-
Bug
-
Resolution: Unresolved
-
Major
-
None
-
None
-
False
-
sat-endeavour
-
None
-
None
-
None
-
None
Description of problem:
https://docs.redhat.com/en/documentation/red_hat_satellite/6.16/html-single/administering_red_hat_satellite/index#planning-for-self-signed-ca-certificate-renewal outlines a procedure to use temporary dual CA during certificate renewal. The overview procedure has two issues:
1) each point should link to the corresponding section of documentation with particular procedure / commands to execute, such that user knows how to execute each step. E.g. currently, a user reading "Add the new SSL certificate to the CA certificate file on Satellite Server" has no idea what particular file on Satellite to update.
2) The step "Deploy the dual CA certificate on hosts. " must mention (directly here or in the linked content) that we need to update Host on two places: A) system trust , and B) also RHSM katello CA (`/etc/rhsm/ca/katello-server-ca.pem` one). That is, we must apply both steps from https://github.com/theforeman/foreman/blob/develop/app/views/unattended/provisioning_templates/snippet/ca_registration.erb in either way.