According to screen 131a and 161a in the spec (http://freeipa.org/wiki/images/b/b7/IPA_July_16.pdf) the UI should take an expiration date for the certificate. The UI and possibly the backend need to be modified to support this parameter.
I'd want to see a use-case for this. Right now the CA decides how long the cert is good for.
This is a part of the UI spec is probably based on my explanation and might have some wishful thinking inspired by me... I would think it is nice to be able to define the expiration using a pre configured value as a default one. But if it is not something doable now we can defer it till later. We probably need to correlate it with support of multiple certificate profiles so may be we need to have a way to select a profile out of the list and have a way to define profiles. Needs more design and thinking and we already have a ticket for that. https://fedorahosted.org/freeipa/ticket/57
Metadata Update from @edewata: - Issue assigned to admiyo - Issue set to the milestone: Tickets Deferred
Given that profiles are supported and selectable in the UI I'm going to mark this as closed.
New location for the referenced pdf: https://www.freeipa.org/page/File:IPA_July_16.pdf
Metadata Update from @rcritten: - Issue close_status updated to: fixed - Issue status updated to: Closed (was: Open)
Login to comment on this ticket.