mirror of
https://salsa.debian.org/freeipa-team/freeipa.git
synced 2026-07-29 23:58:23 -05:00
ipatests: test ipa_server_certinstall with an IPA-issued cert
ipa-server-certinstall takes a slightly different code path if the replacement certificate is IPA-issued so exercise that path. This replaces the Apache cert with itself which is a bit of a no-op but it still goes through the motions. https://pagure.io/freeipa/issue/8204 Signed-off-by: Rob Crittenden <rcritten@redhat.com> Reviewed-By: Fraser Tweedale <ftweedal@redhat.com>
This commit is contained in:
committed by
Florence Blanc-Renaud
parent
dbc7881e36
commit
040d48fa61
@@ -358,6 +358,30 @@ class TestInstallCA(IntegrationTest):
|
||||
assert owner == "root"
|
||||
assert group == "root"
|
||||
|
||||
def test_cert_install_with_IPA_issued_cert(self):
|
||||
"""
|
||||
Test replacing an IPA-issued server cert
|
||||
|
||||
ipa-server-certinstall can replace the web and LDAP certs.
|
||||
A slightly different code path is taken when the replacement
|
||||
certs are issued by IPA. Exercise that path by replacing the
|
||||
web cert with itself.
|
||||
"""
|
||||
self.master.run_command(['cp', '-p', paths.HTTPD_CERT_FILE, '/tmp'])
|
||||
self.master.run_command(['cp', '-p', paths.HTTPD_KEY_FILE, '/tmp'])
|
||||
|
||||
passwd = self.master.get_file_contents(
|
||||
paths.HTTPD_PASSWD_FILE_FMT.format(host=self.master.hostname)
|
||||
)
|
||||
self.master.run_command([
|
||||
'ipa-server-certinstall',
|
||||
'-p', self.master.config.dirman_password,
|
||||
'-w',
|
||||
'--pin', passwd,
|
||||
'/tmp/httpd.crt',
|
||||
'/tmp/httpd.key',
|
||||
])
|
||||
|
||||
def test_is_ipa_configured(self):
|
||||
"""Verify that the old and new methods of is_ipa_installed works
|
||||
|
||||
|
||||
Reference in New Issue
Block a user