#50250 RFE attribute/changelog encryption require export/import on certificate renewal
Closed: wontfix by mreynolds. Opened by tbordaz.

Issue Description

attribute or changelog encryption use a symmetric key (stored in attribute/changelog config). This symmetric key is wrapped using the private key from the server-cert certificate.
The private key is lost on certificate renewal so DB/changelog_DB need to be export/import.

This RFE is to evaluate if an other mechanism could be use to avoid export/import

Package Version and Platform

All version

Steps to reproduce

1.Enable changelog encryption or attribute encryption
2. add few entries
3. stop DS
4. renew certificate
5. start DS and check if replication/update are possible

Actual results

Expected results


could you also have a look at https://pagure.io/389-ds-base/issue/49525

that is for attr encryption, but should apply to changelog as well, maybe we can really simplify the key rollover

Metadata Update from @lkrispen:
- Custom field origin adjusted to None
- Custom field reviewstatus adjusted to None

Closing as duplicate of 49525

Metadata Update from @mreynolds:
- Issue close_status updated to: duplicate
- Issue status updated to: Closed (was: Open)

389-ds-base is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in 389-ds-base's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/389ds/389-ds-base/issues/3309

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Metadata Update from @spichugi:
- Issue close_status updated to: wontfix (was: duplicate)

Metadata