Bug 1265533 - [RFE] katello-certs-check to distinguish between Satellite and Capsule
[RFE] katello-certs-check to distinguish between Satellite and Capsule
Status: NEW
Product: Red Hat Satellite 6
Classification: Red Hat
Component: Installer (Show other bugs)
6.1.1
All Linux
high Severity medium (vote)
: GA
: --
Assigned To: satellite6-bugs
Katello QA List
: FutureFeature
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2015-09-23 03:49 EDT by Pavel Moravec
Modified: 2017-03-23 15:08 EDT (History)
6 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Pavel Moravec 2015-09-23 03:49:40 EDT
Description of problem:
Currently, katello-certs-check checks provided certs and suggest their usage by running katello-installer and/or capsule-certs-generate. Following the output, one can be confused where to use the certificates and there have been attempts to use Satellite's certs for Capsule.

Please remove this ambiguity by printing just katello-installer XOR capsule-certs-generate. It should be enough to compare "CN" part of Subject in the server cert with FQDN of the machine running the script. If those matches, it is assumed the certs are meant for the Satellite and just "katello-installer" part of output shall be printed. If FQDN doesn't match CN of Subject, print just "capsule-certs-generate" part.

(the above is based on assumption that CN of a server's certificate must match the server's FQDN - not sure if this is correct)

Ideally, there should be a line "Provided server's certificate was recognized as a cert for Satellite/Capsule", just to clarify to user the decision the script did.


Version-Release number of selected component (if applicable):
katello-installer-2.3.17-1.el7sat.noarch


How reproducible:
100%


Steps to Reproduce:
1. Have some custom certs and run
/usr/sbin/katello-certs-check


Actual results:
Currently it is ambiguous if I should run katello-installer or capsule-certs-generate.


Expected results:
The tool shall print our either katello-installer example XOR capsule-certs-generate example, not both.


Additional info:

Note You need to log in before you can comment on or make changes to this bug.