Here's a random list of issues that I have had with the client or would like to see, some of which you've probably already fixed:
* About half of my certificate requests fail and must be retried due to "lost connection to MySQL" (running on the same machine as the server)
Hum... That's weird. I suspect the problem comes from the mysql server.
With the beta4, I generated 300.000 profile with 2 certificates per profile, for a total of 600.000 certificates, I didn't have this kind of problem.
* Would _really_ like to see an EE module one of these days, or some way of securely transporting certificates without having to snail-mail CD's to people
This is the last beta, next version will have the EE and the KeyStore.
* Would like to see additional certificate export formats, such as the
CER/PVK format that so many Windows tools expect and the PEM format that my
OpenVPN program requires.
CER is the PEM encoded certificate, this is handled in NewPKI. As for PVK I'll look into this. I added the possibility to export the certificates to PKCS#7.
Also with the option of not specifying a password (PEM only) and the option of not exporting the complete certificate chain.
I don't understand what you mean.
* Will I be able to modify/delete "profiles"? I recognize that this is a complicated subject (if the profile owns any certificates, they must be revoked and advertised as such), but if anything it would be nice to just prune the failed certificate requests.
The possibility to modify/delete profiles is included in beta4. You can modify the profile's DN as you want, however you won't be able to delete any profile until all its certificates are revoked.
The failed certificate requests are not removable, I'll add this option in next release.
* Is there any way to be informed if a certificate is about to expire, or do I wait for the users to be denied access and then snail-mail another CD to them?
That's a good idea, I'll add this option in next release.
* The last server upgrade required me to wipe my certificate store, as the database format had changed and the new version refused to read the older database. It wasn't a big deal then (the PKI was just coming into production and the older data was obsolete), but I would like a version-independant dump of the entire contents of the PKI (something like what Subversion uses?) that is not tied to the MySQL database schema and therefore cannot be rejected by any future version of the program.
I'm afraid that you will have the same problem with beta4.
However, this is the last not-upgradable version, the next release will allow to upgrade from beta4.
* I would like this version-independant dump to allow me to individually load/unload modules from the PKI, adding/removing them from the underlying database. This would allow me to unload the root CA from the database (If I so choose to do it) and either load it onto a more secure machine or choose to keep it offline until its needed again.
You can do this by dumping the database, let's say your ROOT CA is named "root_ca":
- stop the newpki server
- mysql -e "delete from entities_list where entity_name='root_ca';" newpki_server
- mysqldump -c --databases root_ca > root_ca.sql
- mysql -e "drop database root_ca;"
To restore root_ca:
- stop the newpki server
- mysql -e "insert into entities_list (entity_name, entity_type) values ('root_ca', 1);" newpki_server
- cat root_ca.sql | mysql
So, is that enough change requests for the next version ;-)
Here's hoping to improve what I see is the best PKI administration product out there...
Thanks.
-- Fr�d�ric Giudicelli http://www.newpki.org _____________________________________________________________________ NewPKI http://www.newpki.org User Support Mailing List [EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED]
