Bug 1601071
| Summary: | Certificate generation happens with partial attributes in CMCRequest file | |||
|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Geetika Kapoor <gkapoor> | |
| Component: | pki-core | Assignee: | Christina Fu <cfu> | |
| Status: | CLOSED ERRATA | QA Contact: | Asha Akkiangady <aakkiang> | |
| Severity: | high | Docs Contact: | ||
| Priority: | high | |||
| Version: | 7.5 | CC: | cfu, mharmsen, msauton | |
| Target Milestone: | rc | Keywords: | ZStream | |
| Target Release: | --- | |||
| Hardware: | All | |||
| OS: | Linux | |||
| Whiteboard: | ||||
| Fixed In Version: | pki-core-10.5.9-6.el7 | Doc Type: | No Doc Update | |
| Doc Text: |
undefined
|
Story Points: | --- | |
| Clone Of: | ||||
| : | 1611245 (view as bug list) | Environment: | ||
| Last Closed: | 2018-10-30 11:07:14 UTC | Type: | Bug | |
| Regression: | --- | Mount Type: | --- | |
| Documentation: | --- | CRM: | ||
| Verified Versions: | Category: | --- | ||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
| Cloudforms Team: | --- | Target Upstream Version: | ||
| Embargoed: | ||||
| Bug Depends On: | ||||
| Bug Blocks: | 1611245 | |||
|
Comment 2
Christina Fu
2018-08-01 01:13:10 UTC
patch cherry-picked from DOGTAG_10_5_BRANCH https://review.gerrithub.io/c/dogtagpki/pki/+/421026 commit 2609383417755d81419cc6f53d1d9853fdc906df (HEAD -> master, origin/master, origin/HEAD, bug-1601071-CMCSelfSigned-master)
Author: Christina Fu <cfu>
Date: Mon Jul 30 17:15:09 2018 -0700
Bug 1601071 Certificate generation happens with partial attributes in CMCRequest file
This patch addresses the issue where when a cmcSelfSisnged profile is used
in a cmcUserSigned case, the certificate is issued.
A new authToken variable TOKEN_SHARED_TOKEN_AUTHENTICATED_CERT_SUBJECT has
been introduced for shared token case so that the TOKEN_AUTHENTICATED_CERT_SUBJECT can be used for user-signed case.
A new constraint CMCSelfSignedSubjectNameConstraint has been introduced
to verify.
In additional, all profiles that authenticate through CMCUserSignedAuth are
turned off by default to allow site administrators to make conscious decision
on their own for these features.
Also, audit event CERT_STATUS_CHANGE_REQUEST_PROCESSED is now enabled by default.
Change-Id: I8405b2e83f7ea3e3da98164cbc87762cdfa7475f
Hi Christina, I saw that you have changed enable=true to enable=false so bydefault it is disabled and when i try to use this profile i need to enable it before using it with httpclient. Not sure if it is expected? Thanks Geetika Marking this bug verified.I will ask/raise a new bug if Christina feels Comment7 looks like an issue and customer might need it. (In reply to Geetika Kapoor from comment #7) > Hi Christina, > > I saw that you have changed enable=true to enable=false so bydefault it is > disabled and when i try to use this profile i need to enable it before using > it with httpclient. Not sure if it is expected? > > Thanks > Geetika The answer is in comment #4. I'll make sure the install guide mentions to enable this before using. thanks. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2018:3195 |