Re: [Freeipa-devel] [PATCH] 315 Convert external CA chain to PKCS#7 before passing it to pkispawn

2014-08-14 Thread Petr Viktorin
On 08/13/2014 03:57 PM, Martin Kosek wrote: On 08/13/2014 03:12 PM, Petr Viktorin wrote: [...] This works for me, but I'm not sure if I'm correctly reproducing the specific scenario this patch fixes. So as always, can you please add tests for code you write? +1! As far as other scenarios,

Re: [Freeipa-devel] [PATCH] 315 Convert external CA chain to PKCS#7 before passing it to pkispawn

2014-08-13 Thread Petr Viktorin
On 08/08/2014 11:50 AM, Jan Cholasta wrote: Dne 8.8.2014 v 11:20 Martin Kosek napsal(a): On 08/08/2014 10:55 AM, Jan Cholasta wrote: Hi, the attached patch fixes https://fedorahosted.org/freeipa/ticket/4397. Honza Thanks! I did not test, just have couple questions/suggestions: 1) Are we

Re: [Freeipa-devel] [PATCH] 315 Convert external CA chain to PKCS#7 before passing it to pkispawn

2014-08-13 Thread Martin Kosek
On 08/13/2014 03:12 PM, Petr Viktorin wrote: On 08/08/2014 11:50 AM, Jan Cholasta wrote: Dne 8.8.2014 v 11:20 Martin Kosek napsal(a): On 08/08/2014 10:55 AM, Jan Cholasta wrote: Hi, the attached patch fixes https://fedorahosted.org/freeipa/ticket/4397. Honza Thanks! I did not test, just

Re: [Freeipa-devel] [PATCH] 315 Convert external CA chain to PKCS#7 before passing it to pkispawn

2014-08-08 Thread Martin Kosek
On 08/08/2014 10:55 AM, Jan Cholasta wrote: Hi, the attached patch fixes https://fedorahosted.org/freeipa/ticket/4397. Honza Thanks! I did not test, just have couple questions/suggestions: 1) Are we testing that the certificate is in proper format, e.g. is not PKCS7 already? We need to

Re: [Freeipa-devel] [PATCH] 315 Convert external CA chain to PKCS#7 before passing it to pkispawn

2014-08-08 Thread Jan Cholasta
Dne 8.8.2014 v 11:20 Martin Kosek napsal(a): On 08/08/2014 10:55 AM, Jan Cholasta wrote: Hi, the attached patch fixes https://fedorahosted.org/freeipa/ticket/4397. Honza Thanks! I did not test, just have couple questions/suggestions: 1) Are we testing that the certificate is in proper