KRA agent owning ECC certificate cannot access KRA's agent interface. Attempt to access KRA's agent interface with ECC certificate is rejected with "Invalid Credentials" error.
pki-ca10141611 has agent2 with ECC cert imported to local firefox agent2 with ECC cert can access CA's agent interface
pki-kra10141611 has agent2 with ECC cert imported to local firefox and has agent3 with RSA cert imported to local firefox agent2 with ECC cert cannot access KRA's agent interface but agent3 with RSA cert can access KRA's agent interface
I cannot reproduce the issue. I have tested in two cases: 1. adding a brand new KRA agent, issuing it an ECC cert and importing it into the user entry via console. The agent can access KRA agent page without any issue. 2. installing a brand new KRA instance and went through the configuration. At the admin panel, chose ECC keys to generate and got issued an ECC cert. Continued and completed the installation, Was also able to access KRA agent page.
I went to Andrew's desk and went on his environment where he ran into and thus reported this issue. With Andrew witnessing, I added an ECC agent and then accessed the ECC agent page without any issue. I concluded that I still cannot reproduce the issue.
Metadata Update from @nkinder: - Issue assigned to cfu - Issue set to the milestone: ECC Effort
Dogtag PKI is moving from Pagure issues to GitHub issues. This means that existing or new issues will be reported and tracked through Dogtag PKI's GitHub Issue tracker.
This issue has been cloned to GitHub and is available here: https://github.com/dogtagpki/pki/issues/814
If you want to receive further updates on the issue, please navigate to the GitHub issue and click on Subscribe button.
Subscribe
Thank you for understanding, and we apologize for any inconvenience.