Re: [Freeipa-users] using pathlen:0 for freeipa's CA certificate?

2015-05-15 Thread Fraser Tweedale
On Fri, May 15, 2015 at 10:53:20AM +0200, Jan Cholasta wrote: > Dne 15.5.2015 v 09:31 Martin Kosek napsal(a): > >On 05/15/2015 09:22 AM, Fraser Tweedale wrote: > >>On Fri, May 15, 2015 at 07:59:27AM +0200, Jan Cholasta wrote: > >>>Hi, > >>> > >>>Dne 5.5.2015 v 10:43 Martin Kosek napsal(a): > On

Re: [Freeipa-users] using pathlen:0 for freeipa's CA certificate?

2015-05-15 Thread Jan Cholasta
Dne 15.5.2015 v 09:31 Martin Kosek napsal(a): On 05/15/2015 09:22 AM, Fraser Tweedale wrote: On Fri, May 15, 2015 at 07:59:27AM +0200, Jan Cholasta wrote: Hi, Dne 5.5.2015 v 10:43 Martin Kosek napsal(a): On 05/04/2015 01:19 PM, Harald Dunkel wrote: Hi folks, Instead of a self-signed certifi

Re: [Freeipa-users] using pathlen:0 for freeipa's CA certificate?

2015-05-15 Thread Martin Kosek
On 05/15/2015 09:22 AM, Fraser Tweedale wrote: On Fri, May 15, 2015 at 07:59:27AM +0200, Jan Cholasta wrote: Hi, Dne 5.5.2015 v 10:43 Martin Kosek napsal(a): On 05/04/2015 01:19 PM, Harald Dunkel wrote: Hi folks, Instead of a self-signed certificate I would like to use an external CA to sign

Re: [Freeipa-users] using pathlen:0 for freeipa's CA certificate?

2015-05-15 Thread Fraser Tweedale
On Fri, May 15, 2015 at 07:59:27AM +0200, Jan Cholasta wrote: > Hi, > > Dne 5.5.2015 v 10:43 Martin Kosek napsal(a): > >On 05/04/2015 01:19 PM, Harald Dunkel wrote: > >>Hi folks, > >> > >>Instead of a self-signed certificate I would like to use an external > >>CA to sign freeipa's CSR ("ipa-server

Re: [Freeipa-users] using pathlen:0 for freeipa's CA certificate?

2015-05-14 Thread Jan Cholasta
Hi, Dne 5.5.2015 v 10:43 Martin Kosek napsal(a): On 05/04/2015 01:19 PM, Harald Dunkel wrote: Hi folks, Instead of a self-signed certificate I would like to use an external CA to sign freeipa's CSR ("ipa-server-install --external-ca"). Question: Is pathlen:0, e.g. basicConstraints=cr

Re: [Freeipa-users] using pathlen:0 for freeipa's CA certificate?

2015-05-05 Thread Martin Kosek
On 05/04/2015 01:19 PM, Harald Dunkel wrote: > Hi folks, > > Instead of a self-signed certificate I would like to use an external > CA to sign freeipa's CSR ("ipa-server-install --external-ca"). > Question: > > Is pathlen:0, e.g. > > basicConstraints=critical,CA:TRUE, pathlen:0 > > suffic

[Freeipa-users] using pathlen:0 for freeipa's CA certificate?

2015-05-04 Thread Harald Dunkel
Hi folks, Instead of a self-signed certificate I would like to use an external CA to sign freeipa's CSR ("ipa-server-install --external-ca"). Question: Is pathlen:0, e.g. basicConstraints=critical,CA:TRUE, pathlen:0 sufficient for freeipa's CA certificate? Regards Harri -- Manage yo