Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-57674

Use RSNv3 and enable cert pruning by default in RHEL 10.0

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • ipa-4.12.2-8.el10
    • None
    • 6
    • rhel-idm-ipa
    • ssg_idm
    • 16
    • 14
    • 3
    • QE ack, Dev ack
    • False
    • False
    • Hide

      None

      Show
      None
    • Yes
    • 2024-Q3-Bravo-S6, 2024-Q4-Bravo-S1, 2024-Q4-Bravo-S2, 2024-Q4-Bravo-S3, 2024-Q4-Bravo-S4, 2024-Q4-Bravo-S5
    • Approved Exception
    • Enhancement
    • Hide
      .Automated removal of expired certificates is enabled by default

      With this update, automated removal of expired certificates is now enabled by default in Identity Management (IdM) on new replicas. A prerequisite for this is the generation of random serial numbers for certificates using RSNv3, which is now also enabled by default.

      As a result, certificates are now created with random serial numbers and are removed automatically when expired, after a default retention period of 30 days after expiry.
      Show
      .Automated removal of expired certificates is enabled by default With this update, automated removal of expired certificates is now enabled by default in Identity Management (IdM) on new replicas. A prerequisite for this is the generation of random serial numbers for certificates using RSNv3, which is now also enabled by default. As a result, certificates are now created with random serial numbers and are removed automatically when expired, after a default retention period of 30 days after expiry.
    • Done
    • None

      Goal

      • Enable RSN and enable cert pruning by default in RHEL10
      • Allow/force the replica to install with RSN as well

      Acceptance Criteria

      A list of verification conditions, successful functional tests, or expected outcomes in order to declare this story/task successfully completed.

      • IdM in RHEL10.0-beta uses/forces RSN as default
      • Migration procedure from RHEL9 to RHEL10 exists

              rhn-engineering-rcrit Rob Crittenden
              ftrivino@redhat.com Francisco Trivino Garcia
              Florence Renaud Florence Renaud
              Rizwan Shaikh Rizwan Shaikh
              David Vozenilek David Vozenilek
              Votes:
              0 Vote for this issue
              Watchers:
              12 Start watching this issue

                Created:
                Updated:
                Resolved: