XMLWordPrintableJSON

Details

    • Sub-task
    • Status: Open
    • Major
    • Resolution: Unresolved
    • None
    • None
    • Security

    Description

      We have an ozone admin cert command, which has a list and info subcommand.
      We need to add a new subcommand here to revoke a certificate based on certificateSerialID, and to revoke all certificates related to a host, ideally we also should handle a list of certificateSerialIDs or hosts.

      As revoking a certificate can happen in a future, we should also add an option to revoke a certificate at a give time.
      Further consideration will needed for immediate certificate revocation, as we need to give some time for a service to notice if it is certificate is revoked, so that it can renew it in time... This time window we give for an immediate revocation should consider the timeframe since a CRL may be cached in clients, and harmonize with that timeframe.

      Attachments

        Activity

          People

            pifta István Fajth
            pifta István Fajth
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated: