#2254 Add options to trim old CRLs
Closed: Fixed None Opened 5 years ago by vakwetu.

When file based publishing is enabled (as it is in IPA), the publisher will merrily continue to generate time stamped CRL files on a regular basis within a directory without worrying about old CRLs.

As this happens every 4 hours by default - and I believe that we create these even if no changes have occurred - this can eventually fill the disk.

It makes sense to have a purging policy. So, after publishing a new CRL, the publisher will remove any CRL files older than X hours/seconds/days, where X is configurable.

Per discussions with alee: 10.3.1

[vakwetu@vm-130 pki]$ git push origin master
Counting objects: 13, done.
Delta compression using up to 8 threads.
Compressing objects: 100% (11/11), done.
Writing objects: 100% (13/13), 2.62 KiB | 0 bytes/s, done.
Total 13 (delta 7), reused 0 (delta 0)
To ssh://vakwetu@git.fedorahosted.org/git/pki.git

Checked into master:

  • 9ff1cb21bee15cb569ad22b75d82b8312ba47061

Metadata Update from @vakwetu:
- Issue assigned to vakwetu
- Issue set to the milestone: 10.3.2

4 years ago

Dogtag PKI is moving from Pagure issues to GitHub issues. This means that existing or new
issues will be reported and tracked through Dogtag PKI's GitHub Issue tracker.

This issue has been cloned to GitHub and is available here:

If you want to receive further updates on the issue, please navigate to the
GitHub issue and click on Subscribe button.

Thank you for understanding, and we apologize for any inconvenience.

Login to comment on this ticket.