Linux Archive

Linux Archive (http://www.linux-archive.org/)
-   CentOS (http://www.linux-archive.org/centos/)
-   -   Suggestions for a plug and play CA certificate manager? (http://www.linux-archive.org/centos/112858-suggestions-plug-play-ca-certificate-manager.html)

Patrick 06-24-2008 07:27 PM

Suggestions for a plug and play CA certificate manager?
 
On Tue, 2008-06-24 at 13:08 -0400, James B. Byrne wrote:
> I have played with self-signed end-use PKI certificates for about a decade
> now and would really like to set up a proper, albeit private, PKI using
> some sort of OFS CA management software.

Have you looked at the Open Source'd Red Hat Certificate Manager?

http://pki.fedoraproject.org/wiki/PKI_Main_Page

Regards,
Patrick

_______________________________________________
CentOS mailing list
CentOS@centos.org
http://lists.centos.org/mailman/listinfo/centos

Robert Moskowitz 06-24-2008 10:50 PM

Suggestions for a plug and play CA certificate manager?
 
James B. Byrne wrote:

I have played with self-signed end-use PKI certificates for about a decade
now and would really like to set up a proper, albeit private, PKI using
some sort of OFS CA management software. I have looked at OpenCA and found
a few packages on sourceforge but they all seem to fall short of my
desires in one form or another (rpm install, multiple subordinate CAs,
certificate revocation and extension management, web-based or
linux/microsoft GUI) . I have even tried to use the scripts that come
with OpenSSL with very limited success.

What I would like to do is to set up a self-signed root CA certificate,
then use that to issue one or more signing CA's, each possibly limited as
to what type of certificate that they can sign. These issuing CAs would
then sign certificate requests for end-use certificates for hosts, email
accounts, document provenance, objects, etc.
Perhaps more than what you want, but Spyrus just released their
PocketCA(tm). A complete CA on a USB dongle. I know a lot of people at
Spyrus and they are among the best you will find in the PKI arena. So it
is worth a look.


Otherwise, try TinyCA2. It will do what you want too.


_______________________________________________
CentOS mailing list
CentOS@centos.org
http://lists.centos.org/mailman/listinfo/centos


All times are GMT. The time now is 09:53 AM.

VBulletin, Copyright ©2000 - 2014, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO ©2007, Crawlability, Inc.