pki-bot / pki-issues-final

0 stars 0 forks source link

Move serial/request number range configuration into LDAP #1643

Open pki-bot opened 4 years ago

pki-bot commented 4 years ago

This issue was migrated from Pagure Issue #1655. Originally filed by edewata (@edewata) on 2015-10-15 04:36:08:


Currently the serial/request number range configuration is stored in CS.cfg:

dbs.beginReplicaNumber=98
dbs.beginRequestNumber=9990001
dbs.beginSerialNumber=fff0001
dbs.enableRandomSerialNumbers=false
dbs.enableSerialManagement=true
dbs.endReplicaNumber=100
dbs.endRequestNumber=10000000
dbs.endSerialNumber=10000000
dbs.ldap=internaldb
dbs.newSchemaEntryAdded=true
dbs.nextBeginRequestNumber=10000001
dbs.nextBeginSerialNumber=10000001
dbs.nextEndRequestNumber=20000000
dbs.nextEndSerialNumber=20000000
dbs.randomSerialNumberCounter=-1
dbs.replicaCloneTransferNumber=5
dbs.replicaDN=ou=replica
dbs.replicaIncrement=100
dbs.replicaLowWaterMark=20
dbs.replicaRangeDN=ou=replica, ou=ranges
dbs.requestCloneTransferNumber=10000
dbs.requestDN=ou=ca, ou=requests
dbs.requestIncrement=10000000
dbs.requestLowWaterMark=2000000
dbs.requestRangeDN=ou=requests, ou=ranges
dbs.serialCloneTransferNumber=10000
dbs.serialDN=ou=certificateRepository, ou=ca
dbs.serialIncrement=10000000
dbs.serialLowWaterMark=2000000
dbs.serialRangeDN=ou=certificateRepository, ou=ranges

Some of these parameters are redundant because they are already stored in LDAP (e.g. endRequestNumber, endSerialNumber, nextEndRequestNumber, nextEndSerialNumber), so they can be removed from CS.cfg.

Ideally most of these parameters can be moved to LDAP as well, leaving only the following parameters in CS.cfg:

dbs.ldap=internaldb
dbs.replicaDN=ou=replica
dbs.replicaRangeDN=ou=replica, ou=ranges
dbs.requestDN=ou=ca, ou=requests
dbs.requestRangeDN=ou=requests, ou=ranges
dbs.serialDN=ou=certificateRepository, ou=ca
dbs.serialRangeDN=ou=certificateRepository, ou=ranges
pki-bot commented 4 years ago

Comment from mharmsen (@mharmsen) at 2015-10-19 20:50:42

Per CS/DS Meeting of 10/19/2015: 10.4

pki-bot commented 4 years ago

Comment from edewata (@edewata) at 2017-02-27 13:58:55

Metadata Update from @edewata: