1. 05 Jun, 2019 1 commit
    • chuck cranor's avatar
      two additional updates for EXPIRE_PASSWORDS=0 mode · ee6cf209
      chuck cranor authored
      1. In User.pm Create(), only apply the default expire time of 1 year
      to pswd_expires if EXPIRE_PASSWORDS is true.
      2. In tbacct's passwd command: the current behavior is that we set
      the pswd_expires time to "now" if we are changing the the password
      of someone else's account.   this patch adds a new "-e" flag that,
      if specified, uses the default expiration policy instead of now.
      The rational for this change is to allow scripts to import encrypted
      passwords from external account management systems and apply them
      to emulab using "tbacct passwd" without forcing an immediate change.
  2. 03 Jun, 2019 1 commit
  3. 08 Feb, 2019 1 commit
  4. 13 Dec, 2018 1 commit
  5. 12 Dec, 2018 1 commit
  6. 28 Nov, 2018 1 commit
  7. 14 Nov, 2018 2 commits
  8. 29 Aug, 2018 1 commit
    • Leigh Stoller's avatar
      Changes for dump/restore users: · 7ec685f9
      Leigh Stoller authored
      * dumpuser: Change some user table fields to optional, since Portal
        users do not have to fill those things out (address, phone, zip,
        etc). I am using this to transfer accounts from the Mothership to
        inner Emulab when CONFIG_ADMINUSERS=1.
      * newuser: equiv changes, allow some fields to be optional that usually
        are not. Also allow the password has to come through, normally we do
        not pass that through.
  9. 30 Jul, 2018 1 commit
  10. 30 May, 2018 1 commit
  11. 23 May, 2018 2 commits
    • Leigh Stoller's avatar
      Fix mistake in previous revision. · d0c3496f
      Leigh Stoller authored
    • Leigh Stoller's avatar
      Limit new certificate expiration to no later then the signer expiration · d7e60116
      Leigh Stoller authored
      so that we do not get into the same situation as the Geni Portal.
      All of the Cloudlab clusters are more then two years from the CA
      expiration, so this won't present a problem for a while, but we do have
      certificates floating around that are set to expire after the CA.
      User certificates we can regenerate as needed, slice certificates will
      age out before then.
      I bet this *is* a problem on geni racks where expiration is much closer
      to now.
  12. 07 Apr, 2018 1 commit
  13. 28 Mar, 2018 1 commit
  14. 14 Feb, 2018 1 commit
  15. 09 Feb, 2018 1 commit
  16. 05 Dec, 2017 1 commit
  17. 02 Nov, 2017 1 commit
  18. 31 Oct, 2017 2 commits
  19. 30 Oct, 2017 1 commit
  20. 11 Oct, 2017 1 commit
  21. 27 Jul, 2017 1 commit
  22. 30 May, 2017 1 commit
    • Mike Hibler's avatar
      Sort out ZFS refquota/quota settings, part 2. · 2202163e
      Mike Hibler authored
      Add setzfsquotas script to handle fixup of existing quotas, add update
      script to do a one-time invocation of this script at boss-install time,
      and fix accountsetup so it will properly set both quotas going forward.
  23. 12 Jan, 2017 1 commit
  24. 07 Dec, 2016 1 commit
  25. 23 Nov, 2016 1 commit
  26. 21 Oct, 2016 1 commit
  27. 20 Sep, 2016 1 commit
    • Leigh Stoller's avatar
      Two changes: · aea0f297
      Leigh Stoller authored
      1. Fix max days, supposed to be 1000 but was getting set back to 365 in
         one missed place.
      2. Add -P option; use the existing passphrase from the DB instead of a
         new one. This makes it easy to update someones encrypted certificate,
         reusing their key (-r) and their password.
      Note to self; we do not give Portal users a UI for updating their
      encrypted certificates, and we do not do it for them when they
      expire. That will need to change real soon (like, by tomorrow morning
      when the next user gets an expired certificate error).
  28. 02 Sep, 2016 1 commit
    • Leigh Stoller's avatar
      Changes for dealing with group/password file locking errors: · fd0fd225
      Leigh Stoller authored
      * Move user mod (gecos,password) into the accountsetup proxy instead of
        ssh chpass. Wrap all usermod/chpass system calls in a loop that looks
        for the busy file error, back off and try again for a while.
      * Add same wrapping to local (boss) calls of usermod/chpass. I put that
        function into emutil.
      * Rename old modgroups in the proxy to setgroups, since that it is what
        it was actually doing.
  29. 30 Aug, 2016 1 commit
  30. 29 Aug, 2016 1 commit
    • Leigh Stoller's avatar
      Various fixes to deactivate/reactivate code, mostly to deal with not · bf77e242
      Leigh Stoller authored
      wanting to call setgroups cause it is so slow. also refactor the code to
      chown/chgrp user dot files so we can call it from reactivate.
      Refactor the code that bumps user/project activity and calls exports
      setup so that we can call it from reactivate.
      When deleting a ZFS home/proj directory, do the ZFS rename and then
      set the mountpoint=none, no need to have it mounted.
  31. 29 Jul, 2016 2 commits
  32. 26 Jul, 2016 2 commits
  33. 24 Jun, 2016 1 commit
    • Leigh Stoller's avatar
      Change "genesis" to "portal" what the hell was I thinking when I · 040ea3be
      Leigh Stoller authored
      picked genesis. But this change actually has content; we need to
      distinguish between classic projects and emulab portal projects
      (new projects created via the portal, and used via the portal).  For now
      these are distinct until we decide to bring everyone up to the new
  34. 18 May, 2016 1 commit
  35. 18 Mar, 2016 1 commit