IdP v4.1 unattendended plugin install error: INFO - Key import barred by user
Lipscomb, Gary
glipscomb at csu.edu.au
Thu Apr 29 22:26:14 UTC 2021
Hi Scott,
We do download all IdP software to an internal staging server and provision all our servers from this "satellite". The only thing we don't do is re-sign. The initial public key for the plugins is stored within our puppet configuration system and any deviation from the "production" configuration is reported.
Regards
Gary
-----Original Message-----
From: users <users-bounces at shibboleth.net> On Behalf Of Cantor, Scott
Sent: Thursday, 29 April 2021 10:25 PM
To: Shib Users <users at shibboleth.net>
Subject: Re: IdP v4.1 unattendended plugin install error: INFO - Key import barred by user
On 4/28/21, 8:08 PM, "users on behalf of Lipscomb, Gary via users" <users-bounces at shibboleth.net on behalf of users at shibboleth.net> wrote:
> Have tested and if the trust store is populated with the public key
> prior to install the --noPrompt works and the plugin and module are installed.
That's intentional then, that was the intended design. Providing a --noPrompt tha doesn't require that is, well, catastrophically dangerous since you have no idea what you're downloading.
In effect if you want to do that you should run your own "satellite" server to use the RH RPM term. Download your plugins and re-sign them, and prepopulate your own key so you control all the variables. The installer does *not* require that it find its plugins at the published download locations, that's just for easing upgrades.
-- Scott
--
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list