Bug 2327302
| Summary: | Cloned CA not adhering to NextRange for serial numbers | |||
|---|---|---|---|---|
| Product: | Red Hat Certificate System | Reporter: | Marco Fargetta <mfargett> | |
| Component: | pki-core | Assignee: | RHCS Maintainers <rhcs-maint> | |
| Status: | CLOSED ERRATA | QA Contact: | idm-cs-qe-bugs | |
| Severity: | high | Docs Contact: | ||
| Priority: | high | |||
| Version: | 10.8 | CC: | edewata, msauton, skhandel, taherrin | |
| Target Milestone: | rc | Keywords: | MigratedToJIRA | |
| Target Release: | certsys-10.8 | |||
| Hardware: | Unspecified | |||
| OS: | Unspecified | |||
| Whiteboard: | ||||
| Fixed In Version: | redhat-pki-10-8100020250213180344.f9354743 | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | ||
| Clone Of: | ||||
| : | 2329472 (view as bug list) | Environment: | ||
| Last Closed: | 2025-03-31 13:35:27 UTC | Type: | Bug | |
| Regression: | --- | Mount Type: | --- | |
| Documentation: | --- | CRM: | ||
| Verified Versions: | Category: | --- | ||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
| Cloudforms Team: | --- | Target Upstream Version: | ||
| Embargoed: | ||||
| Bug Depends On: | ||||
| Bug Blocks: | 2329472 | |||
|
Description
Marco Fargetta
2024-11-19 14:42:10 UTC
Fixed implementing a new serial generator, SSNv2 documented here: https://github.com/dogtagpki/pki/wiki/Sequential-Serial-Numbers-v2 Migration from current serial id to the new SSNv2: https://github.com/dogtagpki/pki/wiki/Migrating-to-Sequential-Serial-Numbers-v2 Fixed in:
commit 475b58c996abc1999376684b60ef160955930544
Author: Marco Fargetta <mfargett>
Date: Thu Nov 14 18:10:18 2024 +0100
Fix range update to legacy2 with clone
When a new clone is deployed it get the initial allocation from the
current range or the next range already allocated. The code was not
considering the case of next range so it could generate a range overlap.
The fix will check if the next range is totally allocate for the service
or it is partial and in this case only the remaining part is used.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (CA bug fix and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2025:3401 The needinfo request[s] on this closed bug have been removed as they have been unresolved for 120 days |