Hi Roberto,
Are there any "gotchas" that we should worry about, aside from the security risks of having the CA and the RA on the same machine?
No none at all - you can setup a "single site" installation - I think one of the install options does this.
One of our requirements is that we need a system in which a user can enter in a username/pw, and walk out with their certificate. Our authentication is essentially being handled by a party unrelated to OpenCA, which we can trust. I do not believe that there is a way to do this without combining the two databases, and modifying some of the certificate requesting commands. Am I mistaken here?
oooh ugly - I see 2 possible approaches:
1) Run a cron job that signs the certs - so the users have some minutes delay
2) rewrite a huge part of the scripting - I think what you want is not easy...at least not with OpenCA itself..
Oliver
-- Diese Nachricht wurde digital unterschrieben oliwel's public key: http://www.oliwel.de/oliwel.crt Basiszertifikat: http://www.ldv.ei.tum.de/page72
smime.p7s
Description: S/MIME Cryptographic Signature
