Description
We should cover the new PKI system with integration tests properly.
The following scenarios we should surely include, but additional ones might be defined later as we go:
- regular security bootstrap
- certificate rotation before expiration
- rootCA certificate rotation before expiration
- rootCA certificate revocation
- subordinate CA certificate revocation
- revocation of all subordinate CA certs that are signed by the rootCA
- revocation of a single certificate
Attachments
Issue Links
- blocks
-
HDDS-7331 Ozone PKI improvements
- Open