> 
> Certificates are issued from IPA CA with the OCSP responder URI 
> http://ipa-ca.$DOMAIN/ca/ocsp and CRL distribution point 
> http://ipa-ca.$DOMAIN/ipa/crl/MasterCRL.bin (these are set in the 
> certificate extensions).
> 
> flo

Thanks! Does it have to be an IPA server with CA? What if it doesn't have CA 
component - will it forward the request to one of the IPA servers with CA?
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org

Reply via email to