mirror of
https://salsa.debian.org/freeipa-team/freeipa.git
synced 2024-12-24 16:10:02 -06:00
d7e1ab8438
There have been several instances of people using the profile configuration template files as actual profile configurations, resulting in failures and support load. Add a README to the profile template directory to explain that these files should not be used and advise of the recommend procedure. Fixes: https://pagure.io/freeipa/issue/7014 Reviewed-By: Martin Basti <mbasti@redhat.com>
21 lines
817 B
Plaintext
21 lines
817 B
Plaintext
This directory contains profile TEMPLATES for certificate profiles
|
|
included in FreeIPA. Do not import these files or modifications
|
|
thereof - it is likely that Dogtag will accept the configuration,
|
|
but certificate issuance will fail with the updated configuration.
|
|
At best, it will not give you the certificates you want.
|
|
|
|
If you want to modify a profile configuration or create a new
|
|
profile based on an existing profile configuration, you should
|
|
export the current profile configuration with the command:
|
|
|
|
ipa certprofile-show --out FILENAME PROFILE_NAME
|
|
|
|
After modifying the configuration, update the profile configuration:
|
|
|
|
ipa certprofile-mod --file FILENAME PROFILE_NAME
|
|
|
|
Or if you are creating a new profile:
|
|
|
|
ipa certprofile-import --desc DESC --store 1 \
|
|
--file FILENAME NEW_PROFILE_NAME
|