URL: https://github.com/freeipa/freeipa/pull/355
Title: #355: Set up DS TLS on replica in CA-less topology

pvoborni commented:
"""
Running `ipa-certupdate` on all systems after `ipa-ca-install` is problematic. 
But we can at least make sure that `ipa-ca-install` on replica will get 
whatever is possible automatically at beginning (e.g. run equivalent of 
`ipa-certupdate`) and also that it have usable state after finishing 
`ipa-ca-install`, i.e., it will run IPA whatever IPA calls it needs and 
possible.  Anyway it is for other ticket. Maybe it already exists.
"""

See the full comment at 
https://github.com/freeipa/freeipa/pull/355#issuecomment-268754796
-- 
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Reply via email to