[Freeipa-devel] [PATCH] 1091 Don't double-encode CA cert

Martin Kosek mkosek at redhat.com
Thu Mar 7 08:41:55 UTC 2013


On 03/06/2013 10:57 PM, Rob Crittenden wrote:
> When the CA cert was added via the update plugin we were double-encoding it. We
> just need to store the DER value.
> 
> See the ticket for reproduction details.
> 
> rob

This works fine. The certificate is now stored correctly in the attribute and
it can be properly read by ldapsearch and also decoded by tools like Apache
Directory Studio. Surprisingly, the double encoded format worked OK in the
ipa-client-install...

ACK. Pushed to master, ipa-3-1.

Martin




More information about the Freeipa-devel mailing list