freeipa/ipaclient
Jan Cholasta f769045f0a server install: fix KDC PKINIT configuration
Set `pkinit_pool` in `kdc.conf` to a CA certificate bundle of all CAs known
to IPA.

Make sure `cacert.pem` is exported in all installation code paths.

Use the KDC certificate itself as a PKINIT anchor in `login_password`.

https://pagure.io/freeipa/issue/6831

Reviewed-By: Stanislav Laznicka <slaznick@redhat.com>
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com>
2017-05-19 12:31:24 +02:00
..
csrgen csrgen: Change to pure openssl config format (no script) 2017-04-03 07:46:30 +00:00
install server install: fix KDC PKINIT configuration 2017-05-19 12:31:24 +02:00
plugins Use os.fsync instead of os.fdatasync because macOS doesn't support fdatasync 2017-05-17 14:07:13 +02:00
remote_plugins fix minor spelling mistakes 2017-05-19 09:52:46 +02:00
__init__.py Split ipa-client/ into ipaclient/ (Python library) and client/ (C, scripts) 2016-01-27 12:09:02 +01:00
__main__.py Use entry_points for ipa CLI 2017-04-11 13:29:50 +02:00
csrgen_ffi.py csrgen: Modify cert_get_requestdata to return a CertificationRequestInfo 2017-04-03 07:46:30 +00:00
csrgen.py csrgen: Beginnings of NSS database support 2017-04-03 07:46:30 +00:00
frontend.py frontent: Add summary class property to CommandOverride 2016-08-17 14:16:04 +02:00
Makefile.am Build: Makefiles for Python packages 2016-11-09 13:08:32 +01:00
setup.cfg Port all setup.py to setuptools 2016-10-20 18:43:37 +02:00
setup.py Slim down dependencies 2017-05-09 17:17:29 +02:00