Re: [Freeipa-devel] [PATCH] 1097 Bump nss Requires

2013-04-29 Thread Petr Viktorin

On 04/26/2013 06:39 PM, Rob Crittenden wrote:

Set minimum version of nss/nss-tools to pick up fix to certutil handling
of base64-encoded certificates. We saw pretty reliable failures in F-19
without this.

rob


ACK

--
PetrĀ³

___
Freeipa-devel mailing list
Freeipa-devel@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-devel


Re: [Freeipa-devel] [PATCH] 1097 Bump nss Requires

2013-04-29 Thread Rob Crittenden

Petr Viktorin wrote:

On 04/26/2013 06:39 PM, Rob Crittenden wrote:

Set minimum version of nss/nss-tools to pick up fix to certutil handling
of base64-encoded certificates. We saw pretty reliable failures in F-19
without this.

rob


ACK



Pushed to master

___
Freeipa-devel mailing list
Freeipa-devel@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-devel


[Freeipa-devel] [PATCH] 1097 Bump nss Requires

2013-04-26 Thread Rob Crittenden
Set minimum version of nss/nss-tools to pick up fix to certutil handling 
of base64-encoded certificates. We saw pretty reliable failures in F-19 
without this.


rob
From 710435b2a42fc069b9d8345b58151d45091d72f5 Mon Sep 17 00:00:00 2001
From: Rob Crittenden rcrit...@redhat.com
Date: Fri, 26 Apr 2013 12:36:05 -0400
Subject: [PATCH] Require version of NSS that properly parses base64-encoded
 certs

There were cases where a base64-encoded cert with no header/footer would
not be handled properly and rejected. This was causing the CA install
to fail.

https://fedorahosted.org/freeipa/ticket/3586
---
 freeipa.spec.in | 12 ++--
 1 file changed, 10 insertions(+), 2 deletions(-)

diff --git a/freeipa.spec.in b/freeipa.spec.in
index c597b8766a564f024b643e3641dde1e836abaa92..a146d36c1b094ecfd82194f4012a9102f18bc4cb 100644
--- a/freeipa.spec.in
+++ b/freeipa.spec.in
@@ -95,8 +95,13 @@ Requires: %{name}-admintools = %{version}-%{release}
 Requires: %{name}-server-selinux = %{version}-%{release}
 Requires: 389-ds-base = 1.3.0.5
 Requires: openldap-clients
-Requires: nss
-Requires: nss-tools
+%if 0%{?fedora} == 18
+Requires: nss = 3.14.3-2
+Requires: nss-tools = 3.14.3-2
+%else
+Requires: nss = 3.14.3-12.0
+Requires: nss-tools = 3.14.3-12.0
+%endif
 %if 0%{?krb5_dal_version} = 4
 Requires: krb5-server = 1.11.2-1
 %else
@@ -794,6 +799,9 @@ fi
 %ghost %attr(0644,root,apache) %config(noreplace) %{_sysconfdir}/ipa/ca.crt
 
 %changelog
+* Thu Apr 25 2013 Rob Crittenden rcrit...@redhat.com - 3.1.99-8
+- Update nss and nss-tools dependency to fix certutil problem (#872761)
+
 * Tue Apr 23 2013 Martin Kosek mko...@redhat.com - 3.1.99-7
 - Require pki-ca 10.0.2 for 501 response code on find for d9 - d10 upgrades
 
-- 
1.8.1

___
Freeipa-devel mailing list
Freeipa-devel@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-devel