Go to file
Rob Crittenden 0708f603e2 renew_ca_cert: skip removing non-CA certs, fix nickname
This script deletes all CA certificates so a new chain
can be loaded. It identified CA certs by those that did
not have private keys. This change adds the  ca_flags test
in as well. It is probably sufficient on its own but it
is left for compatibility.

An HSM-based NSS database when not accessing it with the
token will not contain the private keys so removing all
certificates without a private key will remove certificates
that it shouldn't. The NSS softoken stores the certifcate
trust so the certificates will be visible but they lack
private keys because those reside in the HSM. Therefore
deleting any certificate without a private key removed
nearly everything.

Preserve the nickname 'caSigningCert cert-pki-ca'. The
certstore uses the nickame format '{REALM} IPA CA' and
will replace the PKI-named key if we don't act to
preserve it.

Fixes: https://pagure.io/freeipa/issue/9273

Signed-off-by: Rob Crittenden <rcritten@redhat.com>
Reviewed-By: Florence Blanc-Renaud <frenaud@redhat.com>
2024-05-16 08:46:32 -04:00
.copr Adding auto COPR builds 2019-12-14 14:20:34 +02:00
.github Let GH auto-notify and auto-close stale PRs 2020-05-06 20:17:01 +02:00
asn1 fix minor spelling mistakes 2017-05-19 09:52:46 +02:00
client component: mail_from_realname config setting added to IPA-EPN 2023-07-26 09:01:37 -04:00
contrib Replace usage of #!/usr/bin/env python3 with #!/usr/bin/python3 2023-05-31 09:21:48 +02:00
daemons ipa-pwd-extop: declare operation notes support from 389-ds locally 2024-03-14 13:53:16 +01:00
doc doc: Add token-password-file to HSM design, set new OID 2024-05-16 08:46:32 -04:00
init Fix ipa-ccache-sweeper activation timer and clean up service file 2022-08-29 18:28:42 +02:00
install renew_ca_cert: skip removing non-CA certs, fix nickname 2024-05-16 08:46:32 -04:00
ipaclient Replace netifaces with ifaddr 2024-05-03 16:35:19 -04:00
ipalib Support the certmonger nss-user option 2024-05-16 08:46:32 -04:00
ipaplatform ipaplatform: add opencloudos/tencentos support 2024-01-12 08:36:20 -05:00
ipapython Support the certmonger nss-user option 2024-05-16 08:46:32 -04:00
ipaserver If HSM is configured add the token name to config-show output 2024-05-16 08:46:32 -04:00
ipasphinx ipasphinx: Correct import of progress_message for Sphinx 6.1.0+ 2023-04-28 13:20:30 -04:00
ipatests ipa-crlgen-manage: manage the cert status task execution time 2024-04-15 16:03:10 +02:00
po internal: fix 'tokensfor' typo and regenerate pot file 2024-04-10 09:30:53 +02:00
pypi Cleanup shebang and executable bit 2018-07-05 19:46:42 +02:00
selinux Update SELinux policy to allow certmonger to PKI config files 2024-05-16 08:46:32 -04:00
util ipa_pwd: Remove unnecessary conditional 2021-01-15 10:01:28 +01:00
.freeipa-pr-ci.yaml ipatests: revert wrong commit on gating definition 2021-11-02 11:40:25 +01:00
.git-commit-template Commit template: use either Fixes or Related 2022-02-14 11:21:01 +02:00
.gitignore gitignore: add install/oddjob/org.freeipa.server.config-enable-sid 2022-08-16 13:07:03 +02:00
.lgtm.yml Replace netifaces with ifaddr 2024-05-03 16:35:19 -04:00
.mailmap mailmap: add ftweedal 2020-11-11 14:08:35 +02:00
.readthedocs.yaml docs: add the readthedocs configuration 2022-05-04 09:36:40 +03:00
.tox-install.sh azure: Don't customize pip's builddir 2021-10-21 08:03:03 +02:00
.wheelconstraints.in pylint: updates related to deprecations 2024-01-09 08:40:47 +01:00
ACI.txt Add attribute ipacahsmconfiguration to the "Read CAs" ACI 2024-05-16 08:46:32 -04:00
API.txt ipa-pwd-extop: allow enforcing 2FA-only over LDAP bind 2024-03-12 13:53:11 +01:00
autogen.sh build tweaks - use automake's foreign mode, avoid creating empty files to satisfy gnu mode - run autoreconf -f to ensure that everything matches 2010-11-29 11:39:55 -05:00
BUILD.txt BUILD.txt: remove redundant dnf-builddep option 2022-07-05 14:26:52 +02:00
CODE_OF_CONDUCT.md Changing Django's CoC to reflect FreeIPA CoC 2018-03-26 09:51:25 +02:00
configure.ac Tolerate absence of PAC ticket signature depending of server capabilities 2023-05-24 13:20:38 +02:00
Contributors.txt Update list of contributors 2023-10-03 14:57:20 +02:00
COPYING Change FreeIPA license to GPLv3+ 2010-12-20 17:19:53 -05:00
COPYING.openssl Add a clear OpenSSL exception. 2015-02-23 16:25:54 +01:00
freeipa.doap.rdf Adding modified DOAP file 2018-06-22 11:02:40 -04:00
freeipa.spec.in Spec file: depend on nfs-utils or nfsv4-client-utils 2024-05-07 14:33:04 +02:00
gpgkey-0E63D716D76AC080A4A33513F40800B6298EB963.asc spec: verify upstream source signature 2023-04-18 08:32:54 +02:00
ipa.in Replace PYTHONSHEBANG with valid shebang 2019-06-24 09:35:57 +02:00
ipasetup.py.in Replace netifaces with ifaddr 2024-05-03 16:35:19 -04:00
make-doc Make an ipa-tests package 2013-06-17 19:22:50 +02:00
make-test Use pytest conftest.py and drop pytest.ini 2017-01-05 17:37:02 +01:00
makeaci.in Warn for permissions with read/write/search/compare and no attrs 2022-07-15 16:59:15 +02:00
makeapi.in doc: allow notes on Param API Reference pages 2023-03-29 10:53:25 +02:00
Makefile.am fastlint: Correct concatenation of file lists 2023-03-24 11:49:23 +01:00
Makefile.python.am Add PYTHON_INSTALL_EXTRA_OPTIONS and --install-layout=deb 2017-03-15 13:48:23 +01:00
Makefile.pythonscripts.am ipa-scripts: fix all ipa command line scripts to operate with -I 2019-09-19 10:44:09 -04:00
makerpms.sh Fix unnecessary usrmerge assumptions 2019-04-17 13:56:05 +02:00
pylint_plugins.py pylint: updates related to deprecations 2024-01-09 08:40:47 +01:00
pylintrc Replace netifaces with ifaddr 2024-05-03 16:35:19 -04:00
README.md Update IRC links to point to Libera.chat 2021-05-27 18:26:28 +03:00
server.m4 ipa-pwd-extop: add MFA note in case of a successful LDAP bind with OTP 2024-03-12 13:53:11 +01:00
tox.ini rpcserver: validate Kerberos principal name before running kinit 2024-02-21 17:07:33 -05:00
VERSION.m4 Bump to IPA 4.12 2023-08-21 16:39:16 +02:00

FreeIPA Server

FreeIPA allows Linux administrators to centrally manage identity, authentication and access control aspects of Linux and UNIX systems by providing simple to install and use command line and web based management tools.

FreeIPA is built on top of well known Open Source components and standard protocols with a very strong focus on ease of management and automation of installation and configuration tasks.

FreeIPA can seamlessly integrate into an Active Directory environment via cross-realm Kerberos trust or user synchronization.

Benefits

FreeIPA:

  • Allows all your users to access all the machines with the same credentials and security settings
  • Allows users to access personal files transparently from any machine in an authenticated and secure way
  • Uses an advanced grouping mechanism to restrict network access to services and files only to specific users
  • Allows central management of security mechanisms like passwords, SSH Public Keys, SUDO rules, Keytabs, Access Control Rules
  • Enables delegation of selected administrative tasks to other power users
  • Integrates into Active Directory environments

Components

The FreeIPA project provides unified installation and management tools for the following components:

Project Website

Releases, announcements and other information can be found on the IPA server project page at http://www.freeipa.org/ .

Documentation

The most up-to-date documentation can be found at http://freeipa.org/page/Documentation .

Quick Start

To get started quickly, start here: http://www.freeipa.org/page/Quick_Start_Guide

For developers

Licensing

Please see the file called COPYING.

Contacts