diff options
| author | Christian Breunig <christian@breunig.cc> | 2026-08-10 18:24:39 +0000 |
|---|---|---|
| committer | Christian Breunig <christian@breunig.cc> | 2026-08-10 21:04:10 +0200 |
| commit | 0cfdd6a869772defbd6ca7778273bdab4b85dfe7 (patch) | |
| tree | e90bcf11da6a8eb800ba167a48abc24ce81a3c58 /src/migration-scripts/https | |
| parent | 9f34c853adcc94cb8c03e25457f739096c175276 (diff) | |
| download | vyos-1x-0cfdd6a869772defbd6ca7778273bdab4b85dfe7.tar.gz vyos-1x-0cfdd6a869772defbd6ca7778273bdab4b85dfe7.zip | |
pki: T9135: don't crash on an ACME certificate not yet issued
Both the with_pki=True chain injection and "show pki ca" unconditionally read
a certificate's own content to check whether an explicit CA already covers its
chain. For an ACME certificate with no cert.pem yet (pending its first issuance,
or after a failed request), that content is never populated and the lookup
raised KeyError - crashing every with_pki=True consumer and "show pki" alike.
Diffstat (limited to 'src/migration-scripts/https')
0 files changed, 0 insertions, 0 deletions
