1
--- a/ipa-client/ipa-install/ipa-client-install
2
+++ b/ipa-client/ipa-install/ipa-client-install
3
@@ -201,7 +201,7 @@ def log_service_error(name, action, erro
4
root_logger.error("%s failed to %s: %s", name, action, str(error))
6
def nickname_exists(nickname):
7
- (sout, serr, returncode) = run(["/usr/bin/certutil", "-L", "-d", "/etc/pki/nssdb", "-n", nickname], raiseonerr=False)
8
+ (sout, serr, returncode) = run(["/usr/bin/certutil", "-L", "-d", "sql:/etc/pki/nssdb", "-n", nickname], raiseonerr=False)
12
@@ -365,7 +365,7 @@ def uninstall(options, env):
13
# Remove our host cert and CA cert
14
if nickname_exists("IPA CA"):
16
- run(["/usr/bin/certutil", "-D", "-d", "/etc/pki/nssdb", "-n", "IPA CA"])
17
+ run(["/usr/bin/certutil", "-D", "-d", "sql:/etc/pki/nssdb", "-n", "IPA CA"])
20
"Failed to remove IPA CA from /etc/pki/nssdb: %s", str(e))
21
@@ -393,7 +393,7 @@ def uninstall(options, env):
23
if nickname_exists(client_nss_nickname):
25
- run(["/usr/bin/certutil", "-D", "-d", "/etc/pki/nssdb", "-n", client_nss_nickname])
26
+ run(["/usr/bin/certutil", "-D", "-d", "sql:/etc/pki/nssdb", "-n", client_nss_nickname])
28
root_logger.error("Failed to remove %s from /etc/pki/nssdb: %s",
29
client_nss_nickname, str(e))
30
@@ -2297,7 +2297,7 @@ def install(options, env, fstore, states
32
# Add the CA to the default NSS database and trust it
34
- run(["/usr/bin/certutil", "-A", "-d", "/etc/pki/nssdb", "-n", "IPA CA", "-t", "CT,C,C", "-a", "-i", CACERT])
35
+ run(["/usr/bin/certutil", "-A", "-d", "sql:/etc/pki/nssdb", "-n", "IPA CA", "-t", "CT,C,C", "-a", "-i", CACERT])
36
except CalledProcessError, e:
37
root_logger.info("Failed to add CA to the default NSS database.")
38
return CLIENT_INSTALL_ERROR
41
@@ -322,7 +322,7 @@ class SSLTransport(LanguageAwareTranspor
42
if self._connection and host == self._connection[0]:
43
return self._connection[1]
45
- dbdir = '/etc/pki/nssdb'
46
+ dbdir = 'sql:/etc/pki/nssdb'
47
no_init = self.__nss_initialized(dbdir)
48
if sys.version_info < (2, 7):
49
conn = NSSHTTPS(host, 443, dbdir=dbdir, no_init=no_init)