On 08/10/2015 08:54 PM, Scott Poore wrote:

----- Original Message -----
From: "Milan Kubík" <mku...@redhat.com>
To: "freeipa-devel" <freeipa-devel@redhat.com>, "Scott Poore" <spo...@redhat.com>, 
"Fraser Tweedale"
<ftwee...@redhat.com>
Cc: "Namita Soman" <nso...@redhat.com>, "Ales Marecek" <amare...@redhat.com>
Sent: Monday, August 10, 2015 4:36:31 AM
Subject: Re: cert profiles - test plan + patches

On 08/05/2015 02:57 PM, Milan Kubík wrote:
Hi list,

I'm sending the test plan [1] for certificate profiles and preliminary
patches for it.
The plan covers basic CRUD test and some corner cases. I'm open to more
suggestions.

More complicated tests involving certificate profiles will require the
code (and tests)
for CA ACLs merged, so it's not there at the moment.

There are some unfinished test cases in places I wasn't sure what the
result should be.
We need to iterate through these to fix it.


[1]: http://www.freeipa.org/page/V4/Certificate_Profiles/Test_Plan

Cheers,
Milan
Hi all,

have you had some time to look at the code and proposal?
Today I want to write a basic CRUD test for the ACLs as well as a few
test cases to check if the ACL is being enforced. It should make it into
wiki today or by tomorrow. I'll send an update then.
I haven't looked at the actual code yet.  Is it checked into git for freeipa 
yet?

This looks good to me for the basic CRUD tests.   I do have some questions and 
requests.

Existing tests:

* Delete default profile
- Did you find out what the expected result should be?

* Try to rename the profile entry
- Can this be renamed to be more specific to trying to rename ldap attr?
- Can we get a new test case to test renaming with certprofile-mod --rename?

Possible new tests:

* Import a profile in xml
- This should fail and I think is at least in the beginning a common mistake.

* Change profile config from file
- This one may be too large in scope but, could be limited to changing 
something simple to make sure the file is read and used.

Where are you planning to put the CA ACL tests?  In the same page?

When you have that will you be adding a cert-request test?
Some additional test cases
(1) Non-existent profile with certprofile-show
(2) certprofile-import with --store both true/false options
(3) certprofile-find with store option

Thanks,
Scott
Cheers,
Milan



--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Reply via email to