Re: [Freeipa-users] certutil - how to delete an orphan key..

2016-04-09 Thread lejeczek



On 09/04/16 01:18, Fraser Tweedale wrote:

On Fri, Apr 08, 2016 at 03:39:49PM -0400, Rob Crittenden wrote:

Pawel Eljasz wrote:

.. would anybody know?
I realize this might be not the ideal place for such a question, sorry.
thanks
L



I don't know that there is a way using a tool to delete a key from an NSS
database. Why do you want to? It won't hurt anything.

rob


According to man page, to list contents of key database:

 certutil ... -K

and to delete a particular key:

 certutil ... -F -n $KEY_ID

well...
https://bugzilla.redhat.com/show_bug.cgi?id=1144186



Cheers,
Fraser



--
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project


Re: [Freeipa-users] certutil - how to delete an orphan key..

2016-04-08 Thread Rob Crittenden

Fraser Tweedale wrote:

On Fri, Apr 08, 2016 at 03:39:49PM -0400, Rob Crittenden wrote:

Pawel Eljasz wrote:

.. would anybody know?
I realize this might be not the ideal place for such a question, sorry.
thanks
L




I don't know that there is a way using a tool to delete a key from an NSS
database. Why do you want to? It won't hurt anything.

rob


According to man page, to list contents of key database:

 certutil ... -K

and to delete a particular key:

 certutil ... -F -n $KEY_ID


Can't believe I missed that, nice catch.

rob



--
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project


Re: [Freeipa-users] certutil - how to delete an orphan key..

2016-04-08 Thread Fraser Tweedale
On Fri, Apr 08, 2016 at 03:39:49PM -0400, Rob Crittenden wrote:
> Pawel Eljasz wrote:
> >.. would anybody know?
> >I realize this might be not the ideal place for such a question, sorry.
> >thanks
> >L
> >
> >
> 
> I don't know that there is a way using a tool to delete a key from an NSS
> database. Why do you want to? It won't hurt anything.
> 
> rob
> 
According to man page, to list contents of key database:

certutil ... -K

and to delete a particular key:

certutil ... -F -n $KEY_ID

Cheers,
Fraser

-- 
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project


Re: [Freeipa-users] certutil - how to delete an orphan key..

2016-04-08 Thread Rob Crittenden

Pawel Eljasz wrote:

.. would anybody know?
I realize this might be not the ideal place for such a question, sorry.
thanks
L




I don't know that there is a way using a tool to delete a key from an 
NSS database. Why do you want to? It won't hurt anything.


rob

--
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project


[Freeipa-users] certutil - how to delete an orphan key..

2016-04-08 Thread Pawel Eljasz
.. would anybody know?I realize this might be not the ideal place for such a 
question, sorry.thanksL
-- 
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project