Bug 1263789

Summary: [RFE] All Host Certificate generation should allow TLSA DNS record generation
Product: Red Hat Enterprise Linux 7 Reporter: Martin Poole <mpoole>
Component: ipaAssignee: Florence Blanc-Renaud <frenaud>
Status: CLOSED DEFERRED QA Contact: Namita Soman <nsoman>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 7.2CC: afarley, ldelouw, mkosek, pasik, pcech, pvoborni, rcritten
Target Milestone: rcKeywords: FutureFeature
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Enhancement
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-12-09 19:42:06 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Martin Poole 2015-09-16 17:14:34 UTC
Description of problem:

When generating Host Certificates it should be possible to specify that TLSA DNS records be generated.

Additionally/Alternatively the "Show Certificate" option should list the various likely options for TLSA records. Most pertinently it should give the SHA256 for the full cert and for the subject rather than forcing the user to locate the cert and perform some manual work to determine the values.

The defaults should be

  Certificate Usage - 3

  Selector - 0

  Matching Type - 1


The sort order should be improved in the GUI to ensure that service selector components like TLSA records are located under the host record.

Possibly consider putting TLSA records in as

  _cert.host TLSA a b c nnnnnnnnnn

and providing simpler mech to create

  _port._(tcp|udp).host CNAME _cert.host

records.

Comment 2 Petr Vobornik 2015-09-18 13:57:20 UTC
Upstream ticket:
https://fedorahosted.org/freeipa/ticket/5312

Comment 3 Petr Vobornik 2017-04-06 16:15:58 UTC
IdM team doesn't have capacity to implement this RFE for RHEL 7.4. Moving to next RHEL version. Implementing the RFE there will depend on capacity of FreeIPA upstream. Without sufficient justification there is a chance that it will be moved again later.

Comment 7 Petr Čech 2019-12-09 19:42:06 UTC
Once the upstream community implements this feature it will be pulled into a corresponding Red Hat Enterprise Linux release following the corresponding schedules.
From now on this issue will be tracked in the community issue tracker only.
Closing this BZ.