[Freeipa-users] Using 3rd party certificates for HTTP/LDAP

Peter Pakos peter at pakos.pl
Thu Jan 14 21:18:15 UTC 2016


On 14/01/2016 18:51, Rob Crittenden wrote:
> You need to add the new root certs to the pki NSS database.

As far as I can see those 3 new CA certs are already in the database 
(unless you're talking about a different db):

$ certutil -d /etc/pki/nssdb/ -L

Certificate Nickname                                         Trust 
Attributes
 
SSL,S/MIME,JAR/XPI

IPA.WANDISCO.COM IPA CA                                      CT,C,C
AddTrust                                                     ,,
USERTrustRSAAddTrustCA                                       ,,
GandiStandardSSLCA2                                          ,,

Please advise.

-- 
Kind regards,
  Peter Pakos




More information about the Freeipa-users mailing list