Skip to content

Setting up Security Domain

Endi S. Dewata edited this page Nov 30, 2023 · 21 revisions

Creating New Security Domain

$ pki-server sd-create \
    --name EXAMPLE

Adding Subsystem

$ pki-server sd-subsystem-add \
    --subsystem CA \
    --hostname pki.example.com \
    --unsecure-port 8080 \
    --secure-port 8443 \
    --domain-manager \
    "CA pki.example.com 8443"

Configuring New Security Domain

$ pki-server ca-config-set securitydomain.select new
$ pki-server ca-config-set securitydomain.name EXAMPLE
$ pki-server ca-config-set securitydomain.host pki.example.com
$ pki-server ca-config-set securitydomain.httpport 8080
$ pki-server ca-config-set securitydomain.httpsadminport 8443
$ pki-server ca-config-set securitydomain.checkIP false
$ pki-server ca-config-set securitydomain.checkinterval 300000
$ pki-server ca-config-set securitydomain.flushinterval 86400000
$ pki-server ca-config-set securitydomain.source ldap

Configuring Existing Security Domain

$ pki-server ca-config-set securitydomain.select existing
$ pki-server ca-config-set securitydomain.name EXAMPLE
$ pki-server ca-config-set securitydomain.host pki.example.com
$ pki-server ca-config-set securitydomain.httpport 8080
$ pki-server ca-config-set securitydomain.httpsadminport 8443
Clone this wiki locally