Hi all, There was recently discussion about how to issue sub-CA certificates to external entities in FreeIPA (i.e. not lightweight CAs which are internal to an IPA deployment). So I blogged a comprehensive HOWTO, with a discussion of the caveats/limitations.
https://frasertweedale.github.io/blog-redhat/posts/2018-08-21-ipa-subordinate-ca.html As always, feedback/errata/follow-up questions are welcome. Cheers, Fraser _______________________________________________ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/freeipa-users@lists.fedorahosted.org/message/QGLAH6SCSZGXH5WDXQHDGRDGSAYK3LIT/