Hello Cornelius,

Cornelius Kölbel wrote:

a) I guess I got the update_ldap_automatic wrong.
Is there a way to update the ldap-server after having signed a certificate or after the user has downloaded his signed certificate?

I'd like to avoid going to the ldap interface and doing
"LDAP Update" -> "Certificates"

To publish certificates automatically, after setting it to "true" in config.xml and running ./configure_etc.sh you must export new certificates from CA to RA, it doesn't matter if you have both interfaces (CA,RA) in one machine, you have to use your export device (by default floppy). So when you import new certificates in RA-Node it publish certificates automatically.



b) Is there any way to change the DN of the certificates?
At the moment the certificates will be stored under
dn:sericalNumber=2,cn=<name>,ou=users,o=<x>,c=<y>

I'd like to store the certs at
dn:sericalNumber=2,uid=<name>,ou=users,o=<x>,c=<y>


I haven't done this, but someone in the list talk about this in the list before, If I'm not wrong you have to activate some flags in config files but I'm not sure.

HTH,
Johnny
Kind regards
Cornelius



-------------------------------------------------------
This SF.Net email is sponsored by:
Power Architecture Resource Center: Free content, downloads, discussions,
and more. http://solutions.newsforge.com/ibmarch.tmpl
_______________________________________________
Openca-Users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openca-users



                
______________________________________________ Renovamos el Correo Yahoo! Nuevos servicios, más seguridad http://correo.yahoo.es



-------------------------------------------------------
This SF.Net email is sponsored by:
Power Architecture Resource Center: Free content, downloads, discussions,
and more. http://solutions.newsforge.com/ibmarch.tmpl
_______________________________________________
Openca-Users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openca-users

Reply via email to