Uploaded image for project: 'Dogtag PKI'
  1. Dogtag PKI
  2. DOGTAG-3233

AEP: try to fetch entire CA chain and import to CAPI/group policy/NTAuthCA stores

    • Moderate
    • rhel-idm-cs
    • rc
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None
    • 42

      AEP - auto enrollment proxy. Right now we have too many
      places to import CA certificates.

      1. Local Computer -> Trusted root certificates store
      2. Active directory -> domain level group policy
      3. publish certs to NTAuthCA store.
      4. proxy configuration -> CA certificate to be pasted in base64 format.

      We should try to see if we can automate this process.

      The ideal fix would be to specify the redhat CA host/port information
      and have the AEP configuration UI fetch the entire CA chain and have
      it imported in all the necessary places as required.

              mharmsen@redhat.com Matthew Harmsen
              ckannan_jira Chandrasekar Kannan (Inactive)
              RH Bugzilla Integration RH Bugzilla Integration
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: