Log In
ftweedal
Fraser Tweedale •
Joined 7 years ago
Overview
Projects
6
Forks
3
Groups
1
Starred
0
Issues
Pull Requests
Issues for
ftweedal
Open
Closed
All
Issues Created
issues
#5432
Issue New Certificate dialogs do not validate data
2
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.4
low
#6309
cert-request does not raise error when CSR does not match profile pattern
1
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.4.2
normal
#5661
paste: cannot create desired project namespace
4
Opened
6 years ago
by
ftweedal
. Modified
6 years ago
fedora-infrastructure
#5707
[RFE] Warn if CN length is 64-octets
4
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5 backlog
normal
#5919
cert-request rfc822Name check compares whole email address case-sensitively
5
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5.5
low
#7123
External CA renewal fails when IPA CA subject DN does not match "CN=Certificate Authority, {subject-base}"
3
Opened
5 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5.4
normal
#6526
remove "request certificate with subjectaltname" permission
1
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5
normal
#37
Investigate ACME client implementation
2
Opened
8 years ago
by
ftweedal
. Modified
5 years ago
certmonger
0.0 NEEDS_TRIAGE
major
#7527
uninstall: server is not removed from lightweight CA key list
4
Opened
4 years ago
by
ftweedal
. Modified
4 years ago
freeipa
robustness
FreeIPA 4.7.2
normal
#5684
Configure 389ds with "default" cipher suite
7
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.3.1
normal
#5323
Mechanism to update included certprofiles
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5 backlog
normal
#7160
Track HTTP/DS cert if issued by IPA lightweight CA?
1
Opened
5 years ago
by
ftweedal
. Modified
5 years ago
freeipa
#5205
Remove CSR allowed-extensions restriction
3
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2.1
normal
#7118
Fix CA-less installation due to incorrect with statement
2
Opened
5 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.6
#6496
remove references to ds_newinst.pl
1
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5
minor
#1629
Lightweight CAs: add audit events
2
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.0
major
#5092
certprofile: add option or command to copy a profile
1
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5 backlog
low
#4907
[RFE] certificate request queue management
1
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5 backlog
normal
#5177
Add ACI and permission for managing user userCertificate attribute
2
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2.1
normal
#7115
ipa-pki-retrieve-key: failure results in crash report
4
Opened
5 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.6.1
#5099
Add permission for user to bypass caacl enforcement
4
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2.1
important
#2225
OCSPClient program does not support HTTPS
2
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.0.a2
major
#7904
Performance workarounds for cert-find and related commands regress on corner cases
1
Opened
3 years ago
by
ftweedal
. Modified
3 years ago
freeipa
#6256
[tracker] Revoke certificate on lightweight CA deletion
2
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.4.2
normal
#5969
replica install: connection check does not distinguish between incorrect password and genuine network issue
3
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
0.0 NEEDS_TRIAGE
low
#6112
[RFE] cert-request: allow DirectoryName SAN
4
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5 backlog
normal
#4899
[RFE] mechanism to map principal info into certificate requests
7
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5 backlog
low
#6557
do not set (or look up) subject_base in sysupgrade file
1
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
Future Releases
low
#5206
[RFE] cert-request: compare issued certificate to CSR
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5 backlog
low
#49543
certmap fails when Issuer DN has comma in name
4
Opened
5 years ago
by
ftweedal
. Modified
2 years ago
389-ds-base
1.3.7.0
#6257
Implement ca-enable/disable commands.
2
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.4.2
normal
#6636
UnboundLocalError during ipa-client-install
1
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5
normal
#2293
Lightweight CAs: retry with backoff on key retrieval failure
2
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.2
major
#5836
Lightweight CAs: allow profile to specify a default CA
1
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
Future Releases
normal
#6230
installer: external CA step 1 successful but reports ScriptError
1
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.4.2
normal
#6398
Refactor certificate inspection code to use python-cryptography
3
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5
normal
#6086
CA replica install logs to wrong log file
4
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.4.1
low
#5096
cert-request: enforce caacl for subjectAltName principals
2
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2
normal
#5778
Installation with external CA: step 2 fails when custom subject is used
2
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
0.0 NEEDS_TRIAGE
low
#5198
Prevent deletion of default profile
2
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2.1
normal
#5578
install fails when locale is "fr_FR.UTF-8"
4
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2.4
normal
#5166
Add --certificate-out option and deprecate --out
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5 backlog
low
#2321
Lightweight CAs: allow certificate search by issuer
2
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.1
major
#6976
External CA: check that IPA CA certificate contains Subject Key Identifier
2
Opened
5 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.6
#2343
Underscore in instance name causes LDAP syntax error
4
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.2
major
#6529
ipaldap: handle binary encoding option transparently
6
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
0.0 NEEDS_TRIAGE
low
#6419
cert-show default output does not show validity
2
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.4.3
normal
#7070
add tests for `{user,host,service}-show --out FILE`
1
Opened
5 years ago
by
ftweedal
. Modified
3 years ago
freeipa
tests
FreeIPA 4.6.5
#6530
service and host plugins do not handle userCertificate;binary attribute
4
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5 backlog
normal
#2328
Deleted LWCA key material not removed from clones.
3
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.2
minor
#6426
Extend CA ACLs to encompass issuance of certs for "external" subjects
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
Future Releases
normal
#6472
cert-request no longer accepts CSR with extraneous data surrounding PEM data
1
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5
normal
#6460
NSSNickname enclosed in single quotes causes ipa-server-certinstall failure
1
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5
normal
#6399
Object-Signing cert is unused; don't create it
1
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5
low
#6178
Add options to retrieve lightweight CA certificate/chain
6
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5
normal
#6422
Enforce CA ACLs in Dogtag
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5 backlog
normal
#4758
Profile management permissions CLI
1
Opened
8 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2
normal
#6260
cert-request: use better error message when CA is disabled
1
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.4.2
normal
#6550
Refactor PKCS #7 parsing to use pyasn1_modules
1
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5
low
#5431
[RFE] Option to acquire publicly trusted HTTP/LDAP certs from Let's Encrypt
6
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
Future Releases
normal
#5254
obj-mod commands that cannot rename entries should not offer --rename
1
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5 backlog
low
#6305
host/service-mod with --certificate= (remove all certs) does not revoke certs
1
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5
normal
#6427
cert-request: only check userCertificate write permission if write would be attempted
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
Future Releases
low
#6573
CA-less replica installation fails due to attempted cert issuance
1
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5
critical
#5523
[RFE] Update default profiles to always add SAN dnsName
3
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.4
important
#5943
dogtag-ipa-ca-renew-agent-submit cannot access api.Object.config
2
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.4
normal
#6556
do not update ipaCertificateSubjectBase and certmap.conf in CA-less mode
1
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
Future Releases
normal
#56
ipa submission should not retry without 'profile' or 'cacn' argument
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
certmonger
0.0 NEEDS_TRIAGE
major
#5968
renew_ca_cert helper cannot access config plugin
2
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.4
normal
#51
Support for specifying IPA lightweight CA
2
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
certmonger
0.0 NEEDS_TRIAGE
critical
#5094
Allow certprofile-show to pretty print profile configuration
1
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5 backlog
normal
#5733
CA ACL rejects user when full principal name used
2
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2.5
normal
#1628
Lightweight CAs: ensure disable CA cannot issue certificates
5
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.0.a2
major
#5089
certprofile: improve profile format documentation
5
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2.1
low
#6415
replica-install creates spurious entries in cn=certificates
4
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5
normal
#5219
[RFE] Add `openssl req' config templates for profiles
2
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.4 Backlog
low
#6146
caacl: error when instantiating rules with service principals
4
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.4.1
normal
#6987
ca-add: invalid X.509 DN fails ungracefully
2
Opened
5 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.6
#7503
multiple occurrences of profileId in certprofile causes incorrect behaviour
3
Opened
4 years ago
by
ftweedal
. Modified
4 years ago
freeipa
FreeIPA 4.6.4
#6432
cert-request: check SAN dnsNames against principal aliases
2
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
0.0 NEEDS_TRIAGE
normal
#6350
IDM admin password gets written to /root/.dogtag/pki-tomcat/ca/pkcs12_password.conf
2
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5
normal
#5091
certprofile-show: add --output option
2
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2
normal
#4761
Implement profile CRUD CLI commands
1
Opened
8 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2
normal
#4752
[RFE] Provide an IEC 62351-8 / DNP3 ID certificate profile
5
Opened
8 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2.1
important
#1361
REST: NPE when modifying profile without 'action' param
4
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.2.5
minor
#6488
ipa-replica-install in CA-less environment does not configure DS TLS
3
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
0.0 NEEDS_TRIAGE
normal
#3085
CRLIP does not refresh CRL info from LDAP when re-initialised.
3
Opened
4 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
#5093
certprofile-mod: add --file option to update profile data
2
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2
normal
#5881
URI details missing and OCSP-URI details are incorrectly displayed when certificate generated using IPA on RHEL 7.2up2
3
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2.5
critical
#6586
Minor string fixes in dsinstance.py
1
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5
low
#2332
Lightweight CAs: internal server error when processing request after CA has been deleted
3
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.2
minor
#2443
Prevent deletion of host CA's keys if LWCA entry deleted
4
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.6
major
#4760
Profile CRUD web UI
1
Opened
8 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2
normal
#2829
CA cert without Subject Key Identifier causes issuance failure
4
Opened
5 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.5.0
blocker
#1323
Investigate ues of jscep for our SCEP support
1
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
major
#4759
Profile management permissions UI
1
Opened
8 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2
normal
#5090
[RFE] certprofile: do not require profileId in profile data
2
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2.1
normal
#7225
CLI: view command / plugin help in pager
2
Opened
5 years ago
by
ftweedal
. Modified
5 years ago
freeipa
ux
rfe
FreeIPA 4.7
#5190
Users cannot self-issue certificate with SAN
3
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2.1
normal
#5735
cert-request cannot handle DER-encoded CSR
1
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
0.0 NEEDS_TRIAGE
low
#2601
Return revocation reason in GET /ca/rest/certs/{id} response.
2
Opened
5 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.4.0
critical
#6232
Insufficient privileges check in certificate revocation (CVE-2016-5404)
1
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2.5
important
#1367
Lightweight CAs: Implement Python API
4
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.0.a2
major
#5191
cert-request rejects request with correct krb5PrincipalName SAN
3
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2.1
normal
#1625
Lightweight CAs: replication support
6
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.1
major
#7178
cert-find command has poor performance
1
Opened
5 years ago
by
ftweedal
. Modified
5 years ago
freeipa
#6528
Remove "alternative principal" procedure for SAN validity
2
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
Future Releases
normal
#1632
Lightweight CAs: ensure CA certs bear correct Authority Key Identifier
5
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.0.a2
major
#1320
Allow lightweight CAs to be individually configured for random/sequential serial numbers
3
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
minor
#1630
Lightweight CAs: provide upgrade script
2
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.0
major
#2387
Add config for default OCSP URI if none given
3
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.4
blocker
#1638
Lightweight CAs: revoke certificate on CA deletion
5
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.6
major
#8410
ACME service: deployment-wide configuration
1
Opened
2 years ago
by
ftweedal
. Modified
2 years ago
freeipa
#3055
number range depletion when multiple clones created from same master
4
Opened
4 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
#1322
[RFE] Add ability to restrict lightweight CAs to subset of profiles
2
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
major
#78
Add support for MS Certificate Template V2 extension
1
Opened
5 years ago
by
ftweedal
. Modified
5 years ago
certmonger
#1189
CRL does not include Authority Key Identifier extension
7
Opened
8 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.2.2
minor
#2322
Lightweight CAs: include issuer DN in CertDataInfo
2
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.1
major
#2682
Set "Status" field to "Closed" when setting "Closed as" field
3
Opened
5 years ago
by
ftweedal
. Modified
5 years ago
pagure
#2327
Lightweight CA: renewal support
4
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.2
major
#1626
Lightweight CAs: ensure correct CRL behaviour for host CA
5
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.0
major
#2359
LWCA initialisation fails in cert update
3
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.3
major
#1702
getStatus reports ready before LDAPProfileSubsystem has loaded all profiles
10
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.2.x
major
#57
Implement authentication of external Persona identities
4
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
ipsilon
Backlog
Minor
#1624
Lightweight CAs: generate sub-CAs via profile subsystem
5
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.0.a2
major
#1324
Add lightweight CA deletion capability
3
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.1
major
#1591
Lightweight CAs: database upgrade
3
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
major
#1236
Add upgrade script to enable CRL AKI extension
4
Opened
8 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
minor
#2466
two-step externally-signed CA installation fails due to missing AuthorityID
4
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.7
major
#7007
Use CommonNameToSANDefault in default profile (new installs only)
3
Opened
5 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5.3
important
#1616
Lightweight CAs: add ability to retrieve certificate chain as sequence of PEMs
3
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
minor
#2388
CA creation responds 500 if certificate issuance fails
3
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.4
major
#7014
Add a README to profile templates directory to discourage use
2
Opened
5 years ago
by
ftweedal
. Modified
5 years ago
freeipa
#1658
CA OCSP servlet does not accept urlencoded OCSP request
5
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.0
major
#2734
Add config knob to disable lightweight CAs
2
Opened
5 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.5.0
major
#2301
Clone installation fails when external CA serial matches Dogtag CA serial
3
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.1
major
#1604
Sub-CAs: implement enable/disable of sub-CAs
3
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
major
#7459
[RFE] replica-install: warn when only one CA exists in topology
2
Opened
4 years ago
by
ftweedal
. Modified
4 years ago
freeipa
rfe
#7476
[RFE] cacert-manage-renew: sanity check Subject DN attribute encodings
Opened
4 years ago
by
ftweedal
. Modified
4 years ago
freeipa
rfe
robustness
normal
#2939
ipa-server-install with different IP fails on /usr/sbin/pkispawn -s CA
6
Opened
4 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.6.0
blocker
#85
start-tracking: principal name is not added to tracking request
3
Opened
5 years ago
by
ftweedal
. Modified
5 years ago
certmonger
#5491
Brittle LDAP connection logic in installer / upgrade
2
Opened
7 years ago
by
ftweedal
. Modified
4 years ago
freeipa
FreeIPA 4.5 backlog
normal
#7383
user-add: user creation proceeds when password is wrong
6
Opened
4 years ago
by
ftweedal
. Modified
4 years ago
freeipa
regression
FreeIPA 4.6.4
critical
#5753
RFE: enhance CA ACLs to use service groups
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
Future Releases
normal
#7282
renew_ra_cert Certmonger hook fails to update people entry
2
Opened
5 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.6
#7097
IPA upgrade from v4.1 fails
3
Opened
5 years ago
by
ftweedal
. Modified
5 years ago
freeipa
#6732
[RFE] customisable MOTD on login / banner in Web UI
3
Opened
5 years ago
by
ftweedal
. Modified
4 years ago
freeipa
FreeIPA 4.7.1
#7287
kra install fails after ipa cert renewed
3
Opened
5 years ago
by
ftweedal
. Modified
5 years ago
freeipa
regression
FreeIPA 4.5.4
critical
#6471
DL0 server-install --setup-ca fails when adding CA entry (contacts wrong master)
5
Opened
6 years ago
by
ftweedal
. Modified
4 years ago
freeipa
FreeIPA 4.5.5
important
#2828
CA cert renewal can change Subject DN attribute encoding
3
Opened
5 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.5.0
#7226
Remove remaining references to Firefox configuration extension
3
Opened
5 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.6.2
#7299
RPM post-install scripts fail because they are run with python2
2
Opened
5 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.6.2
#7425
ipa-server-install with different IP fails on /usr/sbin/pkispawn -s CA
4
Opened
4 years ago
by
ftweedal
. Modified
4 years ago
freeipa
FreeIPA 4.6.4
#7246
Report CA Subject DN and subject base before installing.
1
Opened
5 years ago
by
ftweedal
. Modified
5 years ago
freeipa
easyfix
ux
rfe
FreeIPA 4.7
#7230
promoting CA-less to CA-ful: CA certificate is not installed in HTTP NSSDB
2
Opened
5 years ago
by
ftweedal
. Modified
4 years ago
freeipa
FreeIPA 4.5.5
important
#5734
cert-request: PKCS #10 only is supported but `--request-type' option suggests otherwise
4
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5.1
low
#7309
Integration tests: CA-less -> CA-ful promotion; post-promotion checks
1
Opened
5 years ago
by
ftweedal
. Modified
4 years ago
freeipa
tests
FreeIPA 4.7
important
#7390
cert-request: issuance of malformed certificate causes IPA Internal Error
2
Opened
4 years ago
by
ftweedal
. Modified
4 years ago
freeipa
FreeIPA 4.6.4
#6733
[RFE] support different ticket lifetimes depending on auth method
3
Opened
5 years ago
by
ftweedal
. Modified
2 years ago
freeipa
Future Releases
#7310
Integration tests don't collect logs from other replicas
2
Opened
5 years ago
by
ftweedal
. Modified
4 years ago
freeipa
tests
FreeIPA 4.7
normal
#7453
Mishandled ACL configuration in AAclAuthz.java reverses rules that allow and deny access
2
Opened
4 years ago
by
ftweedal
. Modified
4 years ago
freeipa
#7067
`cert-find` with no args in ca-less install raises internal error
1
Opened
5 years ago
by
ftweedal
. Modified
4 years ago
freeipa
FreeIPA 4.7
normal
#7084
ipa-cacert-manage renew: additional prompts if CA cert expiry is far off
1
Opened
5 years ago
by
ftweedal
. Modified
4 years ago
freeipa
FreeIPA 4.7.1
#7523
external CA installation: step two reports self-signed configuration
2
Opened
4 years ago
by
ftweedal
. Modified
4 years ago
freeipa
bug
easyfix
FreeIPA 4.7
#1964
Add upgrade script to remove NISAuth plugin from CS.cfg
5
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.5.7
minor
#7496
csrgen fails if subject base contains lower-case attribute names
3
Opened
4 years ago
by
ftweedal
. Modified
4 years ago
freeipa
#7564
[RFE] support internationalised email addresses (RFC 8398)
Opened
4 years ago
by
ftweedal
. Modified
4 years ago
freeipa
rfe
FreeIPA 4.7 backlog
normal
#5
unwrapped private key has wrong CKA_ID
7
Opened
4 years ago
by
ftweedal
. Modified
4 years ago
jss
#6790
[RFE] Allow creating IPA CA with 3072-bit key.
10
Opened
5 years ago
by
ftweedal
. Modified
3 years ago
freeipa
rfe
FreeIPA 4.7.1
#7352
external CA installation: check that public key matches private key
3
Opened
5 years ago
by
ftweedal
. Modified
4 years ago
freeipa
ux
FreeIPA 4.6.5
normal
#7096
API context: create enum.Enum for all possible contexts
4
Opened
5 years ago
by
ftweedal
. Modified
4 years ago
freeipa
FreeIPA 4.6.5
#8368
cannot issue certs with multiple IP addresses corresponding to different hosts
4
Opened
2 years ago
by
ftweedal
. Modified
2 years ago
freeipa
#13
PK11Store.importEncryptedPrivateKeyInfo does not import the public key with SQL NSSDB
1
Opened
4 years ago
by
ftweedal
. Modified
4 years ago
jss
4.5.0
#7085
Update ipa-cacert-manage(1) man page with admonition about EE certs
1
Opened
5 years ago
by
ftweedal
. Modified
4 years ago
freeipa
FreeIPA 4.7.1
#7580
Implement standardised certificate revocation behaviour
Opened
4 years ago
by
ftweedal
. Modified
4 years ago
freeipa
FreeIPA 4.8
#7750
ipaldap: invalid modlist when attribute encoding can vary
9
Opened
4 years ago
by
ftweedal
. Modified
3 years ago
freeipa
#7288
set_directive can overwrite wrong directives
6
Opened
5 years ago
by
ftweedal
. Modified
4 years ago
freeipa
FreeIPA 4.5.5
#5218
[RFE] Allow admins to specify default profile for users and hosts/services
1
Opened
7 years ago
by
ftweedal
. Modified
3 years ago
freeipa
FreeIPA 4.5 backlog
normal
#5024
Prevent creation of sub-CA if pathLenConstraint violated
2
Opened
7 years ago
by
ftweedal
. Modified
4 years ago
freeipa
FreeIPA 4.5 backlog
low
#5447
[RFE] option to prune old CRLs kept in /var/lib/ipa/pki-ca/publish
1
Opened
7 years ago
by
ftweedal
. Modified
4 years ago
freeipa
Future Releases
low
#7451
Allow issuing certificates with IP addresses in subjectAltName
7
Opened
4 years ago
by
ftweedal
. Modified
3 years ago
freeipa
FreeIPA 4.6.5
#7762
External CA renewal accepts IPA CA cert with empty Subject Key Identifier
5
Opened
4 years ago
by
ftweedal
. Modified
3 years ago
freeipa
#9048
ca-show does not show enabled/disabled status
Opened
a year ago
by
ftweedal
. Modified
a year ago
freeipa
#8103
CA-less to CA-ful fails if /etc/ipa/ca.crt does not have DS cert issuer first
2
Opened
3 years ago
by
ftweedal
. Modified
3 years ago
freeipa
#7548
Need integration test for --external-ca-type=ms-cs
5
Opened
4 years ago
by
ftweedal
. Modified
3 years ago
freeipa
tests
#7964
GSSAPI failure causing LWCA key replication failure on f30
4
Opened
3 years ago
by
ftweedal
. Modified
3 years ago
freeipa
#117
update 'getcert list' output to show template, v2-template and issuer fields
7
Opened
3 years ago
by
ftweedal
. Modified
3 years ago
certmonger
0.79
major
#6423
Validate cert requests in Dogtag
1
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
freeipa
FreeIPA 4.5 backlog
normal
#7963
x509.Name -> ipapython.dn.DN does not handle multi-valued RDNs
7
Opened
3 years ago
by
ftweedal
. Modified
3 years ago
freeipa
FreeIPA 4.6.6
#7761
External CA renewal accepts issuer key < 2048-bit
8
Opened
4 years ago
by
ftweedal
. Modified
3 years ago
freeipa
#7877
External CA installation: sanity check pathLenConstraints
3
Opened
3 years ago
by
ftweedal
. Modified
3 years ago
freeipa
FreeIPA 4.7.3
normal
#8084
KRA authentication fails when IPA CA has custom Subject DN
8
Opened
3 years ago
by
ftweedal
. Modified
3 years ago
freeipa
bug
Falcon
#8059
Revocation self-service
1
Opened
3 years ago
by
ftweedal
. Modified
3 years ago
freeipa
rfe
Falcon
#8060
CA revocation ACLs
Opened
3 years ago
by
ftweedal
. Modified
3 years ago
freeipa
rfe
Falcon
#8020
support AES in LWCA key replication
3
Opened
3 years ago
by
ftweedal
. Modified
3 years ago
freeipa
#7991
Use profile-based renewal for system certificates
3
Opened
3 years ago
by
ftweedal
. Modified
3 years ago
freeipa
robustness
#7549
[RFE] ipa cert-find cannot exclude revoked certificates
3
Opened
4 years ago
by
ftweedal
. Modified
3 years ago
freeipa
FreeIPA 4.7 backlog
normal
#8142
check Not Before / Not After in externally signed CA sanity check
12
Opened
3 years ago
by
ftweedal
. Modified
3 years ago
freeipa
FreeIPA 4.8.4
#7232
Unable to re-key external CA
5
Opened
5 years ago
by
ftweedal
. Modified
3 years ago
freeipa
FreeIPA 4.6.5
important
#166
Add option to restrict what principal(s) can be used
1
Opened
5 years ago
by
ftweedal
. Modified
2 years ago
gssproxy
#8087
Implicit CA ACL for IPA services
Opened
3 years ago
by
ftweedal
. Modified
2 years ago
freeipa
robustness
Falcon
#3446
password cache: use a better hash algorithm
2
Opened
5 years ago
by
ftweedal
. Modified
2 years ago
SSSD
/
sssd
Future milestone
Possible thesis
SSSD Future releases (no date set yet)
#8186
Add ipa-ca.$DOMAIN alias to IPA server HTTP certificates
6
Opened
2 years ago
by
ftweedal
. Modified
2 years ago
freeipa
#8231
healthcheck: add certificate serial number uniqueness check
1
Opened
2 years ago
by
ftweedal
. Modified
2 years ago
freeipa
#143
manual resubmit is not retried upon failure
9
Opened
2 years ago
by
ftweedal
. Modified
2 years ago
certmonger
#3169
upgrade: add SANToCNDefault to registry
2
Opened
2 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
#7292
vault: occasional failures to retrieve archived data
7
Opened
5 years ago
by
ftweedal
. Modified
2 years ago
freeipa
tests
test-failure
important
#8399
certmonger attempts to add LWCA tracking requests on non-CA server.
3
Opened
2 years ago
by
ftweedal
. Modified
2 years ago
freeipa
#49278
GetEffectiveRights gives false-negative with ACIs containing targetfilter
33
Opened
5 years ago
by
ftweedal
. Modified
2 years ago
389-ds-base
1.3.7.0
#2433
Lightweight CA GET <id>/chain returns bogus PEM data
3
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.5
major
#1213
Add support for multiple sub-CAs underneath primary CA
2
Opened
8 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
major
#1214
Support multiple unrelated CAs in a Dogtag instance
2
Opened
8 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
major
#1212
Provide better feedback when profile add/modify fails due to invalid values
2
Opened
8 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
minor
#1321
Enforce dashes in command line module selection
5
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
minor
#1141
Remove SimpleProperties (use Properties instead)
2
Opened
8 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
trivial
#1245
[WIKI]: Importing client certificate in Chrome fails
14
Opened
8 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
1.0 TASKS
major
#1383
Prevent creation of sub-CA if pathLenConstraint violated
1
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
minor
#1215
Adding profile with bad BasicConstraintsExtConstraint params reports error but adds profile
3
Opened
8 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
minor
#1221
UTF8String-encoded challengePassword attribute causes decode error
3
Opened
8 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.2.1
major
#2585
UnboundLocalError during ipa-client-install
2
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.4.0
#1335
Remove enable and enableBy properties when adding/modifying profiles
1
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
minor
#1333
extract profile validation library from ProfileAdminServlet
2
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
major
#1304
[RFE] add support for Puppet certificate extensions
1
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
minor
#2859
CS.cfg missing `ca.sslserver.certreq` causes KRA spawn failure
5
Opened
5 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.6.0
critical
#1336
Profile raw property format does not retain ordering
1
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
major
#1338
Support different profiles for lightweight CA creation
2
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
major
#1627
Lightweight CAs: add ability to configure CRLs for lightweight CAs
3
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
FUTURE
major
#1337
Support sub-CA OCSP signing delegation
1
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
major
#1360
Support NSSDB in Python API
1
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
major
#1696
[RFE] add option for FileBasedPublisher to prune old objects
2
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
minor
#1347
Ensure profile class ID can be changed
1
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
minor
#1366
Update Python profiles API to support raw format
1
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
major
#1618
Lightweight CAs: include Issuer DN and Serial in AuthorityData
5
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.1
minor
#1710
Add profile component that copies CN to SAN
7
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.4.0
major
#1462
profile update in raw format accepts bad config
4
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.2.6
major
#1589
Lightweight CAs: keygen parameters for CA creation
5
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
critical
#1592
Sub-CAs: functional tests
1
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
major
#1590
Lightweight CAs: audit events for sub-CAs
4
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.0.a1
major
#1617
Lightweight CAs: support using DN to identify CA
4
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
major
#1667
Database upgrade script to add issuerName attribute to all cert entries
6
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.1
major
#2234
Add upgrade script to change XML comments to <?pkidaemon > processing instructions in server.xml
2
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
major
#1612
Decouple core classes from Servlet classes.
2
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
major
#2233
replace caServerCert profile with one that issues RFC 2818-compliant certs
2
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
major
#1639
Lightweight CAs: add VLV indices and pagination support
3
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
minor
#2317
Bad profile subject name default can cause NPE when processing request
3
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.1
major
#1640
Lightweight CAs: investigate TokenException caused by private deletion
5
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.2
major
#2796
lightweight CA replication fails with a NullPointerException:
4
Opened
5 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.4.10
#2230
Lightweight CAs: use correct OCSP signer
2
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.0.a2
major
#1700
Profile creation (LDAPProfileSubsystem) can fail due to race condition
11
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.2.x
major
#2324
Add issuer DN search option to cert-find CLI
1
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
major
#2238
Lightweight CAs: show target CA in ca-request-show command
2
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
major
#2351
Support JSON in ExternalProcessKeyRetriever
3
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
minor
#2237
CRLDistributionPointsExtension may not be added to OIDMap
2
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.0.a2
major
#2291
Support Lightweight CA key replication with non-RSA host authority
1
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
major
#2444
Authority entry without entryUSN is skipped even if USN plugin enabled
4
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.6
major
#2292
Lightweight CAs: HSM support
2
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
UNTRIAGED
major
#2447
CertRequestInfo has incorrect URLs
5
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.6
major
#2475
Multiple host authority entries created
3
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.7
major
#2525
[RFE] FreeIPA to Dogtag permission mapping plugin
5
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.4.1
critical
#2420
CA subsystem OSCP responder fails when LWCAs are not used
4
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.5
major
#2588
profile modification cannot remove existing config parameters
8
Opened
5 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.4.3
critical
#2795
Allow override of pkispawn server startup timeout
3
Opened
5 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.5.0
major
#2711
LWCA creation fails
2
Opened
5 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.4.6
blocker
#2666
Use AES encryption for ca-authority-key-export command
4
Opened
5 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
FUTURE
major
#2909
ProfileService: config values with backslashes have backslashes removed
4
Opened
5 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.5.5
#2827
pki-server subsystem-cert-validate: failure with large serial numbers
3
Opened
5 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.5.0
major
#3060
UpdateNumberRange: create full range assignment for new clones
2
Opened
4 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
0.0 NEEDS_TRIAGE
#2665
CAInfoService: retrieve KRA-related values from the KRA
2
Opened
5 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.4.4
critical
#2809
PKCS #12 files incompatible with NSS >= 3.31
5
Opened
5 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.4.10
#2789
FixDeploymentDescriptor upgrade scriptlet can fail
4
Opened
5 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.4.10
major
#3102
NPE when request LWCA cert before key replication completes
2
Opened
3 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
#2825
Regression in external CA installation when custom CSR extension specified
3
Opened
5 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.5.0
critical
#2736
SubjectNameDefault: improve error handling when substitutions fail
2
Opened
5 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.5
major
#2831
Use token for security domain authentication
6
Opened
5 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.6
#2826
ClientCertImportCLI.importPKCS7 cannot find cert
5
Opened
5 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.5.0
blocker
#2946
libtps does not directly depend on libz (build failure with nss-3.35)
5
Opened
4 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.5.7
#3020
py3: pkispawn with generic CSR extension fails
3
Opened
4 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.6.3
#2957
Console: Adding ACL from pki-console gives StringIndexOutOfBoundsException
4
Opened
4 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.5.7
critical
#3029
profile CLI: inappropriate use of backslash escape breaks profile configuration
3
Opened
4 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.6.4
#2973
regression in wait_for_startup caused by ReadTimeout exception
6
Opened
4 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.6.0
blocker
#3078
startup initialization should not depend on LDAP operational attributes
5
Opened
4 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
#2929
Regression in lightweight CA key replication
3
Opened
4 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.5.6
blocker
#2922
Name Constraints: Using a Netmask produces an odd entry in a certifcate
9
Opened
4 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.5.10
blocker
#2989
Certificate Transparency logging support
1
Opened
4 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
0.0 NEEDS_TRIAGE
#3100
Certificate Policies extension: several issues
1
Opened
3 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
#3106
Starting PKI with zero-length range assignment causes error.
1
Opened
3 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
#3069
Switch to Jackson 2
4
Opened
4 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
#3103
cert-fix fails when HOSTNAME env var not set
1
Opened
3 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
#3081
Setting FUTURE crypto policy causes pkispawn failure
1
Opened
4 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
#3079
zero-length OCTET STRING DerValue cannot be converted to byte[]
2
Opened
4 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
#3109
Cert search: support multiple statuses
1
Opened
3 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
#7219
add command(s) for pruning expired certs from `userCertificate` attribute
3
Opened
5 years ago
by
ftweedal
. Modified
2 years ago
freeipa
#5706
[RFE] Support SAN-only certificates (empty subject dn)
2
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
freeipa
FreeIPA 4.5 backlog
normal
#6424
Extend CA ACLs to encompass operator authorisation
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
freeipa
rfe
Future Releases
normal
#6425
Extend CA ACLs to allow external principals as operator or subject
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
freeipa
rfe
Future Releases
normal
#8577
acme: test with caddy, dehydrated, acme-tiny
Opened
2 years ago
by
ftweedal
. Modified
2 years ago
freeipa
#132
ipa-submit should use system trust
5
Opened
3 years ago
by
ftweedal
. Modified
2 years ago
certmonger
#7885
RFE: wrapper for Dogtag cert-fix command
13
Opened
3 years ago
by
ftweedal
. Modified
a year ago
freeipa
#9126
allow overriding systemd-tmpfiles program
2
Opened
10 months ago
by
ftweedal
. Modified
10 months ago
freeipa
#4751
Implement ACME certificate enrolment
12
Opened
8 years ago
by
ftweedal
. Modified
2 years ago
freeipa
normal
#7752
ipa client throws http.client.ResponseNotReady error
6
Opened
4 years ago
by
ftweedal
. Modified
2 years ago
freeipa
#2074
Add ability to filter "My Issues" by project
2
Opened
5 years ago
by
ftweedal
. Modified
4 days ago
pagure
Issue tracker
RFE
IDM
Assigned Issues
issues
#6011
upgrade failed for 4.4 alpha from 4.2.3.?
1
Opened
6 years ago
by
pvoborni
. Modified
5 years ago
freeipa
FreeIPA 4.4
critical
#7087
ipa-replica-install --setup-kra broken on DL0
16
Opened
5 years ago
by
stlaz
. Modified
4 years ago
freeipa
regression
FreeIPA 4.5.5
important
#6019
Lightweight sub-CA certs are not tracked by certmonger after `ipa-replica-install`
3
Opened
6 years ago
by
jcholast
. Modified
5 years ago
freeipa
FreeIPA 4.4.1
critical
#5323
Mechanism to update included certprofiles
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5 backlog
normal
#3461
[RFE] Extend freeipa's sudo to support selinux transition roles
3
Opened
9 years ago
by
simo
. Modified
5 years ago
freeipa
FreeIPA 4.5
normal
#5205
Remove CSR allowed-extensions restriction
3
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2.1
normal
#7118
Fix CA-less installation due to incorrect with statement
2
Opened
5 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.6
#8369
cert_find returns "CA not configured" in CA-less install
10
Opened
2 years ago
by
gemlau
. Modified
2 years ago
freeipa
#6022
cert-show command does not display Subject Alternative Names
7
Opened
6 years ago
by
pspacek
. Modified
5 years ago
freeipa
FreeIPA 4.4.3
important
#6496
remove references to ds_newinst.pl
1
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5
minor
#5376
[tracker] Replica prepare: Certificate issuance failed
10
Opened
7 years ago
by
mbasti
. Modified
5 years ago
freeipa
FreeIPA 4.4
normal
#7115
ipa-pki-retrieve-key: failure results in crash report
4
Opened
5 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.6.1
#5099
Add permission for user to bypass caacl enforcement
4
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2.1
important
#6020
Server uninstall does not stop tracking lightweight sub-CA with certmonger
2
Opened
6 years ago
by
jcholast
. Modified
5 years ago
freeipa
FreeIPA 4.4.1
normal
#6256
[tracker] Revoke certificate on lightweight CA deletion
2
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.4.2
normal
#4938
[RFE] Allow issuing certificates for user accounts
5
Opened
7 years ago
by
mkosek
. Modified
5 years ago
freeipa
FreeIPA 4.2
important
#7536
[F28] SubCA failing, keys are orphan
12
Opened
4 years ago
by
cheimes
. Modified
4 years ago
freeipa
FreeIPA 4.7
important
#7316
The Issuer DN field in IPA is not updating properly
10
Opened
5 years ago
by
frenaud
. Modified
4 years ago
freeipa
bug
FreeIPA 4.5.4
critical
#6112
[RFE] cert-request: allow DirectoryName SAN
4
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5 backlog
normal
#5269
ipa-server-install in a container fails with RemoteRetrieveError: Non-2xx response from CA REST API: 500 Internal Server Error.
8
Opened
7 years ago
by
adelton
. Modified
5 years ago
freeipa
FreeIPA 4.2.4
important
#5991
Principal does not get created when I add a certificate with "Add principal" checkbox checked
5
Opened
6 years ago
by
ofayans
. Modified
5 years ago
freeipa
FreeIPA 4.4
normal
#6001
[tracker] Sub-CA: ca-add reports validation error as internal error
3
Opened
6 years ago
by
mkosek
. Modified
5 years ago
freeipa
FreeIPA 4.4.1
normal
#5171
user-show: add option to export certificate(s) into file
2
Opened
7 years ago
by
mbasti
. Modified
5 years ago
freeipa
FreeIPA 4.2.1
normal
#6257
Implement ca-enable/disable commands.
2
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.4.2
normal
#6636
UnboundLocalError during ipa-client-install
1
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5
normal
#2293
Lightweight CAs: retry with backoff on key retrieval failure
2
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.2
major
#4559
[RFE] Support lightweight sub-CAs
13
Opened
8 years ago
by
dpal
. Modified
5 years ago
freeipa
FreeIPA 4.4
critical
#6398
Refactor certificate inspection code to use python-cryptography
3
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5
normal
#5185
IPA default CAACL does not allow cert-request for services after upgrade
2
Opened
7 years ago
by
jcholast
. Modified
5 years ago
freeipa
FreeIPA 4.2.1
normal
#5096
cert-request: enforce caacl for subjectAltName principals
2
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2
normal
#5198
Prevent deletion of default profile
2
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2.1
normal
#5578
install fails when locale is "fr_FR.UTF-8"
4
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2.4
normal
#2321
Lightweight CAs: allow certificate search by issuer
2
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.1
major
#6976
External CA: check that IPA CA certificate contains Subject Key Identifier
2
Opened
5 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.6
#2343
Underscore in instance name causes LDAP syntax error
4
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.2
major
#5956
ocsp responer url should aways contain ipa-ca hostname instead of master hostnames.
13
Opened
6 years ago
by
tscherf
. Modified
5 years ago
freeipa
FreeIPA 4.4.1
important
#6529
ipaldap: handle binary encoding option transparently
6
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
0.0 NEEDS_TRIAGE
low
#4002
IPA should own its certificate profile
16
Opened
9 years ago
by
mkosek
. Modified
5 years ago
freeipa
FreeIPA 4.2
normal
#6419
cert-show default output does not show validity
2
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.4.3
normal
#2328
Deleted LWCA key material not removed from clones.
3
Opened
6 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.2
minor
#6426
Extend CA ACLs to encompass issuance of certs for "external" subjects
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
Future Releases
normal
#6472
cert-request no longer accepts CSR with extraneous data surrounding PEM data
1
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5
normal
#6455
Add example of RDN order for ipa-server-install --subject
3
Opened
6 years ago
by
cheimes
. Modified
5 years ago
freeipa
FreeIPA 4.5
minor
#6399
Object-Signing cert is unused; don't create it
1
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5
low
#6178
Add options to retrieve lightweight CA certificate/chain
6
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5
normal
#6422
Enforce CA ACLs in Dogtag
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5 backlog
normal
#5459
Default CA ACL rule is not created during ipa-replica-install
4
Opened
7 years ago
by
mkosek
. Modified
5 years ago
freeipa
FreeIPA 4.2.4
important
#6260
cert-request: use better error message when CA is disabled
1
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.4.2
normal
#2614
[RFE] enhance --subject option for ipa-server-install
10
Opened
10 years ago
by
sbingram
. Modified
5 years ago
freeipa
FreeIPA 4.5 backlog
important
#6226
ipa-replica-install in CA-less environment does not configure DS TLS - ipa-ca-install then fails on replica
11
Opened
6 years ago
by
pvoborni
. Modified
5 years ago
freeipa
FreeIPA 4.4.3
important
#5958
Upgrade is broken on servers without CA
4
Opened
6 years ago
by
pspacek
. Modified
5 years ago
freeipa
FreeIPA 4.3.2
critical
#6305
host/service-mod with --certificate= (remove all certs) does not revoke certs
1
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5
normal
#7516
[F28] ipa-ca-install fails on replica
11
Opened
4 years ago
by
cheimes
. Modified
4 years ago
freeipa
FreeIPA 4.7
critical
#6573
CA-less replica installation fails due to attempted cert issuance
1
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5
critical
#5523
[RFE] Update default profiles to always add SAN dnsName
3
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.4
important
#5999
Some cert commands are missing the --ca option
5
Opened
6 years ago
by
jcholast
. Modified
5 years ago
freeipa
FreeIPA 4.4
important
#57
[RFE] Support for multiple cert profiles
14
Opened
12 years ago
by
rcritten
. Modified
5 years ago
freeipa
FreeIPA 4.2
critical
#5968
renew_ca_cert helper cannot access config plugin
2
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.4
normal
#51
Support for specifying IPA lightweight CA
2
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
certmonger
0.0 NEEDS_TRIAGE
critical
#5733
CA ACL rejects user when full principal name used
2
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2.5
normal
#1628
Lightweight CAs: ensure disable CA cannot issue certificates
5
Opened
7 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
10.3.0.a2
major
#5089
certprofile: improve profile format documentation
5
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2.1
low
#6221
Certificate revocation in service-del and host-del isn't aware of Sub CAs
2
Opened
6 years ago
by
mkubik
. Modified
5 years ago
freeipa
FreeIPA 4.4.2
important
#6415
replica-install creates spurious entries in cn=certificates
4
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5
normal
#6146
caacl: error when instantiating rules with service principals
4
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.4.1
normal
#6987
ca-add: invalid X.509 DN fails ungracefully
2
Opened
5 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.6
#7503
multiple occurrences of profileId in certprofile causes incorrect behaviour
3
Opened
4 years ago
by
ftweedal
. Modified
4 years ago
freeipa
FreeIPA 4.6.4
#6432
cert-request: check SAN dnsNames against principal aliases
2
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
0.0 NEEDS_TRIAGE
normal
#6350
IDM admin password gets written to /root/.dogtag/pki-tomcat/ca/pkcs12_password.conf
2
Opened
6 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.5
normal
#5091
certprofile-show: add --output option
2
Opened
7 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2
normal
#5981
Unhandled PKI error in ca-add
1
Opened
6 years ago
by
mkubik
. Modified
5 years ago
freeipa
FreeIPA 4.4
normal
#4752
[RFE] Provide an IEC 62351-8 / DNP3 ID certificate profile
5
Opened
8 years ago
by
ftweedal
. Modified
5 years ago
freeipa
FreeIPA 4.2.1
important
#3085
CRLIP does not refresh CRL info from LDAP when re-initialised.
3
Opened
4 years ago
by
ftweedal
. Modified
2 years ago
dogtagpki
#6295
cert-request is not aware of Kerberos principal aliases
3
Opened
6 years ago
by
mbabinsk
. Modified
5 years ago
freeipa
FreeIPA 4.5
normal
#5093
certprofile-mod: add --file option to update profile data
2