On 6/7/2016 6:07 AM, Ade Lee wrote:
Hi all,

In a followup to my widely popular previous post on migrating a top
level CA from RHCS 8 -> 9 (http://pki.fedoraproject.org/wiki/Migrating_
a_ca_with_hsm_using_existing_ca_mechanism), I've added a non-HSM based
version which does the migration using a PKCS #12 file to migrate the
signing certificate.

http://pki.fedoraproject.org/wiki/Migrating_a_CA_using_existing_CA_mech
anism

Comments/corrections etc. welcomed.

Ade

I fixed the version numbers in both pages to clarify that these instructions are for RHCS 9.1.

I think in practice it's unlikely that someone would put a hostname in the following parameters so I'd suggest we remove it from the example (or replace it with a domain name instead of hostname):

 pki_ds_base_dn=dc=host1.example.com-pki-rootCA
 pki_ds_database=host1.example.com-pki-rootCA

--
Endi S. Dewata

_______________________________________________
Pki-devel mailing list
[email protected]
https://www.redhat.com/mailman/listinfo/pki-devel

Reply via email to