[CentOS] Suggestions for a plug and play CA certificate manager?

James B. Byrne

byrnejb at harte-lyne.ca
Tue Jun 24 17:08:16 UTC 2008


I have played with self-signed end-use PKI certificates for about a decade
now and would really like to set up a proper, albeit private, PKI using
some sort of OFS CA management software. I have looked at OpenCA and found
a few packages on sourceforge but they all seem to fall short of my
desires in one form or another (rpm install, multiple subordinate CAs,
certificate revocation and extension management, web-based or
linux/microsoft GUI) .  I have even tried to use the scripts that come
with OpenSSL with very limited success.

What I would like to do is to set up a self-signed root CA certificate,
then use that to issue one or more signing CA's, each possibly limited as
to what type of certificate that they can sign. These issuing CAs would
then sign certificate requests for end-use certificates for hosts, email
accounts, document provenance, objects, etc.

| -- root_CA
     |
     | -- issuer_hosts_a_CA
     |    | -- certs
     |    |    | -- cert_issued_index
     |    |    ` -- cert_revoked_list
     |    | -- csrs
     |    ` -- private
     |         ` -- issuer_hosts_a_CA+key.pem
     |
     | -- issuer_services_a_CA
     |    | -- certs
     |    |    | -- cert_issued_index
     |    |    ` -- cert_revoked_list
     |    | -- csrs
     |    ` -- private
     |         ` -- issuer_services_a_CA+key.pem
     |
     ` -- issuer_email_a_CA
          | -- certs
          |    | -- cert_issued_index
          |    ` -- cert_revoked_list
          | -- csrs
          ` -- private
               ` -- issuer_email_a_CA+key.pem

What software do people use to manage a PKI on CentOS5?


Regards,

-- 
***          E-Mail is NOT a SECURE channel          ***
James B. Byrne                mailto:ByrneJB at Harte-Lyne.ca
Harte & Lyne Limited          http://www.harte-lyne.ca
9 Brockley Drive              vox: +1 905 561 1241
Hamilton, Ontario             fax: +1 905 561 0757
Canada  L8E 3C3




More information about the CentOS mailing list