Bug 816236 - permission setting of system certs can fail in clone installation if nicknames are changed
permission setting of system certs can fail in clone installation if nickname...
Status: NEW
Product: Dogtag Certificate System
Classification: Community
Component: Installation Wizard (Show other bugs)
9.0
Unspecified Unspecified
unspecified Severity unspecified
: ---
: ---
Assigned To: Ade Lee
Ben Levenson
:
Depends On:
Blocks: 530474
  Show dependency treegraph
 
Reported: 2012-04-25 11:15 EDT by Ade Lee
Modified: 2015-01-04 19:29 EST (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Ade Lee 2012-04-25 11:15:36 EDT
Description of problem:

In RestoreKeyCertPanel.java , we have the following code to set the trusts on certs that are installed in a clone.  This is wrong because the nicknames may be changes and may not start with the indicated phrases.

if (name.startsWith("caSigningCert")) {
     // we need to change the trust attribute to CT
     InternalCertificate icert = (InternalCertificate) xcert;
     icert.setSSLTrust(InternalCertificate.TRUSTED_CA
                       | InternalCertificate.TRUSTED_CLIENT_CA
                       | InternalCertificate.VALID_CA);
} else if (name.startsWith("auditSigningCert")) {
     InternalCertificate icert = (InternalCertificate) xcert;
     icert.setObjectSigningTrust(InternalCertificate.USER
                                | InternalCertificate.VALID_PEER            
                                | InternalCertificate.TRUSTED_PEER);
}

Version-Release number of selected component (if applicable):


How reproducible:


Steps to Reproduce:
1.
2.
3.
  
Actual results:


Expected results:


Additional info:

Note You need to log in before you can comment on or make changes to this bug.