[Pki-devel] [PATCH] pki-cfu-0045-Ticket-1028-phase2-TPS-rewrite-provide-externalReg-f.patch

Christina Fu cfu at redhat.com
Fri Apr 10 23:18:26 UTC 2015


Please review.

This patch is the 2nd phase of the externalReg feature, it makes the 
following improvements:
* added feature: recovery by keyid (v.s. by cert)
* fixed some auditing message errors
* added some missing ldapStringAttributes needed for delegation to work 
properly
* added missing externalReg required config parameters
* made corrections to some externalReg related parameters to allow 
delegation to work properly
* added handle of some error cases
* made sure externalReg enrollment does not go half-way (once fails, 
bails out)

tested:
* enrollment of the three default TPS profiles (tokenTypes)
* format of the tokens enrolled with the three default tps profiles
* delegation enrollments
* cuid match check

next phase:
* cert/key retention (allow preserving existing certs/keys on the token)

note:
* some of the activity log and cert status related issues that are not 
specifically relating to externalReg will be addressed in other more 
relevant tickets.

thanks,
Christina
-------------- next part --------------
A non-text attachment was scrubbed...
Name: pki-cfu-0045-Ticket-1028-phase2-TPS-rewrite-provide-externalReg-f.patch
Type: text/x-patch
Size: 66177 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/pki-devel/attachments/20150410/2d9d618e/attachment.bin>


More information about the Pki-devel mailing list