#6648 Make ipa-cacert-manage man page more clear
Closed: fixed 7 years ago Opened 7 years ago by jcholast.

There is a confusion about what ipa-cacert-manage renew does:

ddas: jcholast the external ca and current CA cert seems to be valid
jcholast: no
jcholast: also why do you want to run ipa-cacert-manage at all?
ddas: jcholast since some of the certificate became invalid from 2-Feb-2017. 
ddas: jcholast  expires: 2017-02-02 22:51:09 UTC 
jcholast: ipa-cacert-manage manages the CA certificate and nothing else
jcholast: you use it only if you need to renew the CA certificate
jcholast: i.e. caSigningCert cert-pki-ca
jcholast: it has no effect on other certificates
ddas: jcholast so I only need to use "getcert resubmit -i <id>" approach??
jcholast: yes 
jcholast: this seems to be a common misconception
jcholast: I wonder what can we do to make it clear
ddas: jcholast ok got it. I was of the same impression that it look into other certificates too. 
ddas: jcholast I think updating the man page will help with exactly functionality. 
jcholast: could you be more specific? what would you like to see changed in the man page so that it's obvious to you what the command does?
ddas: jcholast regarding the man page. If a note can be added mentioning that the command is used only to update " caSigningCert cert-pki-ca" and for other certificates use "getcert resumit" command will help clear doubts. 
ddas: jcholast recently we have seens 2-3 cases of sub system certs not renewing in IPA 4.x so there is no clear step how to proceed on that unlike in IPA 3.x where we had KCS.  
jcholast: ok, I'm going to file a ticket, thanks

Update the man page as suggested to make it more clear.


Metadata Update from @jcholast:
- Issue assigned to someone
- Issue set to the milestone: FreeIPA 4.5

7 years ago

Metadata Update from @tkrizek:
- Issue assigned to tkrizek (was: someone)

7 years ago

master:

  • 223a48b man: update ipa-cacert-manage

Metadata Update from @tkrizek:
- Custom field affects_doc reset
- Custom field tester adjusted to wanted
- Issue close_status updated to: fixed
- Issue status updated to: Closed (was: Open)

7 years ago

Metadata Update from @tkrizek:
- Custom field affects_doc reset

7 years ago

Login to comment on this ticket.

Metadata