Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-146147

Fix dsconf to allow specifying multiple certificates for use in 389-ds server

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Major Major
    • rhel-10.3
    • rhel-10.2
    • 389-ds-base
    • None
    • None
    • None
    • rhel-idm-ds
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      For post-quantum cryptography migration, it is expected that a deployment might be in a transitional state where some clients will understand PQC algorithms and some aren't yet. Therefore, 389-ds LDAP server needs to be able to negotiate LDAPS or LDAP+startTLS with both types of clients by providing both ML-DSA and RSA/EC certificates.

      This is already possible when configured manually but dsconf tool hardcodes a certificate name (CN) to Server-Cert, making it impossible to add multiple certificates through the dsconf tool.

              Unassigned Unassigned
              abokovoy@redhat.com Alexander Bokovoy
              IdM DS Dev IdM DS Dev
              IdM DS QE IdM DS QE
              Evgenia Martyniuk Evgenia Martyniuk
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated: