Re: [Freeipa-devel] User Certificates in 4.2 - design and questions

2015-05-05 Thread Martin Kosek
On 05/05/2015 08:38 AM, Martin Kosek wrote: > On 05/04/2015 09:23 PM, Simo Sorce wrote: >> On Mon, 2015-05-04 at 16:41 +0200, Martin Kosek wrote: ... >> So I am fine *not* revoking certs automatically and instead documenting >> best practices for certs lifecycle management (ie deleting certs when >

Re: [Freeipa-devel] User Certificates in 4.2 - design and questions

2015-05-05 Thread Fraser Tweedale
On Tue, May 05, 2015 at 08:38:28AM +0200, Martin Kosek wrote: > On 05/04/2015 09:23 PM, Simo Sorce wrote: > > On Mon, 2015-05-04 at 16:41 +0200, Martin Kosek wrote: > >> On 05/04/2015 03:01 PM, Fraser Tweedale wrote: > >>> On Mon, May 04, 2015 at 10:50:15AM +0200, Martin Kosek wrote: > Hello,

Re: [Freeipa-devel] User Certificates in 4.2 - design and questions

2015-05-04 Thread Martin Kosek
On 05/04/2015 09:23 PM, Simo Sorce wrote: > On Mon, 2015-05-04 at 16:41 +0200, Martin Kosek wrote: >> On 05/04/2015 03:01 PM, Fraser Tweedale wrote: >>> On Mon, May 04, 2015 at 10:50:15AM +0200, Martin Kosek wrote: Hello, Please let me promote the design for one of the major FreeIPA

Re: [Freeipa-devel] User Certificates in 4.2 - design and questions

2015-05-04 Thread Simo Sorce
On Mon, 2015-05-04 at 16:41 +0200, Martin Kosek wrote: > On 05/04/2015 03:01 PM, Fraser Tweedale wrote: > > On Mon, May 04, 2015 at 10:50:15AM +0200, Martin Kosek wrote: > >> Hello, > >> > >> Please let me promote the design for one of the major FreeIPA 4.2 > >> features, the > >> (user) certifica

Re: [Freeipa-devel] User Certificates in 4.2 - design and questions

2015-05-04 Thread Martin Kosek
On 05/04/2015 03:01 PM, Fraser Tweedale wrote: > On Mon, May 04, 2015 at 10:50:15AM +0200, Martin Kosek wrote: >> Hello, >> >> Please let me promote the design for one of the major FreeIPA 4.2 features, >> the >> (user) certificates and Smart Card integration: >> >> http://www.freeipa.org/page/V4/

Re: [Freeipa-devel] User Certificates in 4.2 - design and questions

2015-05-04 Thread Fraser Tweedale
On Mon, May 04, 2015 at 10:50:15AM +0200, Martin Kosek wrote: > Hello, > > Please let me promote the design for one of the major FreeIPA 4.2 features, > the > (user) certificates and Smart Card integration: > > http://www.freeipa.org/page/V4/User_Certificates > > The design went through couple

[Freeipa-devel] User Certificates in 4.2 - design and questions

2015-05-04 Thread Martin Kosek
Hello, Please let me promote the design for one of the major FreeIPA 4.2 features, the (user) certificates and Smart Card integration: http://www.freeipa.org/page/V4/User_Certificates The design went through couple interim discussions between developers outside of this list, so there should not

Re: [Freeipa-devel] user certificates

2014-06-11 Thread Dmitri Pal
On 06/11/2014 09:18 PM, Fraser Tweedale wrote: On Wed, Jun 11, 2014 at 08:55:20AM -0400, John Dennis wrote: On 06/11/2014 04:02 AM, Fraser Tweedale wrote: There are other use cases for user certificates, e.g. client authentication for HTTP or other network services. Perhaps you know of others

Re: [Freeipa-devel] user certificates

2014-06-11 Thread Fraser Tweedale
On Wed, Jun 11, 2014 at 08:55:20AM -0400, John Dennis wrote: > On 06/11/2014 04:02 AM, Fraser Tweedale wrote: > > There are other use cases for user certificates, e.g. client > > authentication for HTTP or other network services. Perhaps you know > > of others - in which case let us know. > > 802

Re: [Freeipa-devel] user certificates

2014-06-11 Thread Nathaniel McCallum
On Wed, 2014-06-11 at 13:07 -0400, John Dennis wrote: > On 06/11/2014 12:12 PM, Nathaniel McCallum wrote: > > On Wed, 2014-06-11 at 08:55 -0400, John Dennis wrote: > >> On 06/11/2014 04:02 AM, Fraser Tweedale wrote: > >>> There are other use cases for user certificates, e.g. client > >>> authentica

Re: [Freeipa-devel] user certificates

2014-06-11 Thread John Dennis
On 06/11/2014 12:12 PM, Nathaniel McCallum wrote: > On Wed, 2014-06-11 at 08:55 -0400, John Dennis wrote: >> On 06/11/2014 04:02 AM, Fraser Tweedale wrote: >>> There are other use cases for user certificates, e.g. client >>> authentication for HTTP or other network services. Perhaps you know >>> o

Re: [Freeipa-devel] user certificates

2014-06-11 Thread Nathaniel McCallum
On Wed, 2014-06-11 at 08:55 -0400, John Dennis wrote: > On 06/11/2014 04:02 AM, Fraser Tweedale wrote: > > There are other use cases for user certificates, e.g. client > > authentication for HTTP or other network services. Perhaps you know > > of others - in which case let us know. > > 802.11 wir

Re: [Freeipa-devel] user certificates

2014-06-11 Thread John Dennis
On 06/11/2014 04:02 AM, Fraser Tweedale wrote: > There are other use cases for user certificates, e.g. client > authentication for HTTP or other network services. Perhaps you know > of others - in which case let us know. 802.11 wireless authentication using EAP-TLS A common discussion on the RAD

[Freeipa-devel] user certificates

2014-06-11 Thread Fraser Tweedale
Hi all, Use cases are emerging for user certificates in FreeIPA. Some include: - VPN certificates. A user logs into an IPA domain. They are not connected to a wired network so a background service (SSSD or other) acquires a short-lived client certificate for connecting to the company VPN