Yes, I know it's not recommended, but due to logistical reasons, we are want to experiment with this.

Are there any "gotchas" that we should worry about, aside from the security risks of having the CA and the RA on the same machine?

One of our requirements is that we need a system in which a user can enter in a username/pw, and walk out with their certificate. Our authentication is essentially being handled by a party unrelated to OpenCA, which we can trust. I do not believe that there is a way to do this without combining the two databases, and modifying some of the certificate requesting commands. Am I mistaken here?

Thanks for your help,

Roberto Hoyle


-------------------------------------------------------
This SF.Net email sponsored by Black Hat Briefings & Training.
Attend Black Hat Briefings & Training, Las Vegas July 24-29 - digital self defense, top technical experts, no vendor pitches, unmatched networking opportunities. Visit www.blackhat.com
_______________________________________________
Openca-Users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/openca-users

Reply via email to