diff options
author | Rob Crittenden <rcritten@redhat.com> | 2009-04-22 14:35:27 -0400 |
---|---|---|
committer | Rob Crittenden <rcritten@redhat.com> | 2009-04-24 16:22:38 -0400 |
commit | d5290a60f95ba816a8c3fc9aa7066f25bda74698 (patch) | |
tree | bc0c5860fcf97f2cfda4e13ad4dc803c2db30371 /ipapython | |
parent | 298d5fbce48411d591a3a6ce39ee08ca817866d4 (diff) | |
download | freeipa-d5290a60f95ba816a8c3fc9aa7066f25bda74698.tar.gz freeipa-d5290a60f95ba816a8c3fc9aa7066f25bda74698.tar.xz freeipa-d5290a60f95ba816a8c3fc9aa7066f25bda74698.zip |
Utilities for dealing with dogtag
Diffstat (limited to 'ipapython')
-rw-r--r-- | ipapython/dogtag.py | 41 |
1 files changed, 41 insertions, 0 deletions
diff --git a/ipapython/dogtag.py b/ipapython/dogtag.py new file mode 100644 index 000000000..d0afbb122 --- /dev/null +++ b/ipapython/dogtag.py @@ -0,0 +1,41 @@ +# Authors: Rob Crittenden <rcritten@redhat.com> +# +# Copyright (C) 2009 Red Hat +# see file 'COPYING' for use and warranty information +# +# This program is free software; you can redistribute it and/or +# modify it under the terms of the GNU General Public License as +# published by the Free Software Foundation; version 2 only +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program; if not, write to the Free Software +# Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA +# + +from ipalib import api +import httplib +import xml.dom.minidom + +def get_ca_certchain(): + """ + Retrieve the CA Certificate chain from the configured Dogtag server. + """ + chain = None + conn = httplib.HTTPConnection(api.env.ca_host, 9180) + conn.request("GET", "/ca/ee/ca/getCertChain") + res = conn.getresponse() + if res.status == 200: + data = res.read() + + doc = xml.dom.minidom.parseString(data) + item_node = doc.getElementsByTagName("ChainBase64") + chain = item_node[0].childNodes[0].data + doc.unlink() + conn.close() + + return chain |