#1484 Inconsistent key record creation
Closed: migrated by dmoluguw. Opened by edewata.

The key record in LDAP is created using IKeyRepository.addKeyRecord(record), which is called by several KRA services. The problem is those services do not construct the key record Java object consistently, leading to incomplete key records in LDAP (e.g. missing data type) such as shown in ticket #1481.

One solution is to inspect all codes that call addKeyRecord() to make sure they generate valid key record objects in all cases. This solution doesn't guarantee that future code will not generate invalid key record objects since the validation is only done one time.

Another option is to enforce key record schema, either in Java or in LDAP. A buggy service might break, but at least it won't produce an invalid LDAP key record.

Another option is to create a factory/builder class that prepares a valid initial record object (i.e. with default values), then all modifications to the record object will have to be done via the factory/builder methods that guarantee that the resulting object will still be valid.

Regardless of the options above, the existing key records in LDAP that are incomplete should be fixed using a database upgrade script (depends on #710).

Proposed milestone: 10.3


Per CS/DS meeting of 07/13/2015: 10.3

Metadata Update from @edewata:
- Issue set to the milestone: UNTRIAGED

Dogtag PKI is moving from Pagure issues to GitHub issues. This means that existing or new
issues will be reported and tracked through Dogtag PKI's GitHub Issue tracker.

This issue has been cloned to GitHub and is available here:
https://github.com/dogtagpki/pki/issues/2043

If you want to receive further updates on the issue, please navigate to the
GitHub issue and click on Subscribe button.

Thank you for understanding, and we apologize for any inconvenience.

Metadata Update from @dmoluguw:
- Issue close_status updated to: migrated
- Issue status updated to: Closed (was: Open)

Metadata