#3032 auto renew cert: caJarSigningCert(Signing-Cert) does not auto renewed
Closed: invalid 6 years ago Opened 11 years ago by yizhangid.

This cert:
CA jar signing (4 years)
subject name CN=Object Signing Cert,O=$REALM
enrolled using caJarSigningCert profile
private key in /etc/httpd/alias as "Signing-Cert"
issued by IPA RA agent
used to sign browser auto-configuration jar
(http://freeipa.org/page/Certificate_renewal)

does not get renewed.


It was outside the scope as it isn't a CA subsystem certificate.

We may still want to renew it.

It is normally only used at install time to sign the browser configuration jar file.

With the change to stop using a jar for FF configuration is this even relevant? Should we then close as wontfix? Moving to needs triage.

We are signing the extension too. We don't have to though. It can be installed unsigned too.

But we are still using configure.jar to support Firefox version prior to 15.

Metadata Update from @yizhangid:
- Issue assigned to someone
- Issue set to the milestone: Tickets Deferred

7 years ago

We removed this certificate some time ago. Closing as invalid.

Metadata Update from @ftweedal:
- Issue close_status updated to: invalid

6 years ago

Login to comment on this ticket.

Metadata