Re: [Freeipa-devel] [PATCH] 304 hosts requesting certificates

2009-11-03 Thread Jason Gerard DeRose
On Tue, 2009-11-03 at 09:37 -0500, Rob Crittenden wrote: > Jason Gerard DeRose wrote: > > On Wed, 2009-10-28 at 17:41 -0400, Rob Crittenden wrote: > >> I had originally implemented allowing a host to request certificates for > >> other hosts using the requesting IP address. That was a pretty lousy

Re: [Freeipa-devel] [PATCH] 304 hosts requesting certificates

2009-11-03 Thread Rob Crittenden
Jason Gerard DeRose wrote: On Wed, 2009-10-28 at 17:41 -0400, Rob Crittenden wrote: I had originally implemented allowing a host to request certificates for other hosts using the requesting IP address. That was a pretty lousy way to do it. This patch uses the DS ACI system instead. We came up

Re: [Freeipa-devel] [PATCH] 304 hosts requesting certificates

2009-11-03 Thread Jason Gerard DeRose
On Wed, 2009-10-28 at 17:41 -0400, Rob Crittenden wrote: > I had originally implemented allowing a host to request certificates for > other hosts using the requesting IP address. That was a pretty lousy way > to do it. > > This patch uses the DS ACI system instead. We came up with a clever ACI

[Freeipa-devel] [PATCH] 304 hosts requesting certificates

2009-10-28 Thread Rob Crittenden
I had originally implemented allowing a host to request certificates for other hosts using the requesting IP address. That was a pretty lousy way to do it. This patch uses the DS ACI system instead. We came up with a clever ACI that lets hosts listed in the managedBy attribute in the service m