dalini wrote:

- but as far as i see this right now - the pix or lets say scep can just handle one ca - yeah and here we have a real problem right ahaed

Let's say the PIX only supports one CA. NetScreen ScreenOS supports several CAs and you can activate SCEP for every CA. The only problem with ScreenOS is that you must install the CA certificate with SCEP and not offline if you want to use SCEP for the certificate (but you can check the CA via the fingerprint).


- so if we approve the new ca - we loose validity of certs for the old one, but they are still valid, actually - and we can't proof for crls of the old one two

This is only valid on the PIX but do you be sure that the PIX can only handle one CA?


Michael
--
-------------------------------------------------------------------
Michael Bell                   Email: [EMAIL PROTECTED]
ZE Computer- und Medienservice            Tel.: +49 (0)30-2093 2482
(Computing Centre)                        Fax:  +49 (0)30-2093 2704
Humboldt-University of Berlin
Unter den Linden 6
10099 Berlin                   Email (private): [EMAIL PROTECTED]
Germany                                       http://www.openca.org



-------------------------------------------------------
This SF.Net email is sponsored by: IBM Linux Tutorials
Free Linux tutorial presented by Daniel Robbins, President and CEO of
GenToo technologies. Learn everything from fundamentals to system
administration.http://ads.osdn.com/?ad_id=1470&alloc_id=3638&op=click
_______________________________________________
Openca-Users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/openca-users

Reply via email to