diff options
| author | Fraser Tweedale <ftweedal@redhat.com> | 2016-07-26 14:07:10 +1000 |
|---|---|---|
| committer | Fraser Tweedale <ftweedal@redhat.com> | 2016-08-08 10:01:04 +1000 |
| commit | 018b5c1f3295fadd263d256d00866dd7b9d31163 (patch) | |
| tree | 4cb1aa6d7918e57bfe7248ba70c734181c43c053 /base/server/python | |
| parent | 1d0abd0630d5847c288c65a7adeff580c9c9776b (diff) | |
| download | pki-018b5c1f3295fadd263d256d00866dd7b9d31163.tar.gz pki-018b5c1f3295fadd263d256d00866dd7b9d31163.tar.xz pki-018b5c1f3295fadd263d256d00866dd7b9d31163.zip | |
Fix CA OCSP responder when LWCAs are not in use
The CA subsystem OCSP responder was updated to handle dispatching
OCSP requests to the relevant CertificateAuthority instance,
according to the issuer of the certificates identified in the
request. Unfortunately, the updated routine assumes that the
database updates that enable lightweight CAs have occurred. If they
have not, the OCSP responder always fails.
Fix the issue by inferring that if 'caMap' is empty, lightweight CAs
are not in use, the current instance is the one and only CA, and
proceed straight to validation.
Fixes: https://fedorahosted.org/pki/ticket/2420
Diffstat (limited to 'base/server/python')
0 files changed, 0 insertions, 0 deletions
