[Freeipa-devel] [PATCH] 0043 Allow-PKI-CA-Replica-Installs-when-CRL-exceeds-default

Simo Sorce simo at redhat.com
Wed Dec 19 22:32:33 UTC 2012


On Wed, 2012-12-19 at 20:52 +0000, JR Aquino wrote:
> Due to a limitation with 389 DS, the nsslapd-maxbersize cannot be set dynamically.
> This causes an issue during IPA PKI-CA Replica installs, when the master has a CRL that exceeds the default limit.
> The cainstance.py code attempts to set this value prior to performing the initial PKI-CA replication, however, since the value cannot be set dynamically, the installation fails.
> 
> This patch works around the issue by adding the ldif to the original initialization values bootstrapped by the call to setup-ds.pl

Why are we not simply restarting the instance after setting the value ?

What's in database.ldif ? What produces it ?

Simo.

-- 
Simo Sorce * Red Hat, Inc * New York




More information about the Freeipa-devel mailing list