Re: [Bug 1919563] updated sssd with smart cards now brick systems without full cert chain

2021-03-28 Thread Karl Grindley
Marco, Great! This should be easy for me to test, and I’d be happy to do so. I may be able to do a regression test to make sure the automated NSSDB -> openssl upgrade works as well. This would mean however that the upgrade would need to drop the appropriate sssd.conf.d to configure the

Re: [Bug 1919563] updated sssd with smart cards now brick systems without full cert chain

2021-03-18 Thread Karl Grindley
> On Mar 17, 2021, at 10:01 PM, Marco Trevisan (Treviño) > <1919...@bugs.launchpad.net> wrote: > > So, if I didn't get it wrong, if we'd just use /etc/ssl/certs/ca- > certificates.crt as the SSSD pam certificate in such case would work? While this would technically work, it would be really bad