diff options
author | Jan Cholasta <jcholast@redhat.com> | 2016-02-22 15:05:35 +0100 |
---|---|---|
committer | Jan Cholasta <jcholast@redhat.com> | 2016-02-24 10:53:28 +0100 |
commit | 11592dde1b232a70f318e01f5271b38890090648 (patch) | |
tree | 5aaeafb3a23893af2bc506c06c18404d930bd7f7 /ipatests/test_integration | |
parent | 775ee77bcc091ba31fdd3e59f8d45d0b646a44a0 (diff) | |
download | freeipa-11592dde1b232a70f318e01f5271b38890090648.tar.gz freeipa-11592dde1b232a70f318e01f5271b38890090648.tar.xz freeipa-11592dde1b232a70f318e01f5271b38890090648.zip |
client: stop using /etc/pki/nssdb
Don't put any IPA certificates to /etc/pki/nssdb - IPA itself uses
/etc/ipa/nssdb and IPA CA certificates are provided to the system using
p11-kit. Remove leftovers on upgrade.
https://fedorahosted.org/freeipa/ticket/5592
Reviewed-By: David Kupka <dkupka@redhat.com>
Diffstat (limited to 'ipatests/test_integration')
-rw-r--r-- | ipatests/test_integration/test_caless.py | 17 |
1 files changed, 0 insertions, 17 deletions
diff --git a/ipatests/test_integration/test_caless.py b/ipatests/test_integration/test_caless.py index 4dda79bf9..fdc4fc8ef 100644 --- a/ipatests/test_integration/test_caless.py +++ b/ipatests/test_integration/test_caless.py @@ -112,12 +112,6 @@ class CALessBase(IntegrationTest): # Remove the NSS database shutil.rmtree(cls.cert_dir) - # Remove CA cert in /etc/pki/nssdb, in case of failed (un)install - for host in cls.get_all_hosts(): - cls.master.run_command(['certutil', '-d', paths.NSS_DB_DIR, '-D', - '-n', 'External CA cert'], - raiseonerr=False) - super(CALessBase, cls).uninstall(mh) @classmethod @@ -343,12 +337,6 @@ class TestServerInstall(CALessBase): def tearDown(self): self.uninstall_server() - # Remove CA cert in /etc/pki/nssdb, in case of failed (un)install - for host in self.get_all_hosts(): - self.master.run_command(['certutil', '-d', paths.NSS_DB_DIR, '-D', - '-n', 'External CA cert'], - raiseonerr=False) - def test_nonexistent_ca_pem_file(self): "IPA server install with non-existent CA PEM file " @@ -769,12 +757,7 @@ class TestReplicaInstall(CALessBase): self.master.run_command(['ipa', 'host-del', replica.hostname], raiseonerr=False) - replica.run_command(['certutil', '-d', paths.NSS_DB_DIR, '-D', - '-n', 'External CA cert'], raiseonerr=False) - self.uninstall_server() - self.master.run_command(['certutil', '-d', paths.NSS_DB_DIR, '-D', - '-n', 'External CA cert'], raiseonerr=False) def test_no_certs(self): "IPA replica install without certificates" |