summaryrefslogtreecommitdiffstats
path: root/ipaserver
diff options
context:
space:
mode:
authorJan Cholasta <jcholast@redhat.com>2014-06-09 14:51:23 +0200
committerPetr Viktorin <pviktori@redhat.com>2014-07-30 16:04:21 +0200
commit52f72ec058f11b3ca494c696f7d6a5e16b44cd49 (patch)
tree1a29ffbc9c2d9891b07f06267aebe4aa3440f4e7 /ipaserver
parent1778f0ebc95bf53c2746ce5461f76458c40560cd (diff)
downloadfreeipa-52f72ec058f11b3ca494c696f7d6a5e16b44cd49.tar.gz
freeipa-52f72ec058f11b3ca494c696f7d6a5e16b44cd49.tar.xz
freeipa-52f72ec058f11b3ca494c696f7d6a5e16b44cd49.zip
Do not treat the IPA RA cert as CA cert in DS NSS database.
Reviewed-By: Rob Crittenden <rcritten@redhat.com>
Diffstat (limited to 'ipaserver')
-rw-r--r--ipaserver/install/certs.py2
1 files changed, 1 insertions, 1 deletions
diff --git a/ipaserver/install/certs.py b/ipaserver/install/certs.py
index 90d04a3fb..e201c2529 100644
--- a/ipaserver/install/certs.py
+++ b/ipaserver/install/certs.py
@@ -461,7 +461,7 @@ class CertDB(object):
do that step."""
# export the CA cert for use with other apps
ipautil.backup_file(self.cacert_fname)
- root_nicknames = self.find_root_cert(nickname)
+ root_nicknames = self.find_root_cert(nickname)[:-1]
fd = open(self.cacert_fname, "w")
for root in root_nicknames:
(cert, stderr, returncode) = self.run_certutil(["-L", "-n", root, "-a"])