Hello,

Thank you. I have successfully changed OCSP URI in all certificates
generated during installation using two-step installation method:
http://www.dogtagpki.org/wiki/Two-Step_Installation

I had to edit adminCert.profile, caCert.profile,  serverCert.profile,
caAuditSigningCert.profile,  caOCSPCert.profile,  subsystemCert.profile
in /var/lib/pki/NAME/ca/conf/ before "configuration" step..

After installation I had to edit certificate profiles in
/var/lib/pki/NAME/ca/profiles/ca

as you mentioned and now everything works as I wished :)

Good luck
mirkt

2018.04.27 21:08, John Magne rašė:
> Hello:
>
> I believe you could modify the setting in your link for
> every kind of certificate profile that you care about.
> The AIA extension.
>
> The profiles are stored with each instance roughly here:
>
> /var/lib/pki/pki-tomcat/ca/profiles/ca

_______________________________________________
Pki-users mailing list
Pki-users@redhat.com
https://www.redhat.com/mailman/listinfo/pki-users

Reply via email to