good-bye whoami plugin: we are going to add your behavior to the user plugin, where it belongs.
The key piece of information that made this work possible was how to get a breakpoint to stop the code and let me step through it. The trick, probably old hat to the Pythonistas out there, but new to me was this simple line:
import pdb; pdb.set_trace()
Without that, none of the breakpoints I’d set would get executed, maybe due to threading or something. Not sure, but with this, I was able to determine that what I needed to do was to modify the filter.
I ran the lite-server like this:
./lite-server.py
Which is actually preferable to running it like this
python -m pdb lite-server.py
As you don’t have to type cont, and the debugger is still activated by the breakpoints.
Jessie’s Pants
(to the tune of Jessie’s Girl. Yes, that old tune by Rick Springfield. I’m old and watched too much MTV back when it still played videos. Based on real events.)
Such a geek
I was looking through the IPA code and came across these two lines:
‘Str’: _ipa_create_text_input,
‘Int’: _ipa_create_text_input,
I immediately thought
What is he doing putting D&D character abilities in the code?
Of course, the next line was
‘Bool’: _ipa_create_text_input,
Ah, data types. Once a geek…
Fedora as an Adjective
I’m reading the IRC #fedora-board-meeting as I write this, with a discussion going on about the Vision statement for Fedora and it occurs to me that Fedora is really an Adjective.
Project Values
When a group forms, one of the things it does, over time, is develop values. Different development teams have different values, and people that come into the development process have to learn and adopt those values.  One value of the FreeIPA project that is very different from other recent projects of mine is this: The main code repository is only for “published” code. Work in progress should happen elsewhere. The main git repository should be easily readable.