With ACME pruning there are a number of knobs to tune the frequency, etc of pruning certificates and requests. Up to pki 11.4.3 if one requests a configuration value by calling pki-server ca-config-show <option> the command always has a return value of 0 so no error checking was required.
With pki 11.5.0 the call to pki-server now returns 1 if the option isn't present.
With all versions it returns a message like ERROR: No such parameter: jobsScheduler.job.pruning.certRetentionUnit
Status: disabled Certificate Retention Time: 360 ERROR: No such parameter: jobsScheduler.job.pruning.certRetentionUnit
The ipa-acme-manage command failed.
It fails on the first missing value.
It should list the full configuration.
freeipa-server-4.11.0-7.fc39.x86_64 dogtag-pki-base-11.5.0-0.1.alpha4.20231221172054UTC.2e5ee9c1.fc39.noarch
Upstream PR https://github.com/freeipa/freeipa/pull/7134
master:
ipa-4-11:
Metadata Update from @frenaud: - Issue close_status updated to: fixed - Issue status updated to: Closed (was: Open)
Metadata Update from @frenaud: - Custom field rhbz adjusted to https://issues.redhat.com/browse/RHEL-21811
Log in to comment on this ticket.