#7000 Provide a simple command to issue KDC certificates on a IPA master
Closed: fixed Opened by mbabinsk.

If an admin of a PKINIT-less deployment wishes to configure PKINIT e.g. by issuing KDC certificates from IPA CA, he currently has no other option than to run upgrader. We should be able to easily extract this functionality to a separate CLI command which can be called per master and replace self-signed KDC keypair by a IPA CA issued KDC cert.


Metadata Update from @pvoborni:
- Custom field rhbz adjusted to https://bugzilla.redhat.com/show_bug.cgi?id=1455946

Metadata Update from @pvoborni:
- Custom field rhbz adjusted to https://bugzilla.redhat.com/show_bug.cgi?id=1455946

Issue linked to bug 1455946

Metadata Update from @mbabinsk:
- Issue priority set to: critical
- Issue set to the milestone: FreeIPA 4.5.2

ipa-4-5:

  • 1b62e5aac9d9668604e82879c020bff310fa549f server certinstall: update KDC master entry
  • c072135340bc8e75f621e2b9163b1347b9eb528f pkinit manage: introduce ipa-pkinit-manage
  • cb9353d6e0fbc0912dd20bf29e3835a7740d1af6 server upgrade: do not enable PKINIT by default

master:

  • e131905f3e0fe9179c5f4a09da4e7a204012603a server certinstall: update KDC master entry
  • 92276c1e8809f3ff6b59bd6124869f816627bac7 pkinit manage: introduce ipa-pkinit-manage
  • 0772ef20b39b11950fddc913a350534988294c89 server upgrade: do not enable PKINIT by default

Metadata Update from @mbabinsk:
- Issue close_status updated to: fixed
- Issue status updated to: Closed (was: Open)

Metadata