Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Check to see if ACME is enabled and warn if the Apache cert lacks a SAN for ipa-ca #152

Open
rcritten opened this issue Sep 16, 2020 · 0 comments
Labels
enhancement New feature or request

Comments

@rcritten
Copy link
Collaborator

ACME uses the ipa-ca.$DOMAIN name so there can be a fixed name in an installation for the service.

If a user is providing their own certificate for Apache then it will need to include this SAN in order for ACME to work.

Add a check to see if ACME is enabled and if so ERROR if it lacks an ipa-ca SAN. An ERROR and not a WARN since the request will definitely fail at some point as all CA servers have an ipa-ca CNAME.

@rcritten rcritten added the enhancement New feature or request label Sep 16, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant