You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
FreeIPA uses FileBaseCRLPublisher to publish CRLs to /var/lib/ipa/pki-ca/publish/. Dogtag dumps a new CRL every four hours but never cleans up the directory. For example one of my test VMs has more than 1,200 files in /var/lib/ipa/pki-ca/publish/. The oldest CRL is from June 2015.
I suggest that FileBaseCRLPublisher gets a new option to remove CRLs older than X days. 14 days sound like sane default value.
This issue was migrated from Pagure Issue #2274. Originally filed by cheimes (@tiran) on 2016-04-07 15:06:11:
FreeIPA uses FileBaseCRLPublisher to publish CRLs to /var/lib/ipa/pki-ca/publish/. Dogtag dumps a new CRL every four hours but never cleans up the directory. For example one of my test VMs has more than 1,200 files in /var/lib/ipa/pki-ca/publish/. The oldest CRL is from June 2015.
I suggest that FileBaseCRLPublisher gets a new option to remove CRLs older than X days. 14 days sound like sane default value.
FreeIPA ticket: https://fedorahosted.org/freeipa/ticket/3728
The text was updated successfully, but these errors were encountered: