Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1565519 - Clarify the need to restart services in ipa-server-certinstall(1) [rhel-7.5.z]
Clarify the need to restart services in ipa-server-certinstall(1) [rhel-7.5.z]
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: ipa (Show other bugs)
7.4
Unspecified Unspecified
high Severity unspecified
: rc
: ---
Assigned To: IPA Maintainers
ipa-qe
: ZStream
Depends On: 1518157
Blocks:
  Show dependency treegraph
 
Reported: 2018-04-10 04:18 EDT by Oneata Mircea Teodor
Modified: 2018-05-14 12:11 EDT (History)
9 users (show)

See Also:
Fixed In Version: ipa-4.5.4-10.el7_5.1
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: 1518157
Environment:
Last Closed: 2018-05-14 12:11:15 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2018:1395 None None None 2018-05-14 12:11 EDT

  None (edit)
Description Oneata Mircea Teodor 2018-04-10 04:18:37 EDT
This bug has been copied from bug #1518157 and has been proposed to be backported to 7.5 z-stream (EUS).
Comment 3 Mohammad Rizwan 2018-04-12 06:28:30 EDT
Version:
ipa-server-4.5.4-10.el7_5.1.x86_64

Actual resutl:
[root@master ~]# man ipa-server-certinstall

[..]
DESCRIPTION
       Replace  the current Directory server SSL certificate, Apache server SSL certificate and/or Kerberos KDC certificate with the certificate in the specified files.
       The files are accepted in PEM and DER certificate, PKCS#7 certificate chain, PKCS#8 and raw private key and PKCS#12 formats.

       PKCS#12 is a file format used to safely transport SSL certificates and public/private keypairs.

       They may be generated and managed using the NSS pk12util command or the OpenSSL pkcs12 command.

       The service(s) are not automatically restarted. In order to use the newly installed certificate(s) you will need to manually restart the Directory, Apache and/or Krb5kdc servers.

[..]

Expected result:

The man page should clearly list all services that need to be restarted if the certificate(s) changed.


Making the bug verified based on above observations.
Comment 6 errata-xmlrpc 2018-05-14 12:11:15 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2018:1395

Note You need to log in before you can comment on or make changes to this bug.