URL: https://github.com/freeipa/freeipa/pull/367
Title: #367: Remove nsslib from IPA

stlaz commented:
You're right, I should probably write some design. The current implementation 
does not check CRL or OSCP, so we're "fine" with this change. There is a plan 
on doing CRL check in certmonger, though.

