Olivier G via FreeIPA-users wrote:
> Hi all,
> 
> I have try to sign a certificate with my subCA but I failed each time (with 
> the 'ipa-getcert request' command). Digging the issue, I have been surprised 
> to discover that certmonger does not 'see' a subCA created with 'ipa ca-add' 
> command. The SubCA does not appears in the 'getcert list-cas' command list 
> but it appears in the 'ipa ca-find' command list. Am I doing a mistake ? 
> Is there any way to create subCAs that are visible to certmonger ? What 
> should I do ? Is it possible to configure the certmonger renewal time ( it 
> seems to fixed) ?
> Otherwise what is the recommended workaround ? Is it to develop a (not so 
> simple I guess) in-house certmonger like ?

You misunderstand what a CA is to certmonger. That defines how
certmonger communicates. It doesn't represent individual Certificate
Authorities.

What you're looking for is -issuer=ISSUER.

I'm not sure what you mean by renewal time. Do you mean the validity
period of the certificate or how far in advance to start trying to
renewing it? If the latter that is controlled in certmonger.conf(5)
using the enroll_ttls directive.

The validity period is controlled by the CA profile that issues the
certificate.

rob

-- 
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to