TPS UI: Changes to profile are applied even before Admin submits the changes and agent approves it
Steps to Reproduce:
1. Login to TPS Web UI as Agent user and disable userKey profile 2. Login to TPS Web UI as Admin user and change the userkey signing and encryption keysize from 1024 to 2048 3. Save the changes but do not click submit 4. Login as agent user and check the userKey's keySize params 5. Check the userKey keySize params in CS.cfg
Actual results:
TPS UI shows the change in keySize in step 4 CS.cfg has the keySize changed.
Expected results:
changes to profile should not be applied unless submittd by Admin and approved by agent
Additional info:
debug log messages when TPS changes the parameter values are attached to the associated Bugzilla Bug.
I think the current behavior is consistent with the old TPS. Basically the profile must stay disabled while it's being revised.
We could improve TPS to store pending profile changes somewhere else until it's approved. This will allow the old profile to continue to be used until the new one is approved.
See also the discussion in Bugzilla.
Agreed. This is also consistent with the CA.
+1 for milestone (Future)
As for priority, because this is soemwhat of a useful feature, I'd consider making this Critical to make sure we get around to considering it.
Replying to [comment:3 vakwetu]:
Agreed. This is also consistent with the CA. +1 for milestone (Future) As for priority, because this is soemwhat of a useful feature, I'd consider making this Critical to make sure we get around to considering it.
Per offline triage: Future - critical; clearing proposed priority/milestone
After further discussion with rpattath and alee, it looks like 10.4 is a preferable milestone.
See also http://pki.fedoraproject.org/wiki/TPS_Profile_Lifecycle.
See also #1003.
Metadata Update from @rpattath: - Issue set to the milestone: 10.4
Per PKI Bug Council of 04/06/2017: FUTURE
Metadata Update from @mharmsen: - Custom field feature adjusted to '' - Custom field proposedmilestone adjusted to '' - Custom field proposedpriority adjusted to '' - Custom field reviewer adjusted to '' - Custom field version adjusted to '' - Issue close_status updated to: None - Issue set to the milestone: FUTURE (was: 10.4)
Dogtag PKI is moving from Pagure issues to GitHub issues. This means that existing or new issues will be reported and tracked through Dogtag PKI's GitHub Issue tracker.
This issue has been cloned to GitHub and is available here: https://github.com/dogtagpki/pki/issues/2666
If you want to receive further updates on the issue, please navigate to the GitHub issue and click on Subscribe button.
Subscribe
Thank you for understanding, and we apologize for any inconvenience.
Metadata Update from @dmoluguw: - Issue close_status updated to: migrated - Issue status updated to: Closed (was: Open)