freeipa/ipaserver/install/server
Christian Heimes 74e09087ed Globally disable softhsm2 in p11-kit-proxy
The p11-kit configuration injects p11-kit-proxy into all NSS databases.
Amongst other p11-kit loads SoftHSM2 PKCS#11 provider. This interferes
with 389-DS, certmonger, Dogtag and other services. For example certmonger
tries to open OpenDNSSEC's SoftHSM2 token, although it doesn't use it at
all. It also breaks Dogtag HSM support testing with SoftHSM2.

IPA server does neither need nor use SoftHSM2 proxied by p11-kit.

Related: https://pagure.io/freeipa/issue/7810
Signed-off-by: Christian Heimes <cheimes@redhat.com>
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com>
2019-04-25 12:53:08 +02:00
..
__init__.py Add hidden replica feature 2019-03-28 17:57:58 +01:00
install.py Globally disable softhsm2 in p11-kit-proxy 2019-04-25 12:53:08 +02:00
replicainstall.py Globally disable softhsm2 in p11-kit-proxy 2019-04-25 12:53:08 +02:00
upgrade.py Globally disable softhsm2 in p11-kit-proxy 2019-04-25 12:53:08 +02:00