#6221 Certificate revocation in service-del and host-del isn't aware of Sub CAs
Closed: Fixed None Opened 7 years ago by mkubik.

As a part of the procedure of deleting a service or host entry, any certificates issued for them are revoked.

The function that revokes the certificate (located in service plugin module) is not aware of Sub CAs and calls cert-show without cacn option. This causes a fail because the cert-show will assume the ipa CA for a certificate signed by a Sub CA.

This causes an error during certificate revocation that aborts the delete operation.


master:

  • daeaf2a Make host/service cert revocation aware of lightweight CAs

ipa-4-4:

  • d3f3869 Make host/service cert revocation aware of lightweight CAs

Metadata Update from @mkubik:
- Issue assigned to ftweedal
- Issue set to the milestone: FreeIPA 4.4.2

6 years ago

Login to comment on this ticket.

Metadata