On Срд, 06 мая 2026, Olivier G via FreeIPA-users wrote:
Hi all,

I have try to sign a certificate with my subCA but I failed each time
(with the 'ipa-getcert request' command). Digging the issue, I have
been surprised to discover that certmonger does not 'see' a subCA
created with 'ipa ca-add' command. The SubCA does not appears in the
'getcert list-cas' command list but it appears in the 'ipa ca-find'
command list. Am I doing a mistake ?  Is there any way to create subCAs
that are visible to certmonger ? What should I do ? Is it possible to
configure the certmonger renewal time ( it seems to fixed) ?  Otherwise
what is the recommended workaround ? Is it to develop a (not so simple
I guess) in-house certmonger like ?

You can add new CA configurations with 'getcert-add-ca', see man page.
Basically, you need to copy the one that already exists for IPA CA
(getcert list-cas) and add '-X name' to ipa-submit, see man page for
ipa-submit.

Certmonger has pretty decent documentation included in the package, see
/usr/share/doc/certmonger/helpers.txt for details.


--
/ Alexander Bokovoy
Sr. Principal Software Engineer
Security / Identity Management Engineering
Red Hat Limited, Finland

--
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to