diff options
author | Fraser Tweedale <ftweedal@redhat.com> | 2015-06-04 22:49:01 -0400 |
---|---|---|
committer | Petr Vobornik <pvoborni@redhat.com> | 2015-06-05 19:12:46 +0200 |
commit | ce33f82cfe528c17d3a1367172bb1475fe169b25 (patch) | |
tree | e3ccd4d72b8b00eddddb284ff9951f88799ebe90 /ipaserver | |
parent | d25a45a9f99aa5d841f47baa0332f49223ecffca (diff) | |
download | freeipa-ce33f82cfe528c17d3a1367172bb1475fe169b25.tar.gz freeipa-ce33f82cfe528c17d3a1367172bb1475fe169b25.tar.xz freeipa-ce33f82cfe528c17d3a1367172bb1475fe169b25.zip |
Fix certificate subject base
Profile management patches introduced a regression where a custom
certificate subject base (if configured) is not used in the default
profile. Use the configured subject base.
Part of: https://fedorahosted.org/freeipa/ticket/4002
Reviewed-By: Martin Basti <mbasti@redhat.com>
Diffstat (limited to 'ipaserver')
-rw-r--r-- | ipaserver/install/cainstance.py | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/ipaserver/install/cainstance.py b/ipaserver/install/cainstance.py index ca0b6df5d..42225c28c 100644 --- a/ipaserver/install/cainstance.py +++ b/ipaserver/install/cainstance.py @@ -1665,7 +1665,7 @@ def import_included_profiles(): DOMAIN=ipautil.format_netloc(api.env.domain), IPA_CA_RECORD=IPA_CA_RECORD, CRL_ISSUER='CN=Certificate Authority,o=ipaca', - SUBJECT_DN_O=str(DN(('O', api.env.realm))), + SUBJECT_DN_O=dsinstance.DsInstance().find_subject_base(), ) server_id = installutils.realm_to_serverid(api.env.realm) |