the attached patches implement the server-side part of <https://fedorahosted.org/freeipa/ticket/5381>.



thank you for the patches. I tested them and they work well. But I would like to ask you whether would be possible to extend the response of 'basecert_find' method and probably also 'basecert_show' response. I think of these information:

1) information whether the certificate is issued by our CA or not.

2) this probably wouldn't be possible (as we discussed), but I rather write it too - the information about revocation reason. The same as the 'cert_show' provides.

3) MD5 and SHA1 fingerprints as the 'cert_show' method returns

