Go to file
Fraser Tweedale 3d01ec14c6 Allow full customisability of IPA CA subject DN
Currently only the "subject base" of the IPA CA subject DN can be
customised, via the installer's --subject-base option.  The RDN
"CN=Certificate Authority" is appended to form the subject DN, and
this composition is widely assumed.

Some administrators need more control over the CA subject DN,
especially to satisfy expectations of external CAs when the IPA CA
is to be externally signed.

This patch adds full customisability of the CA subject DN.
Specifically:

- Add the --ca-subject option for specifying the full IPA CA subject
  DN.  Defaults to "CN=Certificate Authority, O=$SUBJECT_BASE".

- ipa-ca-install, when installing a CA in a previous CA-less
  topology, updates DS certmap.conf with the new new CA subject DN.

- DsInstance.find_subject_base no longer looks in certmap.conf,
  because the CA subject DN can be unrelated to the subject base.

Fixes: https://fedorahosted.org/freeipa/ticket/2614
Reviewed-By: Jan Cholasta <jcholast@redhat.com>
2017-01-11 15:26:20 +01:00
asn1 Build: fix distribution of asn1/asn1c files 2016-11-09 13:08:32 +01:00
client Clarify meaning of --domain and --realm in installers 2017-01-05 09:47:25 +01:00
contrib Build: integrate contrib directory into build system 2016-11-09 13:08:32 +01:00
daemons ipa-kdb: search for password policies globally 2016-12-15 17:32:33 +01:00
doc Add main guards to a couple of Python scripts 2016-11-24 16:35:43 +01:00
init Build: create /var/run directories at install time 2016-11-09 13:08:32 +01:00
install Allow full customisability of IPA CA subject DN 2017-01-11 15:26:20 +01:00
ipaclient ipaclient: schema cache: Handle malformed server info data gracefully 2017-01-09 09:13:36 +01:00
ipalib Use pytest conftest.py and drop pytest.ini 2017-01-05 17:37:02 +01:00
ipaplatform client, platform: Use paths.SSH* instead of get_config_dir(). 2017-01-05 17:50:03 +01:00
ipapython Py3: Fix ToASCII method 2017-01-06 12:48:10 +01:00
ipaserver Allow full customisability of IPA CA subject DN 2017-01-11 15:26:20 +01:00
ipatests Use pytest conftest.py and drop pytest.ini 2017-01-05 17:37:02 +01:00
po Lowered the version of gettext 2016-12-09 14:01:06 +01:00
util Build: transform util directory to libutil convenience library 2016-10-24 13:30:12 +02:00
.git-commit-template git: Add commit template 2016-11-14 18:15:04 +01:00
.gitignore Lowered the version of gettext 2016-12-09 14:01:06 +01:00
.mailmap Update Contributors.txt 2016-06-24 12:49:39 +02:00
.test_runner_config.yaml py3: enable py3 pylint 2017-01-11 13:17:15 +01:00
.travis_run_task.sh Travis CI: actually return non-zero exit status when the test job fails 2017-01-09 15:22:51 +01:00
.travis.yml Trim the test runner log to show only pytest failures/errors 2017-01-05 16:21:51 +01:00
ACI.txt DNS: Support URI resource record type 2016-10-11 16:48:47 +02:00
API.txt Add options to write lightweight CA cert or chain to file 2016-12-12 13:03:15 +01:00
autogen.sh build tweaks - use automake's foreign mode, avoid creating empty files to satisfy gnu mode - run autoreconf -f to ensure that everything matches 2010-11-29 11:39:55 -05:00
BUILD.txt Build: remove obsolete instructions about BuildRequires from BUILD.txt 2016-11-09 13:08:32 +01:00
configure.ac Use the tar Posix option for tarballs 2016-12-21 14:54:08 +01:00
Contributors.txt Update Contributors.txt 2016-06-24 12:49:39 +02:00
COPYING Change FreeIPA license to GPLv3+ 2010-12-20 17:19:53 -05:00
COPYING.openssl Add a clear OpenSSL exception. 2015-02-23 16:25:54 +01:00
freeipa.spec.in Py3: Fix ToASCII method 2017-01-06 12:48:10 +01:00
ignore_import_errors.py makeapi, makeaci: do not fail on missing imports 2016-10-24 14:11:08 +02:00
ipa Revert "Switch /usr/bin/ipa to Python 3" 2016-06-14 13:07:04 +02:00
ipasetup.py.in Py3: Fix ToASCII method 2017-01-06 12:48:10 +01:00
lite-server.py Python3 pylint fixes 2016-11-25 16:18:22 +01:00
make-doc Make an ipa-tests package 2013-06-17 19:22:50 +02:00
make-test Use pytest conftest.py and drop pytest.ini 2017-01-05 17:37:02 +01:00
makeaci makeapi, makeaci: do not fail on missing imports 2016-10-24 14:11:08 +02:00
makeapi Python3 pylint fixes 2016-11-25 16:18:22 +01:00
Makefile.am Use pytest conftest.py and drop pytest.ini 2017-01-05 17:37:02 +01:00
Makefile.python.am Build: properly integrate ipasetup.py into build system 2016-11-29 15:28:24 +01:00
makerpms.sh Build: update makerpms.sh to use same paths as rpmbuild 2016-11-16 09:12:07 +01:00
pylint_plugins.py Add file_exists method as a member of transport object 2016-11-14 14:32:10 +01:00
pylintrc Pylint: whitelist packages with extension modules 2016-11-22 17:37:39 +01:00
README Update README and BUILD 2014-02-12 14:04:07 +01:00
VERSION.m4 Add options to write lightweight CA cert or chain to file 2016-12-12 13:03:15 +01:00
zanata.xml Zanata: exlude testing ipa.pot file 2016-11-21 14:47:47 +01:00

                               IPA Server

  Overview
  --------

  FreeIPA allows Linux administrators to centrally manage identity,
  authentication and access control aspects of Linux and UNIX systems
  by providing simple to install and use command line and web based
  managment tools.
  FreeIPA is built on top of well known Open Source components and standard
  protocols with a very strong focus on ease of management and automation
  of installation and configuration tasks.
  FreeIPA can seamlessly integrate into an Active Directory environment via
  cross-realm Kerberos trust or user synchronization.

  Benefits
  --------

  FreeIPA:
  * Allows all your users to access all the machines with the same credentials
    and security settings
  * Allows users to access personal files transparently from any machine in
    an authenticated and secure way
  * Uses an advanced grouping mechanism to restrict network access to services
    and files only to specific users
  * Allows central management of security mechanisms like passwords,
    SSH Public Keys, SUDO rules, Keytabs, Access Control Rules
  * Enables delegation of selected administrative tasks to other power users
  * Integrates into Active Directory environments

  Components
  ----------

  The FreeIPA project provides unified installation and management
  tools for the following components:

  * LDAP Server - based on the 389 project (LDAP)
    http://directory.fedoraproject.org/wiki/Main_Page

  * KDC - based on MIT Kerberos implementation
    http://k5wiki.kerberos.org/wiki/Main_Page

  * PKI based on Dogtag project
    http://pki.fedoraproject.org/wiki/PKI_Main_Page

  * Samba libraries for Active Directory integration
    http://www.samba.org/

  * DNS Server based on BIND and the Bind-DynDB-LDAP plugin
    https://www.isc.org/software/bind
    https://fedorahosted.org/bind-dyndb-ldap


  Project Website
  ---------------

  Releases, announcements and other information can be found on the IPA
  server project page at <http://www.freeipa.org/>.

  Documentation
  -------------

  The most up-to-date documentation can be found at
  <http://freeipa.org/page/Documentation>.

  Quick Start
  -----------

  To get started quickly, start here:
  <http://www.freeipa.org/page/Quick_Start_Guide>

  Licensing
  ---------

  Please see the file called COPYING.

  Contacts
  --------

     * If you want to be informed about new code releases, bug fixes,
       security fixes, general news and information about the IPA server
       subscribe to the freeipa-announce mailing list at
       <https://www.redhat.com/mailman/listinfo/freeipa-interest/>.

     * If you have a bug report please submit it at:
       <https://bugzilla.redhat.com>

     * If you want to participate in actively developing IPA please
       subscribe to the freeipa-devel mailing list at
       <https://www.redhat.com/mailman/listinfo/freeipa-devel/> or join
       us in IRC at irc://irc.freenode.net/freeipa