freeipa / ansible-freeipa

Ansible roles and modules for FreeIPA
GNU General Public License v3.0
480 stars 231 forks source link

Fix ca-less test to use X.509 v3 certificates #1215

Closed t-woerner closed 4 months ago

t-woerner commented 4 months ago

The generated certificates have been X.509 v1. This is not supported any more. Only X.509 v3 is supported.

A new certificates/extensions.conf file has been added to make v3 certificates.

The existing certificates/pkinit/extensions.conf has been renamed to certificates/pkinit-extensions.conf with additional changes. For example "[kdc_cert]" had to be removed for v3.

The extensions config files are using environment variables, which are set by the generate-certificates.sh script before calling openssl.

The script generate-certificates.sh has been reworked for a simpler structure, also new options have been added: "ca" and "cleanup".