Re: Create Certificate Signing Request File

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



xinhuan zheng wrote:
Hello,

I need to create certificate signing request file that can be sent to certificate authority vendors, like GoDaddy, etc. I have two questions:

1) The certutil command line output a CSR file which has different format than the CSR file generated using 389-console the GUI. The main difference is that the certutil command line generates something like:

Certificate request generated by Netscape certutil
Phone: xxx-xxx-xxxx

Common Name: ....
Email: (not specified)
Organization: my organization
State: ...
Country: US

Following above, it's the "BEGIN NEW CERTIFICATE" section.

However, if it's GUI, only "BEGIN NEW CERTIFICATE" section is there.

Why the two methods generates output file different?  Will it be ok to just use certuti command output with "BEGIN NEW CERTIFICATE" section to send to vendor?

The other bit are just a comment. You can strip it out if you want. As for why they are different I don't know, that is probably lost to time but it's been doing that since the late 90's in the Netscape products.

2) Do I also need to create certificate signing request file for each admin server? Will that be the same procedure for the directory server instance?

Yes, you need a CSR for each server. The issued certificate will have the hostname for that server baked into it and it needs to match the server name.

I believe the procedure is very similar for the directory server cert though it's been quite a long time since I've done this.

rob
--
389-users mailing list
389-users@xxxxxxxxxxxxxxxxxxxxxxx
http://lists.fedoraproject.org/admin/lists/389-users@xxxxxxxxxxxxxxxxxxxxxxx




[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux