Bug 1565519 - Clarify the need to restart services in ipa-server-certinstall(1) [rhel-7.5.z]
Summary: Clarify the need to restart services in ipa-server-certinstall(1) [rhel-7.5.z]
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: ipa
Version: 7.4
Hardware: Unspecified
OS: Unspecified
Target Milestone: rc
: ---
Assignee: IPA Maintainers
QA Contact: ipa-qe
Depends On: 1518157
TreeView+ depends on / blocked
Reported: 2018-04-10 08:18 UTC by Oneata Mircea Teodor
Modified: 2018-05-14 16:11 UTC (History)
9 users (show)

Fixed In Version: ipa-4.5.4-10.el7_5.1
Doc Type: If docs needed, set a value
Doc Text:
Clone Of: 1518157
Last Closed: 2018-05-14 16:11:15 UTC
Target Upstream Version:

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2018:1395 0 None None None 2018-05-14 16:11:38 UTC

Description Oneata Mircea Teodor 2018-04-10 08:18:37 UTC
This bug has been copied from bug #1518157 and has been proposed to be backported to 7.5 z-stream (EUS).

Comment 3 Mohammad Rizwan 2018-04-12 10:28:30 UTC

Actual resutl:
[root@master ~]# man ipa-server-certinstall

       Replace  the current Directory server SSL certificate, Apache server SSL certificate and/or Kerberos KDC certificate with the certificate in the specified files.
       The files are accepted in PEM and DER certificate, PKCS#7 certificate chain, PKCS#8 and raw private key and PKCS#12 formats.

       PKCS#12 is a file format used to safely transport SSL certificates and public/private keypairs.

       They may be generated and managed using the NSS pk12util command or the OpenSSL pkcs12 command.

       The service(s) are not automatically restarted. In order to use the newly installed certificate(s) you will need to manually restart the Directory, Apache and/or Krb5kdc servers.


Expected result:

The man page should clearly list all services that need to be restarted if the certificate(s) changed.

Making the bug verified based on above observations.

Comment 6 errata-xmlrpc 2018-05-14 16:11:15 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.