Re: [Freeipa-users] Automatic IPA CA cert generation

2015-09-28 Thread James Masson
On 24/09/15 01:20, Fraser Tweedale wrote: On Wed, Sep 23, 2015 at 11:16:27AM +0100, James Masson wrote: On 23/09/15 11:03, Fraser Tweedale wrote: On Wed, Sep 23, 2015 at 09:09:25AM +0200, David Kupka wrote: On 22/09/15 17:02, James Masson wrote: Hi, we're building IPAs in an automated fa

Re: [Freeipa-users] Automatic IPA CA cert generation

2015-09-23 Thread Fraser Tweedale
On Wed, Sep 23, 2015 at 11:16:27AM +0100, James Masson wrote: > > On 23/09/15 11:03, Fraser Tweedale wrote: > >On Wed, Sep 23, 2015 at 09:09:25AM +0200, David Kupka wrote: > >>On 22/09/15 17:02, James Masson wrote: > >>> > >>>Hi, > >>> > >>>we're building IPAs in an automated fashion, for environm

Re: [Freeipa-users] Automatic IPA CA cert generation

2015-09-23 Thread Rob Crittenden
David Kupka wrote: > On 22/09/15 17:02, James Masson wrote: >> >> Hi, >> >> we're building IPAs in an automated fashion, for environments that get >> created and destroyed a lot. At the moment, the CA certs used inside >> these IPAs are self-signed, as part of the normal "ipa-server-install" >> set

Re: [Freeipa-users] Automatic IPA CA cert generation

2015-09-23 Thread James Masson
On 23/09/15 11:03, Fraser Tweedale wrote: On Wed, Sep 23, 2015 at 09:09:25AM +0200, David Kupka wrote: On 22/09/15 17:02, James Masson wrote: Hi, we're building IPAs in an automated fashion, for environments that get created and destroyed a lot. At the moment, the CA certs used inside these

Re: [Freeipa-users] Automatic IPA CA cert generation

2015-09-23 Thread Fraser Tweedale
On Wed, Sep 23, 2015 at 09:09:25AM +0200, David Kupka wrote: > On 22/09/15 17:02, James Masson wrote: > > > >Hi, > > > >we're building IPAs in an automated fashion, for environments that get > >created and destroyed a lot. At the moment, the CA certs used inside > >these IPAs are self-signed, as pa

Re: [Freeipa-users] Automatic IPA CA cert generation

2015-09-23 Thread David Kupka
On 22/09/15 17:02, James Masson wrote: Hi, we're building IPAs in an automated fashion, for environments that get created and destroyed a lot. At the moment, the CA certs used inside these IPAs are self-signed, as part of the normal "ipa-server-install" setup process. We would like to switch t