Fixes #39446 - Reject non-PEM content in foreman-certificate-check - #676
Satellite-RedHat wants to merge 1 commit into
Conversation
Add the same PEM-only validation used by katello-certs-check so custom certificates and CA bundles fail early during deploy. Co-authored-by: Cursor <cursoragent@cursor.com>
|
@Satellite-RedHat have you investigated a method using |
|
Thanks for the question. Yes — this script already relies on I looked at whether This is the same approach used in foreman-installer #1062, which I ported here to keep both installation paths aligned. |
Summary:
check-pem-contentfrom foreman-installer #1062 intoforeman-certificate-checkBEGIN/END CERTIFICATEblocks (for example PKCS#12 Bag Attributes or comment lines)Reference discussion:
theforeman/foreman-installer#1062 (comment)
Why
foreman-certificate-checkcould previously accept cert/CA files with non-PEM text between blocks. Those files can pass OpenSSL checks but fail later in production. Installer #1062 adds the same guard tokatello-certs-check; this change keeps the containerized install path aligned.Related:
Test cases added