mirror of
https://salsa.debian.org/freeipa-team/freeipa.git
synced 2024-12-24 16:10:02 -06:00
f769045f0a
Set `pkinit_pool` in `kdc.conf` to a CA certificate bundle of all CAs known to IPA. Make sure `cacert.pem` is exported in all installation code paths. Use the KDC certificate itself as a PKINIT anchor in `login_password`. https://pagure.io/freeipa/issue/6831 Reviewed-By: Stanislav Laznicka <slaznick@redhat.com> Reviewed-By: Martin Babinsky <mbabinsk@redhat.com> |
||
---|---|---|
.. | ||
Makefile.am | ||
README | ||
renew_ca_cert | ||
renew_kdc_cert | ||
renew_ra_cert | ||
renew_ra_cert_pre | ||
restart_dirsrv | ||
restart_httpd | ||
stop_pkicad |
This directory contains scripts to be used by the command (-C) option of certmonger to restart services when the certificates are renewed.