Files
freeipa/ipapython
Fraser Tweedale bc6d499514 Add Subject Key Identifier to CA cert validity check
CA certificates MUST have the Subject Key Identifier extension to
facilitiate certification path construction.  Not having this
extension on the IPA CA certificate will cause failures in Dogtag
during signing; it tries to copy the CA's Subject Key Identifier to
the new certificate's Authority Key Identifier extension, which
fails.

When installing an externally-signed CA, check that the Subject Key
Identifier extension is present in the CA certificate.

Fixes: https://pagure.io/freeipa/issue/6976
Reviewed-By: Stanislav Laznicka <slaznick@redhat.com>
2017-05-30 12:39:15 +02:00
..
2017-03-15 19:11:32 +01:00
2016-11-25 16:18:22 +01:00
2017-03-02 15:09:42 +01:00
2017-01-06 12:48:10 +01:00
2015-09-30 10:51:36 +02:00
2016-09-27 13:35:58 +02:00
2016-07-22 16:30:32 +02:00
2016-10-20 18:43:37 +02:00
2017-04-26 12:31:11 +02:00

This is a set of libraries common to IPA clients and servers though mostly
geared currently towards command-line tools.

A brief overview:

config.py - identify the IPA server domain and realm. It uses python-dns to
            try to detect this information first and will fall back to
            /etc/ipa/default.conf if that fails.

ipautil.py - helper functions

entity.py - entity is the main data type. User and Group extend this class
            (but don't add anything currently).

ipavalidate.py - basic data validation routines