[Freeipa-devel] cert profiles - test plan + patches

Fraser Tweedale ftweedal at redhat.com
Tue Aug 11 01:17:19 UTC 2015


On Mon, Aug 10, 2015 at 11:36:31AM +0200, Milan Kubík wrote:
> On 08/05/2015 02:57 PM, Milan Kubík wrote:
> >Hi list,
> >
> >I'm sending the test plan [1] for certificate profiles and preliminary
> >patches for it.
> >The plan covers basic CRUD test and some corner cases. I'm open to more
> >suggestions.
> >
> >More complicated tests involving certificate profiles will require the
> >code (and tests)
> >for CA ACLs merged, so it's not there at the moment.
> >
> >There are some unfinished test cases in places I wasn't sure what the
> >result should be.
> >We need to iterate through these to fix it.
> >
> >
> >[1]: http://www.freeipa.org/page/V4/Certificate_Profiles/Test_Plan
> >
> >Cheers,
> >Milan
> Hi all,
> 
> have you had some time to look at the code and proposal?
> Today I want to write a basic CRUD test for the ACLs as well as a few test
> cases to check if the ACL is being enforced. It should make it into wiki
> today or by tomorrow. I'll send an update then.
> 
> Cheers,
> Milan
> 
Hi Milan,

I have reviewed the V4/Certificate_Profiles/Test_Plan.  Couple of
comments:

- Test case: Import profile with incorrect values
  - Expected result: refused with error.
  - A simple way to provoke this condition is to add a number to
    ``policyset.serverCertSet.list``.
  - A similar test case should exist for certprofile-mod.

- Test case: Delete default profile
  - As discussed elsewhere, expected result should be failure.
    I filed ticket #5198 to make it so :)

I will review the patch soon.

Cheers,
Fraser




More information about the Freeipa-devel mailing list