diff options
author | Zbigniew Kurzynski <zbigniew.kurzynski@intel.com> | 2019-10-10 13:39:21 +0300 |
---|---|---|
committer | Brad Bishop <bradleyb@fuzziesquirrel.com> | 2019-11-05 22:00:57 +0300 |
commit | 8401702b28725a9c52a203b2b0dc839679a63aa5 (patch) | |
tree | d8d8b6f3c35c9871db70d8b240fc2f189e2736f8 /meta-phosphor/recipes-phosphor/certificate/phosphor-nslcd-authority-cert-config | |
parent | 2b59705148feb8ca6aafd9cf050229b069284515 (diff) | |
download | openbmc-8401702b28725a9c52a203b2b0dc839679a63aa5.tar.xz |
Support uploading multiple certificates per authority service
Since the certificate manager can support multiple certificates
the CERTPATH for mode=authentication will be changed to directory.
This change depends on anothere review, see Depends-On tag.
Becase the TrustStore will be used by TLS authentication,
any operation on certificates should result in bmcweb restart, that
is why #Units to restart entry is added.
Since update procedure will not replace configuration file in /etc
all configuration files for the certificate-manager will be deployed
in /usr/share/phosphor-certificate-manager.
(From meta-phosphor rev: 0c09ff71d089c614b14d076d933e849f2f74281e)
Signed-off-by: Zbigniew Kurzynski <zbigniew.kurzynski@intel.com>
Change-Id: Ib7f4ba60760ab8cd1ac647bc51dadf50af7fedc7
Signed-off-by: Brad Bishop <bradleyb@fuzziesquirrel.com>
Diffstat (limited to 'meta-phosphor/recipes-phosphor/certificate/phosphor-nslcd-authority-cert-config')
-rw-r--r-- | meta-phosphor/recipes-phosphor/certificate/phosphor-nslcd-authority-cert-config/env | 5 |
1 files changed, 4 insertions, 1 deletions
diff --git a/meta-phosphor/recipes-phosphor/certificate/phosphor-nslcd-authority-cert-config/env b/meta-phosphor/recipes-phosphor/certificate/phosphor-nslcd-authority-cert-config/env index 849d695b51..d2e8814cb6 100644 --- a/meta-phosphor/recipes-phosphor/certificate/phosphor-nslcd-authority-cert-config/env +++ b/meta-phosphor/recipes-phosphor/certificate/phosphor-nslcd-authority-cert-config/env @@ -3,7 +3,10 @@ ENDPOINT=ldap #Path for the certificate file -CERTPATH=/etc/ssl/certs/Root-CA.pem +CERTPATH=/etc/ssl/certs/authority + +#Units to restart +UNIT=bmcweb.service #Type of service TYPE=authority |