Re: [Freeipa-devel] [PATCH] 242 new method to identify CAs to trust

2009-07-27 Thread Jason Gerard DeRose
On Fri, 2009-07-24 at 09:30 -0400, Rob Crittenden wrote: > Jason Gerard DeRose wrote: > > On Thu, 2009-07-23 at 17:57 -0400, Rob Crittenden wrote: > >> A new way to identify the CAs to trust when importing a PKCS#12 file > >> (like during replica installation). We used to use certutil -O but > >>

Re: [Freeipa-devel] [PATCH] 242 new method to identify CAs to trust

2009-07-24 Thread Rob Crittenden
Jason Gerard DeRose wrote: On Thu, 2009-07-23 at 17:57 -0400, Rob Crittenden wrote: A new way to identify the CAs to trust when importing a PKCS#12 file (like during replica installation). We used to use certutil -O but Fedora 11 changed certutil so it doesn't show untrusted CAs (the whole poi

Re: [Freeipa-devel] [PATCH] 242 new method to identify CAs to trust

2009-07-23 Thread Jason Gerard DeRose
On Thu, 2009-07-23 at 17:57 -0400, Rob Crittenden wrote: > A new way to identify the CAs to trust when importing a PKCS#12 file > (like during replica installation). We used to use certutil -O but > Fedora 11 changed certutil so it doesn't show untrusted CAs (the whole > point of running the com