freeipa/daemons/dnssec
Florence Blanc-Renaud 8080bf7b35 Support OpenDNSSEC 2.1: new ods-signer protocol
The communication between ods-signer and the socket-activated process
has changed with OpenDNSSEC 2.1. Adapt ipa-ods-exporter to support also
the new protocol.

The internal database was also modified. Add a wrapper calling the
right code (table names hab=ve changed, as well as table columns).

With OpenDNSSEC the policy also needs to be explicitely loaded after
ods-enforcer-db-setup has been run, with
ods-enforcer policy import

The command ods-ksmutil notify must be replace with ods-enforce flush.

Related: https://pagure.io/freeipa/issue/8214
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com>
Reviewed-By: Christian Heimes <cheimes@redhat.com>
2020-03-12 21:48:25 +01:00
..
ipa-dnskeysync-replica.in Replace PYTHONSHEBANG with valid shebang 2019-06-24 09:35:57 +02:00
ipa-dnskeysyncd.in Replace PYTHONSHEBANG with valid shebang 2019-06-24 09:35:57 +02:00
ipa-dnskeysyncd.service.in configure: Use ODS_USER and NAMED_GROUP in daemons/dnssec/*.service.in 2017-03-22 13:39:18 +01:00
ipa-ods-exporter.in Support OpenDNSSEC 2.1: new ods-signer protocol 2020-03-12 21:48:25 +01:00
ipa-ods-exporter.service.in configure: Use ODS_USER and NAMED_GROUP in daemons/dnssec/*.service.in 2017-03-22 13:39:18 +01:00
ipa-ods-exporter.socket.in Build: fix path in ipa-ods-exporter.socket unit file 2016-11-21 17:24:58 +01:00
Makefile.am Generate scripts from templates 2018-08-23 14:49:06 +02:00