On 6/7/2016 6:07 AM, Ade Lee wrote:
Hi all,
In a followup to my widely popular previous post on migrating a top
level CA from RHCS 8 -> 9 (
http://pki.fedoraproject.org/wiki/Migrating_
a_ca_with_hsm_using_existing_ca_mechanism), I've added a non-HSM based
version which does the migration using a PKCS #12 file to migrate the
signing certificate.
http://pki.fedoraproject.org/wiki/Migrating_a_CA_using_existing_CA_mech
anism
Comments/corrections etc. welcomed.
Ade
I fixed the version numbers in both pages to clarify that these
instructions are for RHCS 9.1.
I think in practice it's unlikely that someone would put a hostname in
the following parameters so I'd suggest we remove it from the example
(or replace it with a domain name instead of hostname):
pki_ds_base_dn=dc=host1.example.com-pki-rootCA
pki_ds_database=host1.example.com-pki-rootCA
--
Endi S. Dewata