Project

General

Profile

Actions

Bug #32288

closed

Server CA cert not verified for IPA token API call

Added by Lukas Zapletal over 3 years ago. Updated over 3 years ago.

Status:
Closed
Priority:
Normal
Category:
Security
Target version:
-
Difficulty:
Triaged:
Yes
Fixed in Releases:
Found in Releases:

Description

Smart proxy ignores CA server certificate for a HTTPS call to IPA when fetching the token:

https://github.com/theforeman/smart-proxy/blob/88fbc8e67d665e2c3b19acb53b31ff30acf078b7/modules/realm_freeipa/provider.rb#L32-L38

There should be a setting to verify CA cert (enabled by default), an installer option and instructions in our documentation on how to enroll na CA cert into the OS cert store.

This issue was reported by Evgeni Golov, thank you.


Related issues 1 (1 open0 closed)

Related to Installer - Feature #32289: Option to toggle IPA API server CA verificationNewActions
Actions

Also available in: Atom PDF