summaryrefslogtreecommitdiffstats
path: root/ipalib/plugins/host.py
diff options
context:
space:
mode:
authorRob Crittenden <rcritten@redhat.com>2010-12-10 10:53:20 -0500
committerRob Crittenden <rcritten@redhat.com>2010-12-13 09:58:26 -0500
commit5f8a9b9849ea81d0400d915dee055968d8c680e6 (patch)
tree82c89b477165a06b1905c4ae70cf272ba214c296 /ipalib/plugins/host.py
parentc9807f4b252055107118493b7d6b66309e3e0d27 (diff)
downloadfreeipa-5f8a9b9849ea81d0400d915dee055968d8c680e6.tar.gz
freeipa-5f8a9b9849ea81d0400d915dee055968d8c680e6.tar.xz
freeipa-5f8a9b9849ea81d0400d915dee055968d8c680e6.zip
Add --out option to service, host and cert-show to save the cert to a file.
Override forward() to grab the result and if a certificate is in the entry and the file is writable then dump the certificate in PEM format. ticket 473
Diffstat (limited to 'ipalib/plugins/host.py')
-rw-r--r--ipalib/plugins/host.py21
1 files changed, 21 insertions, 0 deletions
diff --git a/ipalib/plugins/host.py b/ipalib/plugins/host.py
index a823fe001..22cd424ed 100644
--- a/ipalib/plugins/host.py
+++ b/ipalib/plugins/host.py
@@ -81,6 +81,8 @@ from ipalib.plugins.service import split_principal
from ipalib.plugins.service import validate_certificate
from ipalib.plugins.service import normalize_certificate
from ipalib.plugins.service import set_certificate_attrs
+from ipalib.plugins.service import make_pem, check_writable_file
+from ipalib.plugins.service import write_certificate
from ipalib.plugins.dns import dns_container_exists, _attribute_types
from ipalib import _, ngettext
from ipalib import x509
@@ -577,6 +579,12 @@ class host_show(LDAPRetrieve):
Display information about a host.
"""
has_output_params = LDAPRetrieve.has_output_params + host_output_params
+ takes_options = LDAPRetrieve.takes_options + (
+ Str('out?',
+ doc=_('file to store certificate in'),
+ ),
+ )
+
member_attributes = ['managedby']
def post_callback(self, ldap, dn, entry_attrs, *keys, **options):
@@ -591,6 +599,19 @@ class host_show(LDAPRetrieve):
return dn
+ def forward(self, *keys, **options):
+ if 'out' in options:
+ check_writable_file(options['out'])
+ result = super(host_show, self).forward(*keys, **options)
+ if 'usercertificate' in result['result']:
+ write_certificate(result['result']['usercertificate'][0], options['out'])
+ result['summary'] = _('Certificate stored in file \'%(file)s\'') % dict(file=options['out'])
+ return result
+ else:
+ raise errors.NoCertificateError(entry=keys[-1])
+ else:
+ return super(host_show, self).forward(*keys, **options)
+
api.register(host_show)