forked from freeipa/freeipa
-
Notifications
You must be signed in to change notification settings - Fork 0
Certmonger
Endi S. Dewata edited this page Mar 8, 2023
·
8 revisions
-
used for renewing CA system certs (signing, OCSP, subsystem, audit)
-
authenticated using IPA RA agent cert (
ipaCert
) -
stores renewed cert under
ca=ca_renewal,cn=ipa,cn=etc,<base DN>
-
used for renewing SSL cert
-
authenticated using host keytab (
/etc/krb5.keytab
) -
IPA forwards the request to PKI