mirror of
https://salsa.debian.org/freeipa-team/freeipa.git
synced 2025-02-25 18:55:28 -06:00
The dogtag REST API has a change of behavior regarding revocation reason 8, REMOVE_FROM_CRL. The XML interface accepts it blindly and marks the certifiate as revoked. This is complicated within RFC 5280 but the jist is that it only affects a certificate on hold and only for delta CRLs. So this modifies the behavior of revocation 8 so that the certificate is put on hold (6) first. Fixes: https://pagure.io/freeipa/issue/9345 Signed-off-by: Rob Crittenden <rcritten@redhat.com> Reviewed-By: Florence Blanc-Renaud <frenaud@redhat.com>