LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-31-2011, 11:52 AM   #1
fiku
LQ Newbie
 
Registered: Oct 2010
Posts: 25

Rep: Reputation: 2
Question [SOLVED] CA server / PKI management


Hi,

I've been wondering if there exists some solutions that helps in managing the certificates tree, e.g. revoking, issuing, generating CRL list, etc.

Found:
But, the first one has huge hardware requierements (written in Java). With the second, I've failed to install it just out-of-the-box.

Is it even safe, to manage such a tree via web UI ? The first problem, that comes to my mind, is that the software would have to have an access to the root.key which is rather inconvenient.

Nevertheless, how is it done in an enterprise?

Requirements:
  • platform: linux
  • cost: opensource


[UPDATE]
Found feature-rich solution. Maybe one would be interested in:
DogTag PKI
Unfortunately, it's Fedora/RedHat/CentOS dependent. I'll try to use it under Debian and give a note, if succeeded.


[UPDATE]
I've abandoned DogTag.
Instead, I've installed and configured EJBCA. I really recommend it. It has many features, that are important (e.g. possibility to isolate CA from RA, group & permissions management, whole certificate life-cycle, and many more).
On the homepage, there's also LiveCD available, so if one want's to test, just go for it

Last edited by fiku; 05-05-2011 at 06:12 AM. Reason: Update
 
Old 02-01-2011, 09:31 PM   #2
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
Quote:
Originally Posted by fiku
... how is it done in an enterprise?
No idea how this is generally done in an enterprise. I manage a small CA for my department, but I get by with openssl(1)'s handy CA.pl(1) interface.

Quote:
Originally Posted by fiku
Is it even safe, to manage such a tree via web UI ?
Short answer (IMO): not really!

Longer answer (IMO): sure - if you keep it on a highly restricted, hardened, non-Internet facing host. (It would of course be your responsibility to assess the level of risk and deploy accordingly.)
 
Old 02-04-2011, 08:12 AM   #3
fiku
LQ Newbie
 
Registered: Oct 2010
Posts: 25

Original Poster
Rep: Reputation: 2
Quote:
Originally Posted by anomie View Post
No idea how this is generally done in an enterprise. I manage a small CA for my department, but I get by with openssl(1)'s handy CA.pl(1) interface.
Actually, I use the same method right now. But it would be nice, to have some interface, when e.g. non-IT person could send a request for his/her certificate to be signed by CA or, as mentioned above, generating CRL (though it's quite simple done by CA.{pl,sh} - actually wrapped CA.{pl,sh} that also deploys the CRL to the WWW server).

Thanks for the response, anyway.
 
Old 05-05-2011, 06:12 AM   #4
fiku
LQ Newbie
 
Registered: Oct 2010
Posts: 25

Original Poster
Rep: Reputation: 2
I've abandoned DogTag.
Instead, I've installed and configured EJBCA. I really recommend it. It has many features, that are important (e.g. possibility to isolate CA from RA, group & permissions management, whole certificate life-cycle, and many more).
On the homepage, there's also LiveCD available, so if one want's to test, just go for it
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How do I determine which PKI certificates are installed on a Red Hat server? batesra Linux - Security 2 01-10-2011 08:39 AM
SSH with PKI prafulnama Linux - Security 6 03-19-2009 09:07 AM
Windows AD management and print server management. barn63 Slackware 5 12-10-2008 09:31 AM
PKI implementation amsri Linux - Networking 0 01-24-2006 07:49 AM
Pki subban Linux - Enterprise 1 12-19-2004 04:02 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:50 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration