Erinn Looney-Triggs wrote:
Is there a reason that ipa-client-install does not add the CA of the IPA
server to the ca-bundle.crt file in /etc/pki/certs/?

Seems like it would be a reasonable move to do that.

I know it imports the CA into /etc/pki/nssdb.

Hopefully I didn't miss something that allows it to. But I wanted to
check if there was a good reason for it not to before going and filing
an RFE.

We will as part of the shared system certificates effort, http://fedoraproject.org/wiki/Features/SharedSystemCertificates Our ticket is https://fedorahosted.org/freeipa/ticket/3504

They are working on tools to make managing these certificates easier for F-20.

rob


_______________________________________________
Freeipa-users mailing list
Freeipa-users@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-users

Reply via email to