Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-15892

Redundant cert/CSR data in CS.cfg

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done-Errata
    • Icon: Undefined Undefined
    • rhel-9.4
    • rhel-9.3.0
    • pki-core
    • None
    • pki-core-11.5.0-0.1.alpha5.el9
    • None
    • rhel-sst-idm-cs
    • ssg_idm
    • None
    • QE ack, Dev ack
    • False
    • Hide

      None

      Show
      None
    • Yes
    • None
    • Pass
    • Hide
      pki-jackson-core-2.14.1-2.el9.noarch
      pki-jackson-annotations-2.14.1-1.el9.noarch
      pki-jackson-databind-2.14.1-2.el9.noarch
      pki-jackson-module-jaxb-annotations-2.14.1-2.el9.noarch
      pki-jackson-jaxrs-providers-2.14.1-2.el9.noarch
      pki-jackson-jaxrs-json-provider-2.14.1-2.el9.noarch
      pki-resteasy-core-3.0.26-18.el9.noarch
      pki-resteasy-servlet-initializer-3.0.26-18.el9.noarch
      pki-resteasy-client-3.0.26-18.el9.noarch
      pki-resteasy-jackson2-provider-3.0.26-18.el9.noarch
      idm-jss-5.5.0-0.4.alpha3.el9.x86_64
      python3-idm-pki-11.5.0-0.1.alpha8.el9.noarch
      idm-pki-base-11.5.0-0.1.alpha8.el9.noarch
      idm-pki-java-11.5.0-0.1.alpha8.el9.noarch
      idm-pki-tools-11.5.0-0.1.alpha8.el9.x86_64
      idm-jss-tomcat-5.5.0-0.4.alpha3.el9.x86_64
      idm-pki-server-11.5.0-0.1.alpha8.el9.noarch
      idm-pki-ca-11.5.0-0.1.alpha8.el9.noarch
      idm-pki-kra-11.5.0-0.1.alpha8.el9.noarch
      Show
      pki-jackson-core-2.14.1-2.el9.noarch pki-jackson-annotations-2.14.1-1.el9.noarch pki-jackson-databind-2.14.1-2.el9.noarch pki-jackson-module-jaxb-annotations-2.14.1-2.el9.noarch pki-jackson-jaxrs-providers-2.14.1-2.el9.noarch pki-jackson-jaxrs-json-provider-2.14.1-2.el9.noarch pki-resteasy-core-3.0.26-18.el9.noarch pki-resteasy-servlet-initializer-3.0.26-18.el9.noarch pki-resteasy-client-3.0.26-18.el9.noarch pki-resteasy-jackson2-provider-3.0.26-18.el9.noarch idm-jss-5.5.0-0.4.alpha3.el9.x86_64 python3-idm-pki-11.5.0-0.1.alpha8.el9.noarch idm-pki-base-11.5.0-0.1.alpha8.el9.noarch idm-pki-java-11.5.0-0.1.alpha8.el9.noarch idm-pki-tools-11.5.0-0.1.alpha8.el9.x86_64 idm-jss-tomcat-5.5.0-0.4.alpha3.el9.x86_64 idm-pki-server-11.5.0-0.1.alpha8.el9.noarch idm-pki-ca-11.5.0-0.1.alpha8.el9.noarch idm-pki-kra-11.5.0-0.1.alpha8.el9.noarch
    • Automated
    • None

      The cert/CSR data stored in CS.cfg might actually be redundant/unused, but it's difficult to determine with 100% certainty.

      Goal

      • Remove cert/CSR from configuration.
        • As a User/Actor, I Want access the certificate from the certificate DB and have a single source of truth and CSR from a configured location, so to avoid consistency problems.

      Acceptance Criteria

      The task successfully completed if:

      • New instance will not use certificates from CS.cfg configuration file
      • Running instance are automatically updated to the new schema

              Unassigned Unassigned
              rh-ee-mfargett Marco Fargetta
              RHCS Maintenance RHCS Maintenance
              Pritam Singh Pritam Singh
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated:
                Resolved: