[Pki-users] exporting sub CA to pem format

Marc Sauton msauton at redhat.com
Fri Feb 8 18:53:08 UTC 2019


I always use the pkispawn command to create instances, not "pki
ca-authority-create", so I have a doubt.
But try to check for a related PKCS #12 file with extension .p12 in ~/ , or
use certutil in /etc/pki/*/alias/ , the default
being /etc/pki/pki-tomcat/alias/
If there is a p12 file, the key material is wrapped, if not, use pk12util
to create a p12 file from the NSS db directory.
If this using an HSM, do not export, or only use the vendor's tools.
Thanks,
M.

On Fri, Feb 8, 2019 at 5:13 AM joris dedieu <joris.dedieu at gmail.com> wrote:

> Hello Pki users,
> I found how to issue a sub certificate with pki ca-authority-create
> and export certificate with  ca-authority-show, but I don't understand
> how to export Sub CA key. I need it to sign some certificates with
> puppet or openssl. Is there a way to do so ?
>
> Best Regards
> Joris
>
> _______________________________________________
> Pki-users mailing list
> Pki-users at redhat.com
> https://www.redhat.com/mailman/listinfo/pki-users
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/pki-users/attachments/20190208/f262bb81/attachment.htm>


More information about the Pki-users mailing list