[Freeipa-users] Centos7, selinux, certmonger, and openldap

Martin Kosek mkosek at redhat.com
Tue Aug 5 06:54:38 UTC 2014


On 08/04/2014 07:06 PM, Nordgren, Bryce L -FS wrote:
> 
>> Hmm, sorry for incomplete instructions then. I updated the instructions to
>> cope with that situation better (details in
>> https://fedorahosted.org/freeipa/ticket/4466#comment:2). Please feel free
>> to report more findings or even better help us enhance the page even
>> further :-)
> 
> Hmm, I thought it looked like your wiki, but when there was no login in the upper-right corner, I assumed it was an online version of your manual. That always gets me, even when I'm looking at a page I know I created myself.

Ah, that's a useful UXD feedback as it seems. BTW, to log in, check "Log in /
create account with OpenID" in the LOWER right corner...

> 
> In this case, tho, I was definitely not qualified to provide a fix. New to both certmonger and that Mozilla certificate database thing.

Don't worry, you will get there.

> Made a comment on the talk page about the related OpenLDAP selinux issues (more than one cert_t defined). Dunno if you get notifications.

Ok. IMO this is a valid bug, system policy should allow certmonger to manage
other cert types. Thanks for filing it.

Martin




More information about the Freeipa-users mailing list