Hi all,

The attached patch fixes the OCSP URI in the Dogtag CA and system
certificates (https://fedorahosted.org/freeipa/ticket/5956).  It
depends on a patch[1] for Dogtag which is expected to be released in
v10.3.4.  In the meantime, you can test with the build of v10.3.4
from my COPR[2].

[1] https://www.redhat.com/archives/pki-devel/2016-June/msg00138.html
[2] https://copr.fedorainfracloud.org/coprs/ftweedal/freeipa/



this upgrade is executed always, is it on purpose?
If not please use sysupgrade and run upgrade only once

It is intentional; the directive only gets added if it is missing.
I do not see any benefit in gating it with the sysupgrade mechanism.


************* Module ipaserver.install.cainstance
ipaserver/install/cainstance.py:465: [E0602(undefined-variable), CAInstance.__spawn_instance] Undefined variable 'IPA_CA_RECORD')

you need ipalib.constants.IPA_CA_RECORD


Ahh nevermind, this is a clash of different patches, works on master :)


Pushed to master: 45daffa22fcc6c481a8302f1947a5e0ded0b3eb8

