Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1563113 - [PATCH] 'rhui-manager cert upload' command does not update client cert and key of each RPM repos
[PATCH] 'rhui-manager cert upload' command does not update client cert and ke...
Status: CLOSED ERRATA
Product: Red Hat Update Infrastructure for Cloud Providers
Classification: Red Hat
Component: RHUA (Show other bugs)
3.0.0
All Linux
unspecified Severity high
: 3.0.3
: ---
Assigned To: RHUI Bug List
Vratislav Hutsky
:
: 1563045 (view as bug list)
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2018-04-03 03:34 EDT by Satoru SATOH
Modified: 2018-05-16 08:48 EDT (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2018-05-16 08:48:53 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2018:1569 None None None 2018-05-16 08:48 EDT

  None (edit)
Description Satoru SATOH 2018-04-03 03:34:45 EDT
Description of problem:
Current implementation of 'rhui-manager cert upload' and corresponding interactive command of rhui-manager (home -> [n] -> [u] ...) look broken due to incompatibilities in rebased version of pulp RHUI v3 using and cannot update all of necessary certs correctly.

It's my understanding that these commands only update the cert in /etc/pki/rhui/redhat/ and does not update client cert and key of each Red Hat RPM repos saved in /var/lib/rhui/remote_share/<repo_id>_yum_importer/pki/. As a result, each repos' importer will fail to sync contents from the Red Hat CDN after updating the (content) cert.

Version-Release number of selected component (if applicable): rh-rhui-tools-libs-3.0.1-3.el7ui

How reproducible: Always, I think.

Steps to Reproduce:
1. Update the RHUI entitlement (content) cert with using 'rhui-manager cert upload' command or its interactive shell command
2. Check the timestamp of /etc/pki/rhui/redhat/*.pem and /var/lib/rhui/remote_share/<repo_id>_yum_importer/pki/client{.cert,key}, and/or try to sync some of repos.

Actual results: Client certs of each repo importers are not updated and it fails to sync repos.

Expected results: Client certs of each repo importers are updated along with the master cert in /etc/pki/rhui/redhat/, and it succeeds to sync repos.

Additional info:
I'll attach a couple of experimental patches taking a little bit different approaches should resolve this issue.
Comment 5 kfujii 2018-04-03 04:43:29 EDT
*** Bug 1563045 has been marked as a duplicate of this bug. ***
Comment 10 errata-xmlrpc 2018-05-16 08:48:53 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2018:1569

Note You need to log in before you can comment on or make changes to this bug.