Actions
Bug #16262
openValidate that the capsule cert's CN doesn't match the server FQDN
Status:
New
Priority:
Normal
Assignee:
-
Category:
Installer
Target version:
-
Description
Making a full validation of CN of certs might be too complex to provide
(we would need to the the interpretation of wildcards etc.) However,
we what we could do is checking, that:
1. in CN or alternative names, there is the FQDN of the capsule, if yes, pass
2. there is '*' in the CN or alternative names, if yes, pass (expecting the admins know, that they are doing when using those)
We can't do it in katello-certs-check, as the we don't know what the capsule fqdn is,
the correct place to put it in would be probably capsule-certs-generate
Actions