Bug 1252540 - katello-certs-check should check the certificate type
Summary: katello-certs-check should check the certificate type
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Red Hat Satellite
Classification: Red Hat
Component: Installation
Version: 6.1.0
Hardware: Unspecified
OS: Unspecified
unspecified
medium
Target Milestone: Unspecified
Assignee: Chris Roberts
QA Contact: Katello QA List
URL: http://projects.theforeman.org/issues...
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2015-08-11 16:11 UTC by Fred van Zwieten
Modified: 2017-08-01 20:35 UTC (History)
9 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2017-08-01 20:35:00 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Foreman Issue Tracker 16299 0 Normal Resolved katello-certs-check should check the certificate type 2020-10-20 19:42:27 UTC

Description Fred van Zwieten 2015-08-11 16:11:55 UTC
Description of problem:
We were under impression that the custom certificate needed to be a ca cert. It needs to be a server cert. However running katello-certs-check did not complain about this. It did give problems later in the process (yum was not able to communicate with satellite) 

Version-Release number of selected component (if applicable):


How reproducible:
Create a custom ca cert, signed by a custom root ca and feed it to the katello-certs-check. It doesn't complain.

Steps to Reproduce:
1.
2.
3.

Actual results:
Validation successful

Expected results:
Validation unsuccessful, wrong certificate type

Additional info:

Comment 3 Ivan Necas 2015-12-11 08:39:43 UTC
Yes, the check script is mainly checking the formats of the cert files, but it not bulletproof and we still need to document the requirements. For example, we can't verify with the script, if the CN matches the needs (to match the fqdn of the server it will be used on),

Comment 5 Bryan Kearney 2016-07-26 15:25:24 UTC
Moving 6.2 bugs out to sat-backlog.

Comment 6 Bryan Kearney 2016-07-26 15:41:51 UTC
Moving 6.2 bugs out to sat-backlog.

Comment 8 Stephen Benjamin 2016-08-25 16:50:56 UTC
Created redmine issue http://projects.theforeman.org/issues/16299 from this bug

Comment 10 Bryan Kearney 2017-08-01 20:35:00 UTC
Thank you for your interest in Satellite 6. We have evaluated this request, and we do not expect this to be implemented in product in the foreseeable future. We are therefore closing this out as WONTFIX. If you have any concerns about this, please feel free to contact Rich Jerrido or Bryan Kearney. Thank you.


Note You need to log in before you can comment on or make changes to this bug.