Hi Christina,
Thanks for the reply. I will go through the attached email.
I had another question - I see that Doghat is supported on Fedora and RHEL. Is it possible
to run Doghat on Ubuntu host? Has anyone tried it and any thoughts on how to make Doghat
work on Ubuntu?
Thanks,
Abha
On Wednesday, July 2, 2014 7:17 PM, Christina Fu <cfu(a)redhat.com> wrote:
I have not played with it, at least not for a long long time, but you can try out the
documentation pointed to from some past thread... see attached.
Regarding SCEP messages, we do not support fully, so the answer is
no, not yet.
Christina
On 07/02/2014 11:27 AM, Abha Jain wrote:
Hi All,
We are looking at using Doghat CA server with Cisco routers. I had a few questions on the
support included in Doghat certificate system.
I just started working on PKI, so please excuse if the questions are quite basic.
1. The Doghat system is built on top of NSS (Network Security Services). Does it have any
issues working with Cisco routers as clients using SCEP? Would there be any OpenSSL and
NSS interactions in this case?
2. Does Doghat support CA Certificate rollover? When CA certificate is about to expire, CA
creates a shadow certificate. All the endpoints associated with that CA can then renew
their ID certificates (this requires support for SCEP Messages such as GetNextCACert,
GetCACaps).
Thanks in advance for your help!
-Abha
_______________________________________________
Pki-users mailing list
Pki-users(a)redhat.com
https://www.redhat.com/mailman/listinfo/pki-users
SCEP is disabled by default in CA, so you need to enable SCEP first:
https://access.redhat.com/site/documentation/en-US/Red_Hat_Certificate_Sy...
If you want to use SCEP with CA authentication, you need to enable
FlatFileAuthentication plug-in:
https://access.redhat.com/site/documentation/en-US/Red_Hat_Certificate_Sy...
If you want to use SCEP with RA authentication, you need to follow RA's
UI to create one time pins for SCEP requests. RA is using SQLite as its
repository so no need to create directory entries.
I would advise you to use SCEP with CA only as more improvements were
provided in this area.
Thanks,
Andrew
On 08/20/2013 07:10 AM, Oleg Antonenko wrote:
Hi!
I'm planning to evaluate Dogtag CA for issuing certs for mobile devices via SCEP.
But before plunging into full blown installation and tests I'd like to understand
overall SCEP cert enrolment workflow supported by Dogtag.
>From the documentation on the web site I've figured out that it is possible to
send SCEP requests either to RA or directly to CA.
As I understood in RA mode a user record with one-time PIN/Challenge has to be created in
the 389 Directory first, and then a cert can be requested via SCEP.
Is that correct?
I did not get an impression that I have to do same when sending SCEP requests directly to
CA.
Does anyone know if I have to create a user record in the 389 DS before sending a SCEP
request to CA directly?
Thanks in advance,
Oleg
_______________________________________________
Pki-users mailing list
Pki-users(a)redhat.com
https://www.redhat.com/mailman/listinfo/pki-users
_______________________________________________
Pki-users mailing list
Pki-users(a)redhat.com
https://www.redhat.com/mailman/listinfo/pki-users
_______________________________________________
Pki-users mailing list
Pki-users(a)redhat.com
https://www.redhat.com/mailman/listinfo/pki-users