Bug 1254641
| Summary: | Remove CSR allowed-extensions restriction | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Petr Vobornik <pvoborni> | ||||||
| Component: | ipa | Assignee: | IPA Maintainers <ipa-maint> | ||||||
| Status: | CLOSED ERRATA | QA Contact: | Namita Soman <nsoman> | ||||||
| Severity: | unspecified | Docs Contact: | |||||||
| Priority: | medium | ||||||||
| Version: | 7.2 | CC: | ftweedal, ipa-maint, jcholast, ksiddiqu, mkosek, rcritten | ||||||
| Target Milestone: | rc | ||||||||
| Target Release: | --- | ||||||||
| Hardware: | Unspecified | ||||||||
| OS: | Unspecified | ||||||||
| Whiteboard: | |||||||||
| Fixed In Version: | ipa-4.2.0-5.el7 | Doc Type: | Bug Fix | ||||||
| Doc Text: | Story Points: | --- | |||||||
| Clone Of: | Environment: | ||||||||
| Last Closed: | 2015-11-19 12:05:41 UTC | Type: | --- | ||||||
| Regression: | --- | Mount Type: | --- | ||||||
| Documentation: | --- | CRM: | |||||||
| Verified Versions: | Category: | --- | |||||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||||
| Embargoed: | |||||||||
| Attachments: |
|
||||||||
|
Description
Petr Vobornik
2015-08-18 14:40:33 UTC
Fixed upstream master: https://fedorahosted.org/freeipa/changeset/02969d09d868907c6d2d5b2aee3089f2f5540dda ipa-4-2: https://fedorahosted.org/freeipa/changeset/7723b3a677b7198bb59957c749d20053611bf32c Please provide the steps to verify this. You can use the attached `openssl req' config (tweak commonName as required) to produce a CSR with a formerly-prohibited extension. Then submit the request via `ipa cert-request' and ensure that, despite the presence of an unknown extension, the request succeeds. Created attachment 1082193 [details]
`openssl req' config to produce CSR with esoteric extension
Verified. IPA Version: ============ [root@dhcp207-115 ~]# rpm -q ipa-server ipa-server-4.2.0-14.el7.x86_64 [root@dhcp207-115 ~]# Please find the attached file for console output. Created attachment 1082311 [details]
console output with verification steps
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHBA-2015-2362.html |