Go to file
Florence Blanc-Renaud 808b1436b4 Refactor installer code requesting certificates
- Temporary modify certmonger dogtag-ipa-ca-renew helper to request the IPA RA
agent cert, using the temp cert created during pkispawn. The cert request
is now processed through certmonger, and the helper arguments are restored
once the agent cert is obtained.

- Modify the installer code creating HTTP and LDAP certificates to use
certmonger's IPA helper with temporary parameters (calling dogtag-submit
instead of ipa-submit)

- Clean-up for the integration tests: sometimes ipa renewal.lock is not
released during ipa-server-uninstall. Make sure that the file is removed
to allow future installations.

https://fedorahosted.org/freeipa/ticket/6433

Reviewed-By: Jan Cholasta <jcholast@redhat.com>
Reviewed-By: Fraser Tweedale <ftweedal@redhat.com>
2016-11-10 14:15:57 +01:00
asn1 Build: fix distribution of asn1/asn1c files 2016-11-09 13:08:32 +01:00
client x509: use python-cryptography to process certs 2016-11-10 10:21:47 +01:00
contrib Build: integrate contrib directory into build system 2016-11-09 13:08:32 +01:00
daemons Support DAL version 5 and version 6 2016-11-10 13:25:51 +01:00
doc Docs: update docs about ipaplatform to match reality 2016-10-24 13:30:12 +02:00
init Build: create /var/run directories at install time 2016-11-09 13:08:32 +01:00
install Refactor installer code requesting certificates 2016-11-10 14:15:57 +01:00
ipaclient Build: Makefiles for Python packages 2016-11-09 13:08:32 +01:00
ipalib Remove __main__ code from ipalib.x509 and ipalib.pkcs10 2016-11-10 10:21:47 +01:00
ipaplatform Build: Makefiles for Python packages 2016-11-09 13:08:32 +01:00
ipapython Refactor installer code requesting certificates 2016-11-10 14:15:57 +01:00
ipaserver Refactor installer code requesting certificates 2016-11-10 14:15:57 +01:00
ipatests Refactor installer code requesting certificates 2016-11-10 14:15:57 +01:00
po Build: fix distdir target for translations 2016-11-09 13:08:32 +01:00
util Build: transform util directory to libutil convenience library 2016-10-24 13:30:12 +02:00
.gitignore gitignore: ignore tar ball 2016-11-10 09:33:01 +01:00
.mailmap Update Contributors.txt 2016-06-24 12:49:39 +02:00
.travis.yml Build: add Python lint target 2016-11-09 13:08:32 +01:00
ACI.txt DNS: Support URI resource record type 2016-10-11 16:48:47 +02:00
API.txt DNS: Support URI resource record type 2016-10-11 16:48:47 +02:00
autogen.sh build tweaks - use automake's foreign mode, avoid creating empty files to satisfy gnu mode - run autoreconf -f to ensure that everything matches 2010-11-29 11:39:55 -05:00
BUILD.txt Build: remove obsolete instructions about BuildRequires from BUILD.txt 2016-11-09 13:08:32 +01:00
configure.ac Build: add polint target for i18n tests 2016-11-09 13:08:32 +01:00
Contributors.txt Update Contributors.txt 2016-06-24 12:49:39 +02:00
COPYING Change FreeIPA license to GPLv3+ 2010-12-20 17:19:53 -05:00
COPYING.openssl Add a clear OpenSSL exception. 2015-02-23 16:25:54 +01:00
freeipa.spec.in Build: fix KDC proxy installation and remove unused kdcproxy.conf 2016-11-09 13:08:32 +01:00
ignore_import_errors.py makeapi, makeaci: do not fail on missing imports 2016-10-24 14:11:08 +02:00
ipa Revert "Switch /usr/bin/ipa to Python 3" 2016-06-14 13:07:04 +02:00
ipasetup.py.in Build: move version handling from Makefile to configure 2016-11-09 13:08:32 +01:00
lite-server.py Port from python-krbV to python-gssapi 2015-08-26 09:41:36 +02:00
make-doc Make an ipa-tests package 2013-06-17 19:22:50 +02:00
make-test Switch make-test to pytest 2014-11-21 12:14:44 +01:00
makeaci makeapi, makeaci: do not fail on missing imports 2016-10-24 14:11:08 +02:00
makeapi makeapi, makeaci: do not fail on missing imports 2016-10-24 14:11:08 +02:00
Makefile.am Build: fix make clean to remove build artifacts from top-level directory 2016-11-10 12:37:58 +01:00
Makefile.python.am Build: Makefiles for Python packages 2016-11-09 13:08:32 +01:00
makerpms.sh Build: add make rpms target and convenience script makerpms.sh 2016-11-09 13:08:32 +01:00
pylint_plugins.py Build: replace ipaplatform magic with symlinks generated by configure 2016-10-24 13:30:12 +02:00
pylintrc pylint: enable the import-error check 2016-10-24 14:11:08 +02:00
pytest.ini Configure pytest to run doctests 2014-11-21 12:14:44 +01:00
README Update README and BUILD 2014-02-12 14:04:07 +01:00
VERSION.m4 Build: move version handling from Makefile to configure 2016-11-09 13:08:32 +01:00
zanata.xml Translations: remove deprecated locale configuration 2016-05-31 13:50:07 +02:00

                               IPA Server

  Overview
  --------

  FreeIPA allows Linux administrators to centrally manage identity,
  authentication and access control aspects of Linux and UNIX systems
  by providing simple to install and use command line and web based
  managment tools.
  FreeIPA is built on top of well known Open Source components and standard
  protocols with a very strong focus on ease of management and automation
  of installation and configuration tasks.
  FreeIPA can seamlessly integrate into an Active Directory environment via
  cross-realm Kerberos trust or user synchronization.

  Benefits
  --------

  FreeIPA:
  * Allows all your users to access all the machines with the same credentials
    and security settings
  * Allows users to access personal files transparently from any machine in
    an authenticated and secure way
  * Uses an advanced grouping mechanism to restrict network access to services
    and files only to specific users
  * Allows central management of security mechanisms like passwords,
    SSH Public Keys, SUDO rules, Keytabs, Access Control Rules
  * Enables delegation of selected administrative tasks to other power users
  * Integrates into Active Directory environments

  Components
  ----------

  The FreeIPA project provides unified installation and management
  tools for the following components:

  * LDAP Server - based on the 389 project (LDAP)
    http://directory.fedoraproject.org/wiki/Main_Page

  * KDC - based on MIT Kerberos implementation
    http://k5wiki.kerberos.org/wiki/Main_Page

  * PKI based on Dogtag project
    http://pki.fedoraproject.org/wiki/PKI_Main_Page

  * Samba libraries for Active Directory integration
    http://www.samba.org/

  * DNS Server based on BIND and the Bind-DynDB-LDAP plugin
    https://www.isc.org/software/bind
    https://fedorahosted.org/bind-dyndb-ldap


  Project Website
  ---------------

  Releases, announcements and other information can be found on the IPA
  server project page at <http://www.freeipa.org/>.

  Documentation
  -------------

  The most up-to-date documentation can be found at
  <http://freeipa.org/page/Documentation>.

  Quick Start
  -----------

  To get started quickly, start here:
  <http://www.freeipa.org/page/Quick_Start_Guide>

  Licensing
  ---------

  Please see the file called COPYING.

  Contacts
  --------

     * If you want to be informed about new code releases, bug fixes,
       security fixes, general news and information about the IPA server
       subscribe to the freeipa-announce mailing list at
       <https://www.redhat.com/mailman/listinfo/freeipa-interest/>.

     * If you have a bug report please submit it at:
       <https://bugzilla.redhat.com>

     * If you want to participate in actively developing IPA please
       subscribe to the freeipa-devel mailing list at
       <https://www.redhat.com/mailman/listinfo/freeipa-devel/> or join
       us in IRC at irc://irc.freenode.net/freeipa