#6831 Extend ipa-server-certinstall and ipa-certupdate to handle PKINIT certificates/anchors
Closed: fixed Opened by mbabinsk.

In order to fully support PKINIT configuration in CA-less deployments, the tools that manipulate 3rd party certificates must be extended to also install PKINIT server certificates and update KDC's PKINIT anchors when 3rd party CA certificates are to be used.


Metadata Update from @mbabinsk:
- Issue priority set to: 1

Metadata Update from @pvoborni:
- Custom field rhbz adjusted to https://bugzilla.redhat.com/show_bug.cgi?id=1438731

Metadata Update from @pvoborni:
- Custom field rhbz adjusted to https://bugzilla.redhat.com/show_bug.cgi?id=1438731

Issue linked to bug 1438731

Metadata Update from @pvoborni:
- Issue set to the milestone: FreeIPA 4.5.1

Metadata Update from @pvoborni:
- Issue assigned to mbabinsk

Metadata Update from @pvoborni:
- Assignee reset

Metadata Update from @dkupka:
- Issue assigned to dkupka

Metadata Update from @stlaz:
- Issue assigned to stlaz (was: dkupka)

Metadata Update from @jcholast:
- Issue assigned to jcholast (was: stlaz)

master:

  • 235265a5f5436148dd8d7e63b7e3928689796560 certdb: add named trust flag constants
  • f0442a2d0ed54abe6567fce6d99fd31f7c6c7883 certdb, certs: make trust flags argument mandatory
  • 52730c786f6bb11aa7992b11fa0f5c94c90f9eb8 certdb: use custom object for trust flags
  • 01a7416d305ddb11d5b83c99afbacf8ba854c148 install: trust IPA CA for PKINIT
  • 11b8a3434655932fa73f05d4bd864bed0194035c client install: fix client PKINIT configuration
  • 4d36cbf6ad412822b8fb029f517f9228e2c8d4ee install: introduce generic Kerberos Augeas lens
  • f769045f0ae9c5fdc651e03c0c96af9cdec8f298 server install: fix KDC PKINIT configuration
  • b9fd123d61fa7adda090c05216906ba0cf4779a9 ipapython.ipautil.run: Add option to set umask before executing command
  • 0c5b2c42bf52dc75ecf9d95036ca8517670877d6 certs: do not export keys world-readable in install_key_from_p12
  • cc572378a69a7e4d18b7297b7fa54e2fe8e33b2f certs: do not export CA certs in install_pem_from_p12
  • 3b5dbf7cdb4c03260057c8f7a2abd5c5712eca41 server install: fix KDC certificate validation in CA-less
  • b3855704f479eaf122139189b762b943b2dcc0fc replica install: respect --pkinit-cert-file
  • 9ea764ecf5c3118df0917d94c4940b4ee38b3a31 cacert manage: support PKINIT
  • 96ca62f81d3505b050eb9b9d71d4fc4c18e1535e server certinstall: support PKINIT

ipa-4-5:

  • 6338dbe47313a70b93bbf53855db451145d24544 certdb: add named trust flag constants
  • 749d504f4335c375cf86bf44814177f03be61b52 certdb, certs: make trust flags argument mandatory
  • e68812331526269f3b556c339f65077f649110d3 certdb: use custom object for trust flags
  • 16b295c5a8580accfbbab016f3cc4eef0a704163 install: trust IPA CA for PKINIT
  • 63c4cbd619f81f16e0c08d3786b69d348c9dcfd7 client install: fix client PKINIT configuration
  • 523a82652e2f95704a07ac25cc829a0782b9e22a install: introduce generic Kerberos Augeas lens
  • b83ebe0e3ff692de37f28834d09a423d04e6ad68 server install: fix KDC PKINIT configuration
  • 5cf5395eb51ff5ec8164075a5ee573abe76bc15e ipapython.ipautil.run: Add option to set umask before executing command
  • e6497f099c09dfa60bd6ae98e4692e99b7381752 certs: do not export keys world-readable in install_key_from_p12
  • bc8deb118dce93fc380793c75090d9108ce61541 certs: do not export CA certs in install_pem_from_p12
  • cbdf6693cc8707dda9c1db42fb05dc5b1d70b7af server install: fix KDC certificate validation in CA-less
  • 77ef29ef30086c714025d97328507bd51e3f0421 replica install: respect --pkinit-cert-file
  • 6f900ec60a426a2b97823d4612949a953fa6d49b cacert manage: support PKINIT
  • e27b3e139ffff16f6e238ef6f9ff7d2ed02492bc server certinstall: support PKINIT

Metadata Update from @mbasti:
- Issue close_status updated to: fixed
- Issue status updated to: Closed (was: Open)

Metadata