Skip to content

Commit

Permalink
Update admin cert profile in tests
Browse files Browse the repository at this point in the history
Previously the subject DN for admin certs in tests were
changed into uid=<username> since it's required by the
caUserCert profile.

The tests have been updated to use the AdminCert profile
which allows any subject DN, so the subject DN no longer
needs to be replaced.
  • Loading branch information
edewata committed Jun 8, 2023
1 parent 207efa5 commit 2b84210
Show file tree
Hide file tree
Showing 14 changed files with 6 additions and 14 deletions.
2 changes: 1 addition & 1 deletion .github/workflows/kra-external-certs-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -160,7 +160,7 @@ jobs:
- name: Issue KRA admin cert
run: |
docker exec ca openssl req -text -noout -in ${SHARED}/kra_admin.csr
docker exec ca pki ca-cert-request-submit --profile caUserCert --csr-file ${SHARED}/kra_admin.csr --subject uid=kraadmin | tee output
docker exec ca pki ca-cert-request-submit --profile AdminCert --csr-file ${SHARED}/kra_admin.csr | tee output
REQUEST_ID=$(sed -n 's/Request ID: *\(.*\)/\1/p' output)
docker exec ca pki -n caadmin ca-cert-request-approve $REQUEST_ID --force | tee output
CERT_ID=$(sed -n 's/Certificate ID: *\(.*\)/\1/p' output)
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/ocsp-crl-direct-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -151,7 +151,7 @@ jobs:
- name: Issue OCSP admin cert
run: |
docker exec ca openssl req -text -noout -in ${SHARED}/ocsp_admin.csr
docker exec ca pki ca-cert-request-submit --profile caUserCert --csr-file ${SHARED}/ocsp_admin.csr --subject uid=ocspadmin | tee output
docker exec ca pki ca-cert-request-submit --profile AdminCert --csr-file ${SHARED}/ocsp_admin.csr | tee output
REQUEST_ID=$(sed -n 's/Request ID: *\(.*\)/\1/p' output)
docker exec ca pki -n caadmin ca-cert-request-approve $REQUEST_ID --force | tee output
CERT_ID=$(sed -n 's/Certificate ID: *\(.*\)/\1/p' output)
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/ocsp-crl-ldap-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -152,7 +152,7 @@ jobs:
- name: Issue OCSP admin cert
run: |
docker exec ca openssl req -text -noout -in ${SHARED}/ocsp_admin.csr
docker exec ca pki ca-cert-request-submit --profile caUserCert --csr-file ${SHARED}/ocsp_admin.csr --subject uid=ocspadmin | tee output
docker exec ca pki ca-cert-request-submit --profile AdminCert --csr-file ${SHARED}/ocsp_admin.csr | tee output
REQUEST_ID=$(sed -n 's/Request ID: *\(.*\)/\1/p' output)
docker exec ca pki -n caadmin ca-cert-request-approve $REQUEST_ID --force | tee output
CERT_ID=$(sed -n 's/Certificate ID: *\(.*\)/\1/p' output)
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/ocsp-external-certs-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -147,7 +147,7 @@ jobs:
- name: Issue OCSP admin cert
run: |
docker exec ca openssl req -text -noout -in ${SHARED}/ocsp_admin.csr
docker exec ca pki ca-cert-request-submit --profile caUserCert --csr-file ${SHARED}/ocsp_admin.csr --subject uid=ocspadmin | tee output
docker exec ca pki ca-cert-request-submit --profile AdminCert --csr-file ${SHARED}/ocsp_admin.csr | tee output
REQUEST_ID=$(sed -n 's/Request ID: *\(.*\)/\1/p' output)
docker exec ca pki -n caadmin ca-cert-request-approve $REQUEST_ID --force | tee output
CERT_ID=$(sed -n 's/Certificate ID: *\(.*\)/\1/p' output)
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/tks-external-certs-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -139,7 +139,7 @@ jobs:
- name: Issue TKS admin cert
run: |
docker exec ca openssl req -text -noout -in ${SHARED}/tks_admin.csr
docker exec ca pki ca-cert-request-submit --profile caUserCert --csr-file ${SHARED}/tks_admin.csr --subject uid=tksadmin | tee output
docker exec ca pki ca-cert-request-submit --profile AdminCert --csr-file ${SHARED}/tks_admin.csr | tee output
REQUEST_ID=$(sed -n 's/Request ID: *\(.*\)/\1/p' output)
docker exec ca pki -n caadmin ca-cert-request-approve $REQUEST_ID --force | tee output
CERT_ID=$(sed -n 's/Certificate ID: *\(.*\)/\1/p' output)
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/tps-external-certs-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -210,7 +210,7 @@ jobs:
- name: Issue TPS admin cert
run: |
docker exec ca openssl req -text -noout -in ${SHARED}/tps_admin.csr
docker exec ca pki ca-cert-request-submit --profile caUserCert --csr-file ${SHARED}/tps_admin.csr --subject uid=tpsadmin | sed -n 's/Request ID: *\(.*\)/\1/p' > tps_admin.reqid
docker exec ca pki ca-cert-request-submit --profile AdminCert --csr-file ${SHARED}/tps_admin.csr | sed -n 's/Request ID: *\(.*\)/\1/p' > tps_admin.reqid
docker exec ca pki -n caadmin ca-cert-request-approve `cat tps_admin.reqid` --force | sed -n 's/Certificate ID: *\(.*\)/\1/p' > tps_admin.certid
docker exec ca pki ca-cert-export `cat tps_admin.certid` --output-file ${SHARED}/tps_admin.crt
docker exec ca openssl x509 -text -noout -in ${SHARED}/tps_admin.crt
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,6 @@ [email protected]
pki_admin_name=kraadmin
pki_admin_nickname=kraadmin
pki_admin_password=Secret.123
pki_admin_subject_dn=uid=kraadmin
pki_admin_uid=kraadmin

pki_client_database_password=Secret.123
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,6 @@ [email protected]
pki_admin_name=kraadmin
pki_admin_nickname=kraadmin
pki_admin_password=Secret.123
pki_admin_subject_dn=uid=kraadmin
pki_admin_uid=kraadmin

pki_client_database_password=Secret.123
Expand Down
1 change: 0 additions & 1 deletion base/server/examples/installation/kra-standalone-step1.cfg
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,6 @@ [email protected]
pki_admin_name=kraadmin
pki_admin_nickname=kraadmin
pki_admin_password=Secret.123
pki_admin_subject_dn=uid=kraadmin
pki_admin_uid=kraadmin

pki_client_database_password=Secret.123
Expand Down
1 change: 0 additions & 1 deletion base/server/examples/installation/kra-standalone-step2.cfg
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,6 @@ [email protected]
pki_admin_name=kraadmin
pki_admin_nickname=kraadmin
pki_admin_password=Secret.123
pki_admin_subject_dn=uid=kraadmin
pki_admin_uid=kraadmin

pki_client_database_password=Secret.123
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,6 @@ [email protected]
pki_admin_name=ocspadmin
pki_admin_nickname=ocspadmin
pki_admin_password=Secret.123
pki_admin_subject_dn=uid=ocspadmin
pki_admin_uid=ocspadmin

pki_client_database_password=Secret.123
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,6 @@ [email protected]
pki_admin_name=ocspadmin
pki_admin_nickname=ocspadmin
pki_admin_password=Secret.123
pki_admin_subject_dn=uid=ocspadmin
pki_admin_uid=ocspadmin

pki_client_database_password=Secret.123
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,6 @@ [email protected]
pki_admin_name=ocspadmin
pki_admin_nickname=ocspadmin
pki_admin_password=Secret.123
pki_admin_subject_dn=uid=ocspadmin
pki_admin_uid=ocspadmin

pki_client_database_password=Secret.123
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,6 @@ [email protected]
pki_admin_name=ocspadmin
pki_admin_nickname=ocspadmin
pki_admin_password=Secret.123
pki_admin_subject_dn=uid=ocspadmin
pki_admin_uid=ocspadmin

pki_client_database_password=Secret.123
Expand Down

0 comments on commit 2b84210

Please sign in to comment.