Bug 1244914
| Summary: | scep ca helper does not parse command line options correctly | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Kaleem <ksiddiqu> |
| Component: | certmonger | Assignee: | Jan Cholasta <jcholast> |
| Status: | CLOSED ERRATA | QA Contact: | Kaleem <ksiddiqu> |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | 7.2 | CC: | dkupka, nalin, nsoman |
| Target Milestone: | rc | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| URL: | https://git.fedorahosted.org/cgit/certmonger.git/commit/?id=365e2b388e1c44db22c5656f8cc283b5dabc8860 | ||
| Whiteboard: | |||
| Fixed In Version: | certmonger-0.78.3-1.el7 | Doc Type: | Bug Fix |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2015-11-19 11:59:11 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Kaleem
2015-07-20 18:32:52 UTC
This breaks SCEP to servers over HTTPS, and the same bug likely breaks dogtag-submit's parsing of -o and -O command-line options, which is functionality that IPA needs. Pulling the fixes for these in to the 0.78 branch and tagging an 0.78.3 release to fix it. Verified. Certmonger version: =================== [root@dhcp207-177 ~]# rpm -q certmonger certmonger-0.78.4-1.el7.x86_64 [root@dhcp207-177 ~]# Snip from console output: ========================= [root@yttrium ~]# getcert add-scep-ca -c scepca -u https://sceptest/CertSrv/mscep/mscep.dll -R /root/sceptest/ca-bundle.pem New CA "scepca" added. [root@yttrium ~]# getcert list-cas -c scepca CA 'scepca': is-default: no ca-type: EXTERNAL helper-location: /usr/libexec/certmonger/scep-submit -u https://sceptest/CertSrv/mscep/mscep.dll -R /root/sceptest/ca-bundle.pem SCEP CA certificate thumbprint (MD5): 15D13237 EA719245 DD02978F AB9EDB8C SCEP CA certificate thumbprint (SHA1): 890CB405 68D3EAB2 4A09CFAE BA49D623 A7BF7740 [root@yttrium ~]# getcert request -c scepca -k /root/sceptest/newkey.prv -f /root/sceptest/newcert.cer -I newtest -L EA90FEF73AD5DA5A203F590AC1428CCCNew signing request "newtest" added. [root@yttrium ~]# getcert list -i newtest Number of certificates and requests being tracked: 1. Request ID 'newtest': status: MONITORING stuck: no key pair storage: type=FILE,location='/root/sceptest/newkey.prv' certificate: type=FILE,location='/root/sceptest/newcert.cer' signing request thumbprint (MD5): 68393421 536D0CAA CD9EBD03 F1C853BA signing request thumbprint (SHA1): 7E24A0F5 3CBD01E3 49524694 6247C3C5 6396A8A9 CA: scepca issuer: CN=sceptest-SCEPTEST-CA,DC=sceptest,DC=qe subject: CN=yttrium.idmqe.lab.eng.bos.redhat.com expires: 2017-08-05 16:38:33 UTC dns: yttrium.idmqe.lab.eng.bos.redhat.com key usage: digitalSignature,keyEncipherment eku: iso.org.dod.internet.security.mechanisms.8.2.2 certificate template/profile: IPSECIntermediateOffline pre-save command: post-save command: track: yes auto-renew: yes [root@yttrium ~]# Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHBA-2015-2365.html |