Customer had mutiple certs (ie. some older expired and renewed certs) in the master certdb. The clone install failed on the RestoreKeyCertsPanel.
This is at least on Dogtag 10.
IMPORTANT!
This change likely needs to be backported - most likely to 10.0 and 10.1. Please add/clone tickets when this ticket is addressed.
Proposed Milestone: 10.2.1 (per CS Meeting of 09/17/2014)
We need steps to reproduce the problem.
Steps to reproduce: 1. Optional: assuming ticket #1226 is fixed, edit /usr/share/pki/ca/conf/caOCSP.profile, change the range and add the rangeUnit properties to create a short-lived certificate:
2.default.params.range=1 2.default.params.rangeUnit=minute
The CA clone installation will fail since it incorrectly imports just the expired certificate but not the valid one.
master:
Cloned to #1231 for 10.1.
Metadata Update from @vakwetu: - Issue assigned to edewata - Issue set to the milestone: 10.2.1
Dogtag PKI is moving from Pagure issues to GitHub issues. This means that existing or new issues will be reported and tracked through Dogtag PKI's GitHub Issue tracker.
This issue has been cloned to GitHub and is available here: https://github.com/dogtagpki/pki/issues/1656
If you want to receive further updates on the issue, please navigate to the GitHub issue and click on Subscribe button.
Subscribe
Thank you for understanding, and we apologize for any inconvenience.
Login to comment on this ticket.