Hello, Thank you. I have successfully changed OCSP URI in all certificates generated during installation using two-step installation method: http://www.dogtagpki.org/wiki/Two-Step_Installation
I had to edit adminCert.profile, caCert.profile, serverCert.profile, caAuditSigningCert.profile, caOCSPCert.profile, subsystemCert.profile in /var/lib/pki/NAME/ca/conf/ before "configuration" step.. After installation I had to edit certificate profiles in /var/lib/pki/NAME/ca/profiles/ca as you mentioned and now everything works as I wished :) Good luck mirkt 2018.04.27 21:08, John Magne rašė: > Hello: > > I believe you could modify the setting in your link for > every kind of certificate profile that you care about. > The AIA extension. > > The profiles are stored with each instance roughly here: > > /var/lib/pki/pki-tomcat/ca/profiles/ca _______________________________________________ Pki-users mailing list Pki-users@redhat.com https://www.redhat.com/mailman/listinfo/pki-users