Hi Lyle,

Lyle Winton wrote:

I've been using OpenCA for a little over a year now, mainly in the context of managing Grid certificates. One change I've had to make in the code is to allow the signing of certificates in multiple DN domains. I was wondering, would anybody else find this a useful feature to be incorporated into OpenCA?

I think yes and therefore OpenCA supports this feature. The last 0.9.1.2 and the CVS HEAD support this feature. Perhaps we publish a 0.9.1.3 next week because of an additional fix to support really strict LDAP servers which have problems with CAs which include an emailaddress in it's subject (dn).


OpenCA 0.9.0-2, which I am running, does not support this as 'OpenCA/etc/servers/online.conf' and 'ldap.conf' only has one 'basedn' setting. On importing signed certs into the RA the error "Error ( dn conflicts with basedn )" caused by "addLDAPobject()" prevents the import!! If anybody is interested in my changes please email me.

We have already implemented this feature but we are interested in others code too. The reason is very simple. We can compare the code and use the best one :)


Best regards

Michael
--
-------------------------------------------------------------------
Michael Bell                   Email: [EMAIL PROTECTED]
ZE Computer- und Medienservice            Tel.: +49 (0)30-2093 2482
(Computing Centre)                        Fax:  +49 (0)30-2093 2704
Humboldt-University of Berlin
Unter den Linden 6
10099 Berlin                   Email (private): [EMAIL PROTECTED]
Germany                                       http://www.openca.org



-------------------------------------------------------
This SF.net email is sponsored by: VM Ware
With VMware you can run multiple operating systems on a single machine.
WITHOUT REBOOTING! Mix Linux / Windows / Novell virtual machines at the
same time. Free trial click here: http://www.vmware.com/wl/offer/345/0
_______________________________________________
Openca-Users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/openca-users

Reply via email to