[Freeipa-devel] Re: [DESIGN] Certificate profile update mechanism

2017-07-10 Thread Fraser Tweedale via FreeIPA-devel
On Mon, Jul 10, 2017 at 12:44:40PM +0200, Tomas Krizek wrote: > On 07/10/2017 12:16 PM, Simo Sorce via FreeIPA-devel wrote: > > Hi Fraser, > > I think you put on a reasonable proposal, however If I had to design > > this right now and had the freedom to change dogtag and the rest of > > freeipa to

[Freeipa-devel] Re: [DESIGN] Certificate profile update mechanism

2017-07-10 Thread Simo Sorce via FreeIPA-devel
On Mon, 2017-07-10 at 12:44 +0200, Tomas Krizek wrote: > On 07/10/2017 12:16 PM, Simo Sorce via FreeIPA-devel wrote: > > Hi Fraser, > > I think you put on a reasonable proposal, however If I had to > > design > > this right now and had the freedom to change dogtag and the rest of > > freeipa to cop

[Freeipa-devel] Re: [DESIGN] Certificate profile update mechanism

2017-07-10 Thread Tomas Krizek via FreeIPA-devel
On 07/10/2017 12:16 PM, Simo Sorce via FreeIPA-devel wrote: > Hi Fraser, > I think you put on a reasonable proposal, however If I had to design > this right now and had the freedom to change dogtag and the rest of > freeipa to cope I would do the following: > > - Change the LDAP profile storage to

[Freeipa-devel] Re: [DESIGN] Certificate profile update mechanism

2017-07-10 Thread Simo Sorce via FreeIPA-devel
Hi Fraser, I think you put on a reasonable proposal, however If I had to design this right now and had the freedom to change dogtag and the rest of freeipa to cope I would do the following: - Change the LDAP profile storage to have versioned subtrees for "system" profiles, and have a "custom" subt