Continuing the discussion for #5836 as requested from triage
IMO it is not important for FreeIPA 4.4. It is nice to have but I
doubt it will make it.
Honza suggested it should be the other way around, i.e. CA specifies
default profile rather than profile specifies default CA.
The fact (also raised by Christian) is that multiple profiles may be
used with a single CA, and vice-versa. CA ACLs will govern what
combinations are acceptable.
Thinking from user perspective, there are a couple of things to
- Currently, to request a particular kind of cert, user must specify
a profile ID.
- It is more natural to ask for a particular profile and have the
request dispatched to a profile-specified default CA, than to ask
for a cert issued by a particular CA, and a CA-specified default
profile will be used.
Given these points, I am strongly in favour of having the profile
indicate the default CA - not the other way around.
Manage your subscription for the Freeipa-devel mailing list:
Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code