Bug 2226794 - Satellite documentation does not indicate the required fields for custom certificates [NEEDINFO]
Summary: Satellite documentation does not indicate the required fields for custom cert...
Keywords:
Status: ASSIGNED
Alias: None
Product: Red Hat Satellite
Classification: Red Hat
Component: Certificates
Version: 6.14.0
Hardware: x86_64
OS: Linux
urgent
urgent
Target Milestone: 6.14.0
Assignee: Malhar Jivrajani
QA Contact: Satellite QE Team
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-07-26 14:41 UTC by Ganesh Payelkar
Modified: 2023-08-18 00:20 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Target Upstream Version:
Embargoed:
mdolezel: needinfo? (mjivraja)
mdolezel: needinfo? (agadhave)


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker SAT-19186 0 None None None 2023-07-26 14:41:49 UTC

Comment 1 Eric Helms 2023-07-27 13:52:48 UTC
I think we should add to our docs some of the known requirements for custom certificates to help guide customers. These requirements are captured in our katello-certs-check tool:

 * Certificates should be PEM encoded
 * Certificate should not also be CA certificate (No CA:TRUE flag)
 * The private key cannot have a passphrase
 * Certificate should include a Subject Alt Name (SAN) entry that matches the Common Name (CN)
 * Certificate should allow for Key Encipherment (via Key Usage extension)
 * Certificate cannot have a shortname as the Common Name (CN)


Note You need to log in before you can comment on or make changes to this bug.