Hi all,

I am working with OpenCA since a few months and after using it I've
got some doubts. I hope someone could help me.

Everytime you make a request you have to insert your data and a PIN
code. According to my experience, this code it's used as a passphrase
to encrypt the private key generated, but it's not stored in any
database and it's no longer used by OpenCA (unless you want to
download the key, a PCKS#12 file or even change it).

This behaviour is OK for user requests, but has nosense for server
requests because in that case  the encpryted pair of keys and also a
CSR has already benn generated in the server. Why is needed to give a
PIN code? Is it used?  Is it stored anywhere? Can I use it later for
any kind of authentication?

Thanks for your help.

Regards,
Manolo


-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now.
http://ads.osdn.com/?ad_id=6595&alloc_id=14396&op=click
_______________________________________________
Openca-Users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openca-users

Reply via email to