Re: [Freeipa-users] Heads-up: Removing self-sign CA

2013-03-28 Thread Christian Horn
Hi, On Tue, Mar 26, 2013 at 05:02:34PM +0100, Petr Viktorin wrote: We will soon be introducing a way to install IPA with custom certificates without a CA at all. When that is merged, it will no longer be possible to install a self-sign server. I see that the change in functionality is in

Re: [Freeipa-users] Heads-up: Removing self-sign CA

2013-03-28 Thread Petr Viktorin
On 03/28/2013 09:10 AM, Christian Horn wrote: Hi, On Tue, Mar 26, 2013 at 05:02:34PM +0100, Petr Viktorin wrote: We will soon be introducing a way to install IPA with custom certificates without a CA at all. When that is merged, it will no longer be possible to install a self-sign server. I

Re: [Freeipa-users] Heads-up: Removing self-sign CA

2013-03-28 Thread Christian Horn
On Thu, Mar 28, 2013 at 09:32:36AM +0100, Petr Viktorin wrote: To clarify: this is about removing the --selfsign option to ipa-server-install, which installs a limited CA (for example, it doesn't support CA replication or cert-find). The default Dogtag CA also uses a self-signed

[Freeipa-users] Heads-up: Removing self-sign CA

2013-03-26 Thread Petr Viktorin
Hello list, FreeIPA's self-sign CA is a holdout from days where the our integration with a real CA wasn't that good. Also its name is confusing: the Dogtag CA also uses a self-signed certificate by default. We will soon be introducing a way to install IPA with custom certificates without a CA