mirror of
https://salsa.debian.org/freeipa-team/freeipa.git
synced 2026-08-05 10:47:27 -05:00
It is not obvious why we "renew" (reuse only) the IPA CA certificate in ipa-certupdate. Add some commentary to explain this behaviour. Related: https://pagure.io/freeipa/issue/7751 See also: https://github.com/freeipa/freeipa/pull/2576#issuecomment-442220840 Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com>