public inbox for gentoo-server@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-server] Local CA on Gentoo
@ 2012-02-10  1:03 Vinícius Ferrão
  2012-02-10  4:58 ` Denis Bondar
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Vinícius Ferrão @ 2012-02-10  1:03 UTC (permalink / raw
  To: gentoo-server

[-- Attachment #1: Type: text/plain, Size: 453 bytes --]

Hi peeps,

I would like to know if someone successfully implemented a Local CA to sign services and servers using Gentoo or other Linux.

I'm currently in a Mixed Environment (we have: Windows 2008R2, OS X Lion, Linux and FreeBSD), and I really want a single solution, since I need certs for my servers, as example: a Postfix Mail Gateway, a W2k8 Domain Controller, Exchange Server, Mac OS X Time Machine Server, etc.

Thanks in advance,
Vinícius

[-- Attachment #2: smime.p7s --]
[-- Type: application/pkcs7-signature, Size: 2327 bytes --]

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [gentoo-server] Local CA on Gentoo
  2012-02-10  1:03 [gentoo-server] Local CA on Gentoo Vinícius Ferrão
@ 2012-02-10  4:58 ` Denis Bondar
  2012-02-10  6:37 ` Ewald Wasscher
  2012-02-15  0:29 ` Ramon van Alteren
  2 siblings, 0 replies; 4+ messages in thread
From: Denis Bondar @ 2012-02-10  4:58 UTC (permalink / raw
  To: gentoo-server

[-- Attachment #1: Type: text/plain, Size: 674 bytes --]

Hi-

As an option look at https://www.startssl.com/
It provides valid certs for free.

2012/2/10 Vinícius Ferrão <viniciusferrao@cc.if.ufrj.br>

> Hi peeps,
>
> I would like to know if someone successfully implemented a Local CA to
> sign services and servers using Gentoo or other Linux.
>
> I'm currently in a Mixed Environment (we have: Windows 2008R2, OS X Lion,
> Linux and FreeBSD), and I really want a single solution, since I need certs
> for my servers, as example: a Postfix Mail Gateway, a W2k8 Domain
> Controller, Exchange Server, Mac OS X Time Machine Server, etc.
>
> Thanks in advance,
> Vinícius




-- 
Kind regards,
Denis Bondar

[-- Attachment #2: Type: text/html, Size: 1020 bytes --]

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [gentoo-server] Local CA on Gentoo
  2012-02-10  1:03 [gentoo-server] Local CA on Gentoo Vinícius Ferrão
  2012-02-10  4:58 ` Denis Bondar
@ 2012-02-10  6:37 ` Ewald Wasscher
  2012-02-15  0:29 ` Ramon van Alteren
  2 siblings, 0 replies; 4+ messages in thread
From: Ewald Wasscher @ 2012-02-10  6:37 UTC (permalink / raw
  To: gentoo-server@lists.gentoo.org

Hi,

IMHO EJBCA (http://www.ejbca.org) from the kind people at PrimeKey is
a very good open source CA solution. It is used in many large,
professional and certified/audited environments worldwide.

Regards,

Ewald



Op 10 feb. 2012 om 02:04 heeft "Vinícius Ferrão"
<viniciusferrao@cc.if.ufrj.br> het volgende geschreven:

> Hi peeps,
>
> I would like to know if someone successfully implemented a Local CA to sign services and servers using Gentoo or other Linux.
>
> I'm currently in a Mixed Environment (we have: Windows 2008R2, OS X Lion, Linux and FreeBSD), and I really want a single solution, since I need certs for my servers, as example: a Postfix Mail Gateway, a W2k8 Domain Controller, Exchange Server, Mac OS X Time Machine Server, etc.
>
> Thanks in advance,
> Vinícius



^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [gentoo-server] Local CA on Gentoo
  2012-02-10  1:03 [gentoo-server] Local CA on Gentoo Vinícius Ferrão
  2012-02-10  4:58 ` Denis Bondar
  2012-02-10  6:37 ` Ewald Wasscher
@ 2012-02-15  0:29 ` Ramon van Alteren
  2 siblings, 0 replies; 4+ messages in thread
From: Ramon van Alteren @ 2012-02-15  0:29 UTC (permalink / raw
  To: gentoo-server

I did, but it is far from trivial to do right....
And even then the mess in certificate fields and the non-standard way
all kinds of implementations are done over various services sometimes
drives me insane.....

Anyway, if your needs are fairly simple (1-2 level CA + signing
certificates) I can definitly recommend xca:
http://xca.sourceforge.net/

I has reasonable documentation and a nice GUI. It also produces well
defined certificates and most importantly has the ability to revoke
certificates that you have issued...

If you stick it's database into a VCS you can share the work.

/Ramon

2012/2/10 Vinícius Ferrão <viniciusferrao@cc.if.ufrj.br>:
> Hi peeps,
>
> I would like to know if someone successfully implemented a Local CA to sign services and servers using Gentoo or other Linux.
>
> I'm currently in a Mixed Environment (we have: Windows 2008R2, OS X Lion, Linux and FreeBSD), and I really want a single solution, since I need certs for my servers, as example: a Postfix Mail Gateway, a W2k8 Domain Controller, Exchange Server, Mac OS X Time Machine Server, etc.
>
> Thanks in advance,
> Vinícius



^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2012-02-15  0:30 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-02-10  1:03 [gentoo-server] Local CA on Gentoo Vinícius Ferrão
2012-02-10  4:58 ` Denis Bondar
2012-02-10  6:37 ` Ewald Wasscher
2012-02-15  0:29 ` Ramon van Alteren

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox