#7885 RFE: wrapper for Dogtag cert-fix command
Closed: fixed by ftweedal. Opened by ftweedal.

RFE: implement a wrapper for the Dogtag offline renewal tool
(https://pagure.io/dogtagpki/issue/2776) that handles IPA-specific certificates and scenarios.

In particular:

  • Identify IPA-specific certificates that need renewal
  • Run pki-server cert-fix with appropriate arguments
  • Copy IPA-related renewed certificates to correct locations (files, NSSDBs, LDAP)
  • Become the renewal master if "shared" certificates were renewed.

ipa-4-6:

  • 0a54a4c83f4e613ef5a7e52b697d849cf3676d22 Extract ca_renewal cert update subroutine
  • 4f42ba8625436806120c6dbb6345f7327b06cd0a cainstance: add function to determine ca_renewal nickname
  • 01a487ede34c351f0916e480ba7cbc96ba6b4f7c constants: add ca_renewal container
  • a2f9a704e8145b9d0c0b14a3005efd4a44a64532 Add ipa-cert-fix tool
  • d0b9507e677042d5acba036e6d872fbcf247b28a ipa-cert-fix: add man page
  • e3131495f07ce633fda86486056300138ff8fc80 ipa-cert-fix: use customary exit statuses

Metadata Update from @frenaud:
- Custom field rhbz adjusted to https://bugzilla.redhat.com/show_bug.cgi?id=1690191

I'm looking to get the Dogtag cert-fix enhancements merged into master and the 10.6 branch, before doing the forward port of ipa-cert-fix to IPA master and ipa-4-7. (A bit hard for folks to test otherwise).

The Dogtag PR for master is here: https://github.com/dogtagpki/pki/pull/182. 10.6 branch will follow merge to master.

10.6 PR here: https://github.com/dogtagpki/pki/pull/181. The forward-port is still blocked on an upstream Dogtag release that contains pki-server cert-fix with required features.

IPA master PR: https://github.com/freeipa/freeipa/pull/3136

master:

  • a2a006c74667155e5e4c4a1bb0bd9c12da9b4aed Extract ca_renewal cert update subroutine
  • c28a42e27e1cff115aca1066bf3c943ff46ccc48 cainstance: add function to determine ca_renewal nickname
  • a3becc76dd22b3f26442261f163824264e7b8425 constants: add ca_renewal container
  • 09aa3d1f769ac532069e2c39c2ff1eaf8ba0331f Add ipa-cert-fix tool
  • a9f09fee56645120d2e202e5707dc017f8d3d3f3 ipa-cert-fix: add man page
  • e41b7457f3acd3bf6c1db17c5d14c23f81c0ad4b ipa-cert-fix: use customary exit statuses
  • 72027226821f9dfc92b6ece0fefbccab1430c95c require Dogtag 10.7.0-1
  • 582cc7da1dde44618b57d4073a8513e92ecd4783 ipa-cert-fix: handle 'pki-server cert-fix' failure
  • 162dce1c70f8585931e3b748790bc313d6fcd1fe ipa-cert-fix: fix spurious renewal master change
  • f30f040dca1c262541933ebefbc08b6356e42530 (HEAD) avoid realm_to_serverid deprecation warning

ipa-4-7 PR: https://github.com/freeipa/freeipa/pull/3211

couple of fixes for ipa-4-6: https://github.com/freeipa/freeipa/pull/3180

ipa-4-6:

  • 1ee6bb2a019e6b042de7536a9b8e179d375b8b9e ipa-cert-fix: handle 'pki-server cert-fix' failure
  • 4c25a83c30b63228f19ffa7e1e1f6d86fe08fe90 (HEAD) ipa-cert-fix: fix spurious renewal master change

ipa-4-7:

  • 74677ec9fce47cbfe035ea409753c5fac2f629de Extract ca_renewal cert update subroutine
  • 9e514b5935ea526897c5c6d94a41c8a75c2da2ee cainstance: add function to determine ca_renewal nickname
  • 2affa462f31d1f636237bd33d4e96986486df25b constants: add ca_renewal container
  • 016e66811ae808ead5c9ae4784b6b4c7782f0505 Add ipa-cert-fix tool
  • 71de231c69f237a811cab0687df7fffab9074608 ipa-cert-fix: add man page
  • 9b9d0c4cfd6b66645fa56b8f7f4de20468fde445 ipa-cert-fix: use customary exit statuses
  • 4683c6b2efb83da0765b74c12b2795c04b620b36 require Dogtag 10.7.0-1
  • 392c99e12cc6ad5ad2169831c3e6051af76382cd ipa-cert-fix: handle 'pki-server cert-fix' failure
  • 266746ffd19b032e4ca229b375aa8aa70ec927a6 (HEAD) ipa-cert-fix: fix spurious renewal master change

Metadata Update from @ftweedal:
- Issue close_status updated to: fixed
- Issue status updated to: Closed (was: Open)

master:

  • f49c7dafc4a6660db0fbac1e6bd1a5788762e47f ipatests: Test if ipa-cert-fix renews expired certs
  • f7ef6d5ab78e8d692f8777fe95230ae428f2e7e9 Move fixture outside the class and add setup_kra capability
  • 0904bb2387738c3eddf89d27f0c18123a083f99e ipatests: Test if ipa-cert-fix renews expired certs with kra installed
  • 1197e2ef852336325027a4f02907b0e10ba2823a ipatests: update nightly definition for ipa_cert_fix suite

ipa-4-9:

  • 7f30ddb1b7e30c22f9b7d14d2658b58a0ea6b459 ipatests: Test if ipa-cert-fix renews expired certs
  • 36a60dbb35cb4429f00528f79bec8b7982a30c74 Move fixture outside the class and add setup_kra capability
  • c84e0547e1a693ba0e9edbfeea7bafdb2fb2b4a2 ipatests: Test if ipa-cert-fix renews expired certs with kra installed
  • 260fbcb03297ef1ed5418b16c0df0587d2989b22 ipatests: update nightly definition for ipa_cert_fix suite

master:

  • 99e7ad0fd8d7f621f1d3999c3fb7327802293ec6 ipatests: test to renew certs on replica using ipa-cert-fix

ipa-4-9:

  • e0aef5296b66c0b460f7e10993610fe68b312241 ipatests: test to renew certs on replica using ipa-cert-fix
  • a620e5e9e152defe144705913521c3cf556faa0e ipatests: wait while http/ldap/pkinit cert get renew on replica
  • 1b38afc0487efde57f04cf4a8c15f03be46971f3 ipatests: update the timemout for test_ipa_cert_fix.py in nightlies
  • 4a3a15f45aad016730252c09e3e173a18184603e ipatests: refactor test_ipa_cert_fix with tasks

master:

  • 50c6359 ipatests: wait while http/ldap/pkinit cert get renew on replica
  • c963adc ipatests: update the timemout for test_ipa_cert_fix.py in nightlies
Metadata