#8524 Deploy & manage the ACME service topology wide from a single system
Closed: fixed by rcritten. Opened by rcritten.

As administrator, I want to be able to deploy and manage the ACME service topology wide from a single system, so the way how management is done is the consistent with the rest of IPA environment.

ACME is not enabled by default so the ipa-acme-manage command will remain but it only needs to be executed once to turn on/off ACME on all CA masters.

This relies on changes in dogtag in https://github.com/dogtagpki/pki/pull/562


Metadata Update from @rcritten:
- Custom field rhbz adjusted to https://bugzilla.redhat.com/show_bug.cgi?id=1851835

master:

  • 2ef53196c6a012ad7d02aed5672d69fbcb5d0a4e Enable importing LDIF files not shipped by IPA
  • e13d058a066bdbd8a81b794b6f18ca8eca1f31c8 Let dogtag.py be imported if the api is not initialized
  • c0d55ce6de5e41a98b1e37e23e8bdb339e772c0f Centralize enable/disable of the ACME service
  • 92c3ea4e293a4fca58269265b7fbf511024dab59 Don't install ACME if full support is not available
  • 69ae48c8b614a23f530ec6ed33c9019e0b491e50 Add a status option to ipa-acme-manage
  • e7fd791579eca8b7a1c30b4f17bfac7c4fafe2a7 ipatests: Check if ACME is enabled on all CA servers
  • d4ef64b229541200564131e927cd0b4b32662fe2 ipatests: Collect the let's encrypt log

Metadata Update from @rcritten:
- Issue close_status updated to: fixed
- Issue status updated to: Closed (was: Open)

master:

  • b691850cc9718818893291bb813cc227a8daa3d9 Change KRA profiles in certmonger tracking so they can renew
  • 0037b698eda11185cb5f22ff74f4b008bc24fe40 Test that the KRA profiles can renewal its three certificates
  • 6816de0892a11c203f1a2e6f7819d533c7658fa9 Require PKI 10.10+ for KRA profile and ACME support

ipa-4-8:

  • 69adf813acb6c37fd5b64f5713f41dce7ddf0207 Change KRA profiles in certmonger tracking so they can renew
  • c3c577aead10e592bf01bc04b6a31d0cf4d4a2be Test that the KRA profiles can renewal its three certificates
  • c1659014d0b9e038896ba860a0d76bb70dad7bac Require PKI 10.10+ for KRA profile and ACME support

ipa-4-9:

  • a9e1c014f601a567f4aa5135d02883c498835268 Change KRA profiles in certmonger tracking so they can renew
  • bd4771d75f8549fe1790540764f23d47bf3d187c Test that the KRA profiles can renewal its three certificates
  • 3e530e93c37ee71a560714e26285cd85e71557c9 Require PKI 10.10+ for KRA profile and ACME support
Metadata