freeipa/ipaserver/install/plugins
Florence Blanc-Renaud 800f2690f5 ipa upgrade: handle double-encoded certificates
Issue is linked to the ticket
 #3477 LDAP upload CA cert sometimes double-encodes the value
In old FreeIPA releases (< 3.2), the upgrade plugin was encoding twice
the value of the certificate in cn=cacert,cn=ipa,cn=etc,$BASEDN.

The fix for 3477 is only partial as it prevents double-encoding when a
new cert is uploaded but does not fix wrong values already present in LDAP.

With this commit, the code first tries to read a der cert. If it fails,
it logs a debug message and re-writes the value caCertificate;binary
to repair the entry.

Fixes https://pagure.io/freeipa/issue/7775
Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
Reviewed-By: Christian Heimes <cheimes@redhat.com>
2018-11-30 11:05:17 +01:00
..
__init__.py Server Upgrade: specify order of plugins in update files 2015-04-14 19:25:47 +02:00
adtrust.py Support Samba 4.9 2018-09-26 11:40:19 +02:00
ca_renewal_master.py Move config directives handling code 2018-05-29 17:03:56 +02:00
dns.py Sprinkle raw strings across the code base 2018-09-27 10:23:03 +02:00
fix_replica_agreements.py logging: remove object-specific loggers 2017-07-14 15:55:59 +02:00
rename_managed.py Py3: Remove subclassing from object 2018-09-27 11:49:04 +02:00
update_ca_topology.py Add absolute_import future imports 2018-04-20 09:43:37 +02:00
update_dna_shared_config.py logging: remove object-specific loggers 2017-07-14 15:55:59 +02:00
update_fix_duplicate_cacrt_in_ldap.py Fix ipa-server-upgrade: This entry already exists 2017-08-30 12:47:53 +02:00
update_idranges.py logging: do not log into the root logger 2017-07-14 15:55:59 +02:00
update_ldap_server_list.py Move ds.replica_populate to an update plugin 2016-11-11 12:13:56 +01:00
update_managed_permissions.py logging: remove object-specific loggers 2017-07-14 15:55:59 +02:00
update_nis.py Add absolute_import future imports 2018-04-20 09:43:37 +02:00
update_pacs.py logging: remove object-specific loggers 2017-07-14 15:55:59 +02:00
update_passsync.py logging: do not log into the root logger 2017-07-14 15:55:59 +02:00
update_ra_cert_store.py Add absolute_import future imports 2018-04-20 09:43:37 +02:00
update_referint.py logging: do not log into the root logger 2017-07-14 15:55:59 +02:00
update_services.py logging: do not log into the root logger 2017-07-14 15:55:59 +02:00
update_uniqueness.py logging: do not log into the root logger 2017-07-14 15:55:59 +02:00
upload_cacrt.py ipa upgrade: handle double-encoded certificates 2018-11-30 11:05:17 +01:00