roy liang via FreeIPA-users wrote:
> On 25.7.2022 16.33, Rob Crittenden wrote:
>
> libnsspem has been in the distro since 18.04 ("bionic"), though it's
> called nss-plugin-pem since
>
> I think this installation was somehow rolled manually, because the
> packaging has used the right nssdb location for a long time now
ubuntu16.04 not libnsspem
Should have used LiBNSS3?
root@migration-ipa-65-186:/home/liangrui# dpkg -l|grep libnss3
ii libnss3:amd64 2:3.28.4-0ubuntu0.16.04.14 amd64
Network Security Service libraries
ii libnss3:i386 2:3.28.4-0ubuntu0.16.04.14 i386
Network Security Service libraries
ii libnss3-1d:amd64 2:3.28.4-0ubuntu0.16.04.14 amd64
Network Security Service libraries - transitional package
ii libnss3-dev:amd64 2:3.28.4-0ubuntu0.16.04.14 amd64
Development files for the Network Security Service libraries
ii libnss3-nssdb 2:3.28.4-0ubuntu0.16.04.14 all
Network Security Security libraries - shared databases
ii libnss3-tools 2:3.28.4-0ubuntu0.16.04.14 amd64
Network Security Service tools
You may want to broaden your search for just pem.
It's possible this was never available in your release. I don't know if
it can be backported or not.
What this does is lets flat files, which in this case contain the RA
certificate and private key necessary for IPA to authenticate to the CA,
be used by an NSS database by making them appear as a PKCS#11 device.
rob