Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RE_Enroll operation does not revoke the original certificates on the token #2607

Closed
pki-bot opened this issue Oct 3, 2020 · 2 comments
Closed

Comments

@pki-bot
Copy link

pki-bot commented Oct 3, 2020

This issue was migrated from Pagure Issue #2487. Originally filed by rpattath (@rpattath) on 2016-09-28 00:57:47:


RE_Enroll operation does not revoke the original certificates on the token

Steps to Reproduce:

1. Enroll a token of userKey token type.
2. Edit the token policy using the Web UI with RE_ENROLL=YES
3. Enroll the token again
4. Default TPS CS.cfg was used which has op.format.userKey.revokeCert=true

Actual results:

Original certificates are not revoked

Expected results:

Original certificates are expected to be revoked.

Additional info:

attaching the tps debug log

Created attachment 1205287
TPS re-enroll debug log
@pki-bot pki-bot added this to the 10.3.6 milestone Oct 3, 2020
@pki-bot
Copy link
Author

pki-bot commented Oct 3, 2020

Comment from mharmsen (@mharmsen) at 2016-10-11 23:27:13

CLOSING AS WORKSFORME:

Christina Fu 2016-10-07 14:04:38 EDT

I cannot reproduce.  It works for me.
Did you literally enter (delimited by ';')?
FORCE_FORMAT=YES;RE_ENROLL=YES

Roshni 2016-10-07 14:45:20 EDT

With fresh TPS instance the original certs were revoked during re-enrollment
when FORCE_FORMAT=YES;RE_ENROLL=YES was set for the token.

@pki-bot pki-bot closed this as completed Oct 3, 2020
@pki-bot
Copy link
Author

pki-bot commented Oct 3, 2020

Comment from rpattath (@rpattath) at 2017-02-27 14:11:35

Metadata Update from @rpattath:

  • Issue set to the milestone: 10.3.6

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant