Hi Roberto,

Are there any "gotchas" that we should worry about, aside from the security risks of having the CA and the RA on the same machine?

No none at all - you can setup a "single site" installation - I think one of the install options does this.

One of our requirements is that we need a system in which a user can enter in a username/pw, and walk out with their certificate. Our authentication is essentially being handled by a party unrelated to OpenCA, which we can trust. I do not believe that there is a way to do this without combining the two databases, and modifying some of the certificate requesting commands. Am I mistaken here?

oooh ugly - I see 2 possible approaches:
1) Run a cron job that signs the certs - so the users have some minutes delay

2) rewrite a huge part of the scripting - I think what you want is not easy...at least not with OpenCA itself..

Oliver

--
Diese Nachricht wurde digital unterschrieben
oliwel's public key: http://www.oliwel.de/oliwel.crt
Basiszertifikat: http://www.ldv.ei.tum.de/page72

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature



Reply via email to