Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
The RHEL package subscription-manager-rhsm-certificates provides
most of the trust chain for RHSM host certs in the PEM bundle
/etc/rhsm/ca/redhat-uep.pem. The file contains the root CA
(Entitlement Master CA) and first intermediate CA (Red Hat
Entitlement Operations Authority). It's missing the intermediate
Candlepin CA that sits between the operations cert and RHSM
end-entity cert for each host.
Designs for upcoming features for Red Hat Hybrid Cloud Console have
launched VMs use the RHSM certificate for TLS client certificate
authentication and Kerberos PKINIT. As an operational
consideration, we need the entire trust chain. In particular,
PKINIT requires the full chain on both the KDC and client.
To address this issue, add the latest version of the Red Hat
Candlepin Authority certificate to the redhat-uep.pem bundle.
See also: https://issues.redhat.com/browse/HMS-1316