freeipa/ipaserver
Pavel Vomacka e0b32dac54
Turn on NSSOCSP check in mod_nss conf
Turn on NSSOCSP directive during install/replica install/upgrade.
That check whether the certificate which is used for login is
revoked or not using OSCP.

Marks the server cert in httpd NSS DB as trusted peer ('P,,')
to avoid chicken and egg problem when it is needed to contact
the OCSP responder when httpd is starting.

https://pagure.io/freeipa/issue/6370

Reviewed-By: Florence Blanc-Renaud <frenaud@redhat.com>
Reviewed-By: Rob Crittenden <rcritten@redhat.com>
Reviewed-By: Jan Cholasta <jcholast@redhat.com>
Reviewed-By: Martin Basti <mbasti@redhat.com>
2017-05-10 09:08:34 +02:00
..
advise scripts, tests: explicitly set confdir in the rest of server code 2017-02-22 08:07:48 +00:00
dnssec Fix PKCS11 helper 2017-04-12 09:54:10 +02:00
install Turn on NSSOCSP check in mod_nss conf 2017-05-10 09:08:34 +02:00
plugins Refresh Dogtag RestClient.ca_host property 2017-05-02 17:33:25 +02:00
secrets ipa-kra-install: fix check_host_keys 2017-05-09 14:28:13 +02:00
__init__.py Change FreeIPA license to GPLv3+ 2010-12-20 17:19:53 -05:00
dcerpc.py ipaserver/dcerpc: unify error processing 2017-04-11 14:16:39 +02:00
dns_data_management.py Fix compatibility with python-dns 1.15.0 2016-10-11 15:45:41 +02:00
Makefile.am Build: Makefiles for Python packages 2016-11-09 13:08:32 +01:00
p11helper.py Fix PKCS11 helper 2017-04-12 09:54:10 +02:00
rpcserver.py kerberos session: use CA cert with full cert chain for obtaining cookie 2017-05-02 13:42:52 +02:00
servroles.py Introduce "NTP server" role 2016-06-15 13:51:48 +02:00
setup.cfg Port all setup.py to setuptools 2016-10-20 18:43:37 +02:00
setup.py Turn on NSSOCSP check in mod_nss conf 2017-05-10 09:08:34 +02:00
topology.py Fix topologysuffix-verify failing connections 2016-06-24 13:32:02 +02:00