Bug 1389348

Summary: ipa-server-certinstall does not update all certificate stores and doesn't set proper trust permissions
Product: Red Hat Enterprise Linux 7 Reporter: Jaroslav Reznik <jreznik>
Component: ipaAssignee: IPA Maintainers <ipa-maint>
Status: CLOSED ERRATA QA Contact: Kaleem <ksiddiqu>
Severity: medium Docs Contact: Marc Muehlfeld <mmuehlfe>
Priority: high    
Version: 7.2CC: akasurde, apetrova, frenaud, ipa-maint, jcholast, jreznik, mbasti, mmuehlfe, nsoman, pvoborni, rcritten, tscherf
Target Milestone: rcKeywords: ZStream
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: ipa-4.4.0-13.el7_3 Doc Type: Bug Fix
Doc Text:
Previously, when installing a third-party service certificate, the ipa-server-certinstall utility did not verify if the certificate was issued by a certificate authority (CA) known to Identity Management (IdM). Consequently, certificates issued by an unknown CA could be installed, and services using these certificates failed to start or worked incorrectly. A patch has been applied and as a result, the ipa-server-certinstall utility now verifies if the certificate to be installed has been issued by a CA known to IdM.
Story Points: ---
Clone Of: 1360813 Environment:
Last Closed: 2016-12-06 17:02:46 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On: 1360813    
Bug Blocks:    
Attachments:
Description Flags
console.log none

Description Jaroslav Reznik 2016-10-27 13:27:23 UTC
This bug has been copied from bug #1360813 and has been proposed
to be backported to 7.3 z-stream (EUS).

Comment 7 Abhijeet Kasurde 2016-11-10 09:29:08 UTC
Created attachment 1219256 [details]
console.log

Comment 8 Abhijeet Kasurde 2016-11-10 09:29:49 UTC
Verified using IPA version ::
ipa-server-4.4.0-14.el7_3.x86_64

Marking BZ as verified.

Comment 12 errata-xmlrpc 2016-12-06 17:02:46 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2016-2863.html