dogtagpki / pki

The Dogtag Certificate System is an enterprise-class Certificate Authority (CA) which supports all aspects of certificate lifecycle management, including key archival, OCSP and smartcard management.
https://www.dogtagpki.org
GNU General Public License v2.0
363 stars 135 forks source link

Removing subject DN requirement when submitting a CSR via CLI #2264

Open pki-bot opened 3 years ago

pki-bot commented 3 years ago

This issue was migrated from Pagure Issue #1705. Originally filed by edewata (@edewata) on 2015-11-26 00:33:41:


Currently when submitting a CSR via CLI the user is still required to specify a request type and a subject DN:

$ pki ca-cert-request-submit \
 --profile caUserCert \
 --csr-file testuser.csr \
 --request-type pkcs10 \
 --subject UID=testuser,O=EXAMPLE

To improve usability, the CLI should obtain the request type and subject DN from the CSR itself. The server should also obtain the information from the CSR directly.

The client may display the request data for confirmation:

$ pki ca-cert-request-submit --profile caUserCert --csr-file testuser.csr
Certificate request:
  Request type     : PKCS 10
  Subject:
    UID            : testuser
    Organization   : EXAMPLE
  Key Type         : RSA
  Key Size         : 2048
  ...
Submit certificate request (Y/n)? 

There should also be an option to skip the confirmation:

$ pki ca-cert-request-submit --profile caUserCert --csr-file testuser.csr -y
pki-bot commented 3 years ago

Comment from mharmsen (@mharmsen) at 2015-11-30 21:24:22

Per CS/DS Meeting of 11/30/2015: 10.3 minor

pki-bot commented 3 years ago

Comment from ftweedal (@frasertweedale) at 2016-01-12 02:56:11

fixed in ec9c68d68eabff3784fcf6dabf2c6745734b3c9c

pki-bot commented 3 years ago

Comment from mharmsen (@mharmsen) at 2016-01-26 23:35:17

Ticket has been cloned to Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=1302125

pki-bot commented 3 years ago

Comment from ftweedal (@frasertweedale) at 2016-01-27 01:37:16

Misinterpreted this bug - it is for additional enhancements to the csr-file option implemented in the referenced commit.

Reopening.

pki-bot commented 3 years ago

Comment from mharmsen (@mharmsen) at 2016-04-21 00:31:39

Per CS Bug/Ticket Triage held 04/19/2016: 10.4

pki-bot commented 3 years ago

Comment from mharmsen (@mharmsen) at 2016-12-01 21:20:28

Per Offline Triage of 11/30/2016-12/01/2016: FUTURE - minor

pki-bot commented 3 years ago

Comment from edewata (@edewata) at 2017-02-27 14:10:19

Metadata Update from @edewata:

pki-bot commented 3 years ago

Comment from mharmsen (@mharmsen) at 2018-04-18 20:07:47

Per 10.5.x/10.6 Triage: FUTURE

RHBZ: CLOSED UPSTREAM

pki-bot commented 3 years ago

Comment from mharmsen (@mharmsen) at 2018-04-18 20:07:47

Metadata Update from @mharmsen: