[Freeipa-users] using pathlen:0 for freeipa's CA certificate?

Harald Dunkel harald.dunkel at aixigo.de
Mon May 4 11:19:01 UTC 2015


Hi folks,

Instead of a self-signed certificate I would like to use an external
CA to sign freeipa's CSR ("ipa-server-install --external-ca").
Question:

Is pathlen:0, e.g.

	basicConstraints=critical,CA:TRUE, pathlen:0

sufficient for freeipa's CA certificate?


Regards
Harri




More information about the Freeipa-users mailing list