#2999 Cert validation for installation with external CA cert
Closed: fixed Opened by mharmsen.

RootCA --> externalCA(cmc) ---> another externalCA (cmc)
(Level1) (Level2) (Level3)

Level1 -- worked
Level2 -- worked
Level3 -- failure

Steps to Reproduce:

1.Setup a RootCA
2.Setup externalCA1 signed using CMC mechanism with RootCA
3.Setup externalCA2 signed using CMC mechanism with ExternalCA

Actual results:

ExternalCA2 install fails

Expected results:

ExternalCA2 install should work without failures.

Additional info:

This is same in case of a non-cmc environment.
See detailed info in the associated rhbz.

Per 10.5.x/10.6 Triage: 10.5

edewata: seems to be a common scenario.

Metadata Update from @mharmsen:
- Custom field component adjusted to None
- Custom field feature adjusted to None
- Custom field origin adjusted to None
- Custom field proposedmilestone adjusted to None
- Custom field proposedpriority adjusted to None
- Custom field reviewer adjusted to None
- Custom field rhbz adjusted to https://bugzilla.redhat.com/show_bug.cgi?id=1540924
- Custom field type adjusted to None
- Custom field version adjusted to None

Metadata Update from @mharmsen:
- Issue assigned to edewata

Metadata Update from @mharmsen:
- Issue priority set to: critical (was: major)

Fixed in master branch:

  • https://github.com/dogtagpki/pki/commit/6c3ca7d4dcaf804ef46a42206ac95974beba7965

Fixed in 10.5 branch:

  • https://github.com/dogtagpki/pki/commit/313c701957bedfd59f7f6368d0c37d2928d1a4a1

Metadata Update from @edewata:
- Issue set to the milestone: 10.5.9 (was: 10.5)

Metadata Update from @edewata:
- Issue status updated to: Closed (was: Open)

Metadata Update from @mharmsen:
- Issue close_status updated to: fixed

Dogtag PKI is moving from Pagure issues to GitHub issues. This means that existing or new
issues will be reported and tracked through Dogtag PKI's GitHub Issue tracker.

This issue has been cloned to GitHub and is available here:
https://github.com/dogtagpki/pki/issues/3117

If you want to receive further updates on the issue, please navigate to the
GitHub issue and click on Subscribe button.

Thank you for understanding, and we apologize for any inconvenience.

Metadata