Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 534064

Summary: CA ignores validity period in profile for issuing certificate
Product: [Retired] Dogtag Certificate System Reporter: David Stutzman <david.k.stutzman2.ctr>
Component: Certificate ManagerAssignee: Christina Fu <cfu>
Status: CLOSED EOL QA Contact: Ben Levenson <benl>
Severity: medium Docs Contact:
Priority: low    
Version: 1.2CC: dpal, jgalipea, nkinder
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-03-27 19:42:44 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 530474    
Attachments:
Description Flags
image shows snippet from the agent interface and then the issued certificate's validity
none
profile in question none

Description David Stutzman 2009-11-10 13:04:56 UTC
Created attachment 368380 [details]
image shows snippet from the agent interface and then the issued certificate's validity

Description of problem:
After submitting a certificate request on the ee interface and going to the agent interface to approve the certificate, validity shows up as expected (25 years).  After I approve the certificate request, the certificate is issued and shown on the next screen, but the validity period is just 2 years.

Version-Release number of selected component (if applicable):
Dogtag 1.2.0 built from svn r803, pki-ca is 1.2.0-4

Attached image shows snippet from the agent interface and then the issued certificate's validity.

As the console isn't working these days, I edited the profile by hand and it is attached as well.

Comment 1 David Stutzman 2009-11-10 13:06:37 UTC
Created attachment 368381 [details]
profile in question

Comment 4 Nathan Kinder 2012-12-11 16:44:55 UTC
Upstream ticket:
https://fedorahosted.org/pki/ticket/454

Comment 7 David Stutzman 2015-07-16 17:09:02 UTC
I don't know when it happened but this is working properly now.  I send CMC requests with CRMF requests with the validity set and I am getting the # requested on the issued certificate.  I'm currently running 
pki-ca-9.0.3-38.el6_6.noarch.