Bug 928478 - Install CA anchor into standard location
Summary: Install CA anchor into standard location
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: freeipa
Version: 20
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Rob Crittenden
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
: 928479 974482 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2013-03-27 18:06 UTC by Stef Walter
Modified: 2014-02-28 18:36 UTC (History)
7 users (show)

Fixed In Version: freeipa-3.3.4-3.fc20
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2014-02-28 18:36:52 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Stef Walter 2013-03-27 18:06:18 UTC
As part of this Fedora feature, we're working on having a standard location and API for installing system trust anchors. 

https://fedoraproject.org/wiki/Features/SharedSystemCertificates

In Fedora 19 there's a standard location for Admins to add these system trust anchors. In Fedora 20, we want to add standard tools to do this task.

ipa-client-install currently adds the root certificate for the domain to  /etc/pki/nssdb. By instead using these new facilities, all applications using any of the standard locations (via OpenSSL, GnuTLS, NSS, java, and so on) will be able to use the FreeIPA CA root as a trusted anchor.

Comment 1 Stef Walter 2013-03-27 18:12:42 UTC
*** Bug 928479 has been marked as a duplicate of this bug. ***

Comment 2 Stef Walter 2013-03-27 18:20:09 UTC
We can choose to solve this in Fedora 19 or Fedora 20:

Current Fedora 19:

 * Place the certificate authority in /etc/pki/ca-trust/source/anchors
 * Run 'p11-kit extract-trust'

Wait for Fedora 20:

 * Run future standard tool to add the certificate authority

Comment 3 Martin Kosek 2013-04-04 08:47:23 UTC
Upstream ticket:
https://fedorahosted.org/freeipa/ticket/3504

Comment 4 Martin Kosek 2013-06-14 11:03:21 UTC
*** Bug 974482 has been marked as a duplicate of this bug. ***

Comment 5 Fedora End Of Life 2013-09-16 13:21:28 UTC
This bug appears to have been reported against 'rawhide' during the Fedora 20 development cycle.
Changing version to '20'.

More information and reason for this action is here:
https://fedoraproject.org/wiki/BugZappers/HouseKeeping/Fedora20

Comment 6 Petr Viktorin (pviktori) 2013-11-20 12:17:08 UTC
Fixed upstream:
master: https://fedorahosted.org/freeipa/changeset/4a0e91449e2b65304ae8d660d1a480200b1a13d3

Comment 7 Martin Kosek 2014-01-28 11:44:16 UTC
Related commit which is a requirement for patch above: 

https://fedorahosted.org/freeipa/changeset/60b472479d6427243b5ef51c4dd60cdcd9e52afd

Comment 8 Fedora Update System 2014-01-28 14:45:15 UTC
freeipa-3.3.4-1.fc20 has been submitted as an update for Fedora 20.
https://admin.fedoraproject.org/updates/freeipa-3.3.4-1.fc20

Comment 9 Fedora Update System 2014-01-29 03:01:33 UTC
Package freeipa-3.3.4-1.fc20:
* should fix your issue,
* was pushed to the Fedora 20 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing freeipa-3.3.4-1.fc20'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-2014-1666/freeipa-3.3.4-1.fc20
then log in and leave karma (feedback).

Comment 10 Fedora Update System 2014-02-06 04:03:00 UTC
Package freeipa-3.3.4-2.fc20:
* should fix your issue,
* was pushed to the Fedora 20 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing freeipa-3.3.4-2.fc20'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-2014-1666/freeipa-3.3.4-2.fc20
then log in and leave karma (feedback).

Comment 11 Fedora Update System 2014-02-12 14:46:17 UTC
Package freeipa-3.3.4-3.fc20:
* should fix your issue,
* was pushed to the Fedora 20 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing freeipa-3.3.4-3.fc20'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-2014-1666/freeipa-3.3.4-3.fc20
then log in and leave karma (feedback).

Comment 12 Fedora Update System 2014-02-28 18:36:52 UTC
freeipa-3.3.4-3.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.