[Freeipa-devel] cert profiles - test plan + patches

Kaleemullah Siddiqui ksiddiqu at redhat.com
Mon Aug 10 17:16:59 UTC 2015



On 08/10/2015 08:54 PM, Scott Poore wrote:
>
> ----- Original Message -----
>> From: "Milan Kubík" <mkubik at redhat.com>
>> To: "freeipa-devel" <freeipa-devel at redhat.com>, "Scott Poore" <spoore at redhat.com>, "Fraser Tweedale"
>> <ftweedal at redhat.com>
>> Cc: "Namita Soman" <nsoman at redhat.com>, "Ales Marecek" <amarecek at redhat.com>
>> Sent: Monday, August 10, 2015 4:36:31 AM
>> Subject: Re: cert profiles - test plan + patches
>>
>> On 08/05/2015 02:57 PM, Milan Kubík wrote:
>>> Hi list,
>>>
>>> I'm sending the test plan [1] for certificate profiles and preliminary
>>> patches for it.
>>> The plan covers basic CRUD test and some corner cases. I'm open to more
>>> suggestions.
>>>
>>> More complicated tests involving certificate profiles will require the
>>> code (and tests)
>>> for CA ACLs merged, so it's not there at the moment.
>>>
>>> There are some unfinished test cases in places I wasn't sure what the
>>> result should be.
>>> We need to iterate through these to fix it.
>>>
>>>
>>> [1]: http://www.freeipa.org/page/V4/Certificate_Profiles/Test_Plan
>>>
>>> Cheers,
>>> Milan
>> Hi all,
>>
>> have you had some time to look at the code and proposal?
>> Today I want to write a basic CRUD test for the ACLs as well as a few
>> test cases to check if the ACL is being enforced. It should make it into
>> wiki today or by tomorrow. I'll send an update then.
> I haven't looked at the actual code yet.  Is it checked into git for freeipa yet?
>
> This looks good to me for the basic CRUD tests.   I do have some questions and requests.
>
> Existing tests:
>
> * Delete default profile
> - Did you find out what the expected result should be?
>
> * Try to rename the profile entry
> - Can this be renamed to be more specific to trying to rename ldap attr?
> - Can we get a new test case to test renaming with certprofile-mod --rename?
>
> Possible new tests:
>
> * Import a profile in xml
> - This should fail and I think is at least in the beginning a common mistake.
>
> * Change profile config from file
> - This one may be too large in scope but, could be limited to changing something simple to make sure the file is read and used.
>
> Where are you planning to put the CA ACL tests?  In the same page?
>
> When you have that will you be adding a cert-request test?
Some additional test cases
(1) Non-existent profile with certprofile-show
(2) certprofile-import with --store both true/false options
(3) certprofile-find with store option
>
> Thanks,
> Scott
>> Cheers,
>> Milan
>>
>>




More information about the Freeipa-devel mailing list