OpenCA Project Overview:
========================
The OpenCA Project is a collaborative effort to develop a robust,
full featured and Open Source out-of-the-box Certification Authority
implementing the most used protocols with full-strength cryptography
world-wide. OpenCA is based on many Open Source Projects. Among the
supported software is OpenLDAP, OpenSSL, Apache Project, mod_ssl.
The project development is divided in two main tasks: studying and
refining the security scheme that guarantees the best model to be
used in a CA and developing software to easily setup and manage a
Certification Authority.
Project Status:
===============
OpenCA version 0.9.0 Status: Developing
OpenCA version 0.8.0 Status: Bug Fixing [Soon to be released]
OpenCA version 0.6.0 Status: Never Released
OpenCA version 0.2.0 Status: Released
Core developers' Tasks:
=======================
Massimiliano Pala is currently working on:
o OCSP responder development/integration;
o Smart Cards integration;
o OpenCA 0.8 Release (fixing current glitches);
o RPMs;
Michael Bell is currently working on:
o DBI module updating (DB2/Oracle/Postgress/MySQL support)
o RBAC Module (Role Based Management)
o Revocation Process engeneering through the use of CRIN codes
(Certificate Revocation PIN)
o LDAP support improving
o Export-Import utils
Robert Joop is currently working on:
o merge configure.in and src/modules/openca-sv/configure.in
o drop bogus "AC_PATH_PROG( CD, ...", cd can only be a shell
built-in.
o making the Makefiles more standard (e.g. separate `make` and
`make install` steps, which would become `make ca` and `make
install-ca`, ...)
o making the Makefiles more robust: currently, a lot of errors
go unnoticed because e.g. of the use of for-loops without
error checking.
o adjust things so that only files that need to be written by
the CGIs get the web server's uid/gid.
o changing the hardwired paths
Open Issues:
============
o LDAP v3 specific support
o SCEP support
o Attributes Certificates
o
Wishes:
=======
o
References:
===========
The OpenCA Project main website can be found at http://www.openca.org ( or
at http://openca.sourceforge.net ). You can find all current versions and
available documentation there.
You can also download any part of the software or documentation also at the
official ftp site:
ftp://ftp.openca.org
ftp://openca.sourceforge.net/pub/openca (soon removed)
or from one of the official mirrors:
http://openca.sourceforge.net/doc/download.shtml
S/MIME Cryptographic Signature