[Freeipa-devel] [PATCH] 0079 Set default OCSP URI on install and upgrade

Martin Basti mbasti at redhat.com
Tue Jun 28 17:18:09 UTC 2016



On 28.06.2016 12:32, Martin Basti wrote:
>
>
> On 28.06.2016 12:31, Martin Basti wrote:
>>
>>
>> On 27.06.2016 14:22, Martin Basti wrote:
>>>
>>>
>>> On 27.06.2016 14:10, Fraser Tweedale wrote:
>>>> On Mon, Jun 27, 2016 at 02:02:15PM +0200, Martin Basti wrote:
>>>>>
>>>>> On 27.06.2016 13:58, Fraser Tweedale wrote:
>>>>>> Hi all,
>>>>>>
>>>>>> The attached patch fixes the OCSP URI in the Dogtag CA and system
>>>>>> certificates (https://fedorahosted.org/freeipa/ticket/5956).  It
>>>>>> depends on a patch[1] for Dogtag which is expected to be released in
>>>>>> v10.3.4.  In the meantime, you can test with the build of v10.3.4
>>>>>> from my COPR[2].
>>>>>>
>>>>>> [1] 
>>>>>> https://www.redhat.com/archives/pki-devel/2016-June/msg00138.html
>>>>>> [2] https://copr.fedorainfracloud.org/coprs/ftweedal/freeipa/
>>>>>>
>>>>>> Cheers,
>>>>>> Fraser
>>>>>>
>>>>>>
>>>>> Hello,
>>>>>
>>>>> this upgrade is executed always, is it on purpose?
>>>>> If not please use sysupgrade and run upgrade only once
>>>>>
>>>> It is intentional; the directive only gets added if it is missing.
>>>> I do not see any benefit in gating it with the sysupgrade mechanism.
>>>>
>>>> Thanks,
>>>> Fraser
>>> Ok
>>>
>> ************* Module ipaserver.install.cainstance
>> ipaserver/install/cainstance.py:465: [E0602(undefined-variable), 
>> CAInstance.__spawn_instance] Undefined variable 'IPA_CA_RECORD')
>>
>> you need ipalib.constants.IPA_CA_RECORD
>>
>> Martin^2
>>
> Ahh nevermind, this is a clash of different patches, works on master :)
>
ACK

Pushed to master: 45daffa22fcc6c481a8302f1947a5e0ded0b3eb8




More information about the Freeipa-devel mailing list