[Freeipa-users] Re: Certificate profile to ignore (drop) email in SAN - possible?

2021-07-11 Thread Fraser Tweedale via FreeIPA-users
On Tue, Jul 06, 2021 at 01:29:48PM -0400, Rob Crittenden via FreeIPA-users wrote: > Ian Pilcher via FreeIPA-users wrote: > > I've hit a roadblock while trying to generate a certificate for > > a VMware vSphere appliance. > > > > The VMware "Certificate Management" tool doesn't allow one to > >

[Freeipa-users] Re: Certificate profile to ignore (drop) email in SAN - possible?

2021-07-07 Thread Ian Pilcher via FreeIPA-users
On 7/6/21 12:29 PM, Rob Crittenden wrote: IPA doesn't allow a CSR that has a RFC822Name SAN for a non-user. This validation happens before the CSR is submitted to the CA. You'd have to modify code to drop this requirement. Bummer, but understandable. Thanks for clarifying! --

[Freeipa-users] Re: Certificate profile to ignore (drop) email in SAN - possible?

2021-07-06 Thread Rob Crittenden via FreeIPA-users
Ian Pilcher via FreeIPA-users wrote: > I've hit a roadblock while trying to generate a certificate for a VMware > vSphere appliance. > > The VMware "Certificate Management" tool doesn't allow one to upload a > certificate and key.  Instead, one has to generate a CSR in the VMware > GUI which then