'katello-certs-check' should display a warning messages if server.crt contains CN=shortname
Description of problem:
'katello-certs-check' succeeds if the server cert has CN=shortname.
We recommend Satellite configuration with FQDN and if customer tries to configure custom certs with short-name it creates lot of issues.
Steps to Reproduce:
1.Gnerate/get certs with satellite's shortname.
It should display a warining message.
It should fail.
Fixes #31326: Error in certs check if using only a shortname
Katello requires an FQDN be used for installation and thus the
same requirement exists for any custom certificates being used.
This adds a check that the CN is not set to a shortname, and/or
if using Subject Alt Name that there is not a single SAN that
is a shortname.
#3 Updated by Eric Helms 2 months ago
- Status changed from Ready For Testing to Closed
Applied in changeset installer|d215e0776c583fe68e8f23f936c4f8ed440b47f4.
#4 Updated by Ewoud Kohl van Wijngaarden about 2 months ago
- Triaged changed from No to Yes
- Target version set to 2.3.0
- Category set to foreman-installer script
- Subject changed from 'katello-certs-check' should display a warning messages if server.crt contains CN=shortname to 'katello-certs-check' should display a warning messages if server.crt contains CN=shortname
- Fixed in Releases 2.3.0 added
- Fixed in Releases deleted (