[Freeipa-users] can(should) IPA issue/manage certificates...

Fraser Tweedale ftweedal at redhat.com
Fri Nov 25 03:18:40 UTC 2016


On Thu, Nov 24, 2016 at 04:19:03PM +0000, lejeczek wrote:
> .. for entities outside of it's own domain?
> Would you use IPA this way?
> 
> I'm thinking - it would be nice that have one central point(console) and
> manage all my "virtual" domains certification, but, I'm not an expert on the
> subject.
> And if yes then what would be the steps?
> 
Can IPA manage certs for "external" entities?  No.

Should it be able to?  Maybe.  There have been some preliminary
discussions about use cases and how it could be implemented.

Do you want to elaborate on your use case?

(Bear in mind that, unless your IPA CA is chained to a publicly
trusted CA, certs issued by it will not be publicly trusted.)

Cheers,
Fraser

> mthx,
> L.
> 
> -- 
> Manage your subscription for the Freeipa-users mailing list:
> https://www.redhat.com/mailman/listinfo/freeipa-users
> Go to http://freeipa.org for more info on the project




More information about the Freeipa-users mailing list