#6256 [tracker] Revoke certificate on lightweight CA deletion
Closed: Fixed Opened by ftweedal.

Lightweight CAs should be revoked on deletion.

This will be implemented in Dogtag. The IPA-side work for this
ticket is simply to bump the pki minimum version to one that has
revoke-on-delete implement, and to clearly document the behaviour.


See #6220 for related discussion.

master:

  • 6b3f4984296f3caff8f29490eae3ed1dca64b8c3 spec: require Dogtag >= 10.3.5-6
  • 2b8163ab5dfcf28a9eba319ef685046ae9d8b5e8 Add commentary about CA deletion to plugin doc

ipa-4-4:

  • 358e50b2e194d3ae3d0e8c22c774a24ab84d8be1 spec: require Dogtag >= 10.3.5-6
  • 810c38efce6a3911b39e29b7aac010e467ef25a7 Add commentary about CA deletion to plugin doc

Metadata Update from @ftweedal:
- Issue assigned to ftweedal
- Issue set to the milestone: FreeIPA 4.4.2

Metadata