[Freeipa-devel] [PATCH] fix replica-install to use SSL connections early on

Stephen Gallagher sgallagh at redhat.com
Tue Aug 12 13:10:14 UTC 2008


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Simo Sorce wrote:
> This patch install the ca.crt file early on and enforce the use of SSL
> to set up the replication agreement.
> 
> 
> ------------------------------------------------------------------------

I don't like the use of the hard-coded CACERT variable. We're trying to
eliminate the use of hard-coded paths. See Bugzilla #430000 for more
details.

I also don't understand why you removed the try/except block around the
LDAP bind in replication.py. What exactly did that gain us?

- --

- --------------------
Stephen Gallagher
RHCE 804006346421761
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org

iEYEARECAAYFAkihi7YACgkQc7MaxVic+2oGtwCdH34pqpZgvZ7O4MpDwO0KhBZ+
dAYAoKQWxWdqCPdwpCKyKNCQ3bjSnZBO
=kaJL
-----END PGP SIGNATURE-----




More information about the Freeipa-devel mailing list