Using EJBCA with an existing Samba Active Directory + PKI setup #714
-
Hello all, My understanding for my setup is I should go for 'Install EJBCA as a CA without a Management CA' as my management CA is in my case "User CA". I have created my P12 keystore such as:
I copied it to When I wanted to deploy my keystore:
I cannot see any mention of BTW, I guess in my 'truststore.jks' I must also have at least two certificates: one that matches |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 12 replies
-
toimcat.p12 is the TLS server certificate itself. It's usually issued from the same Management CA, but can be from any other CA as long as it can issue TLS server certificates for the correct DNS name. |
Beta Was this translation helpful? Give feedback.
-
@oliviermartin I came across this discussion with your project on PKI and I find it particularly interesting, especially in relation to my field. I would love to discuss your work and possibly exchange ideas. Could you please let me know if I might have your contact details to discuss this further? Thank you in advance for your response! |
Beta Was this translation helpful? Give feedback.
toimcat.p12 is the TLS server certificate itself. It's usually issued from the same Management CA, but can be from any other CA as long as it can issue TLS server certificates for the correct DNS name.
Typically truststore.jks only need to contain the Root as the issuing CA is typically part of the TLS handshake.