[Freeipa-users] [PATCH] 512 track server certs with certmonger

2010-08-13 Thread Rob Crittenden
Have certmonger track the initial Apache and 389-ds server certs. We don't use certmonger to get certificates during installation because of the chicken-and-egg problem. This means that the IPA web and ldap certs aren't being tracked for renewal. This requires some manual changes to the certmong

[Freeipa-users] [PATCH] 511 improve dogtag install feedback and add arg to pkisilent

2010-08-13 Thread Rob Crittenden
Break out install into more steps, add -key_algorithm to pkisilent. Installing dogtag is quite slow and it isn't always clear that things are working. This breaks out some restart calls into separate steps to show some amount of progress. There are still some steps that take more than a minute