dogtagpki / pki

The Dogtag Certificate System is an enterprise-class Certificate Authority (CA) which supports all aspects of certificate lifecycle management, including key archival, OCSP and smartcard management.
https://www.dogtagpki.org
GNU General Public License v2.0
369 stars 136 forks source link

Automatic key recovery when the token is terminated #2729

Open pki-bot opened 4 years ago

pki-bot commented 4 years ago

This issue was migrated from Pagure Issue #2609. Originally filed by mharmsen (@mharmsen) on 2017-03-03 12:40:18:


Automatic key recovery when the token is terminated

Steps to Reproduce:

  1. MAke the following changes to TPS CS.cfg op.enroll.userKey.keyGen.encryption.recovery.terminated.holdRevocationUntilLast Credential=false op.enroll.userKey.keyGen.encryption.recovery.terminated.revokeCert=true op.enroll.userKey.keyGen.encryption.recovery.terminated.revokeCert.reason=1 op.enroll.userKey.keyGen.encryption.recovery.terminated.revokeExpiredCerts=false op.enroll.userKey.keyGen.encryption.recovery.terminated.scheme= GenerateNewKeyAndRecoverLast
  2. Enroll a smartcard token
  3. Mark the token terminated
  4. Issue a new token for the user

Actual results:

New certificates are generated for the token

Expected results:

the new token should have the encryption cert on the terminated token recovered on it.

Additional info:

Attaching the log debug log info to associated bug.

pki-bot commented 4 years ago

Comment from mharmsen (@mharmsen) at 2017-03-03 12:40:19

Metadata Update from @mharmsen:

pki-bot commented 4 years ago

Comment from mharmsen (@mharmsen) at 2017-03-03 12:40:19

Metadata Update from @mharmsen:

pki-bot commented 4 years ago

Comment from mharmsen (@mharmsen) at 2017-03-03 18:54:29

Metadata Update from @mharmsen:

pki-bot commented 4 years ago

Comment from mharmsen (@mharmsen) at 2017-08-09 12:36:57

Per CS/DS Meeting of August 7, 2017, it was determined to move this issue from 10.4 ==> FUTURE.

pki-bot commented 4 years ago

Comment from mharmsen (@mharmsen) at 2017-08-09 12:36:57

Metadata Update from @mharmsen: