Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-80133

[RFE] Enable an option to be able to provide wildcard certificates in IdM ACME Dogtag CA

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Story Story
    • Resolution: Unresolved
    • Icon: Normal Normal
    • rhel-10.2
    • None
    • ipa
    • None
    • Moderate
    • 1
    • rhel-idm-pki
    • ssg_idm
    • 15
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • IPA: RHELs for 10.2 and 9.8
    • None
    • New Test Coverage
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      Dogtag CA ACME server supports wildcard certificates via the mechanism defined in the standard ACME protocol (RFC 8555), even with wildcard certificates enabled by default on standalone Dogtag / RHCS deployment, this option is disabled by default on IPA context. The objective of this RFE is to be able to test it and extend the ipa-acme-manage CLI program to provide a way to control that settings. With an option to be able to enable this wildcard certificates it will suffice.

      The are for example one option to be able to enable this like setting policy.wildcard=true in /etc/pki/pki-tomcat/acme/engine.conf  and use a regular acme client (e.g. certbot) to request a wildcard cert. But this is not optimal and not tested in our product and we need an easier and tested way to provide wildcard support to IPA. it's just about enable/disable this feature, is the feature available and enabled, or not.

              Unassigned Unassigned
              rh-ee-jfont Josep Andreu Font
              Sudhir Menon Sudhir Menon
              Votes:
              0 Vote for this issue
              Watchers:
              8 Start watching this issue

                Created:
                Updated: