diff options
author | Endi S. Dewata <edewata@redhat.com> | 2016-03-25 03:12:27 +0100 |
---|---|---|
committer | Endi S. Dewata <edewata@redhat.com> | 2016-04-15 20:03:30 +0200 |
commit | 08f032de4090467ac4096f970609e19834b997ac (patch) | |
tree | b41d3508f85ff46281b0b5c3793d6d932c8e9942 /base/server/etc/default.cfg | |
parent | e3449617d90f5f73afdb568cc2f43769e5ea760b (diff) | |
download | pki-08f032de4090467ac4096f970609e19834b997ac.tar.gz pki-08f032de4090467ac4096f970609e19834b997ac.tar.xz pki-08f032de4090467ac4096f970609e19834b997ac.zip |
Simplified deployment properties for existing CA case.
A new pki_existing deployment property has been added to install
CA with existing CA certificate and key in a single step.
New certificate deployment properties have been added as aliases
for some external CA properties to allow them to be used in more
general cases:
- pki_ca_signing_csr_path -> pki_external_csr_path
- pki_ca_signing_cert_path -> pki_external_ca_cert_path
- pki_cert_chain_path -> pki_external_ca_cert_chain_path
- pki_cert_chain_nickname -> pki_external_ca_cert_chain_nickname
https://fedorahosted.org/pki/ticket/1736
Diffstat (limited to 'base/server/etc/default.cfg')
-rw-r--r-- | base/server/etc/default.cfg | 13 |
1 files changed, 9 insertions, 4 deletions
diff --git a/base/server/etc/default.cfg b/base/server/etc/default.cfg index 924df9ddc..dc30468df 100644 --- a/base/server/etc/default.cfg +++ b/base/server/etc/default.cfg @@ -135,6 +135,9 @@ pki_theme_server_dir=/usr/share/pki/common-ui pki_token_name=internal pki_token_password= pki_user=pkiuser +pki_existing=False +pki_cert_chain_path= +pki_cert_chain_nickname=caSigningCert External CA pki_pkcs12_path= pki_pkcs12_password= @@ -370,17 +373,19 @@ pki_ca_signing_nickname=caSigningCert cert-%(pki_instance_name)s CA pki_ca_signing_signing_algorithm=SHA256withRSA pki_ca_signing_subject_dn=cn=CA Signing Certificate,o=%(pki_security_domain_name)s pki_ca_signing_token=Internal Key Storage Token +pki_ca_signing_csr_path= +pki_ca_signing_cert_path= pki_external=False pki_req_ext_add=False # MS subca request ext data pki_req_ext_oid=1.3.6.1.4.1.311.20.2 pki_req_ext_critical=False pki_req_ext_data=1E0A00530075006200430041 -pki_external_csr_path= pki_external_step_two=False -pki_external_ca_cert_chain_path= -pki_external_ca_cert_chain_nickname=caSigningCert External CA -pki_external_ca_cert_path= +pki_external_csr_path=%(pki_ca_signing_csr_path)s +pki_external_ca_cert_path=%(pki_ca_signing_cert_path)s +pki_external_ca_cert_chain_path=%(pki_cert_chain_path)s +pki_external_ca_cert_chain_nickname=%(pki_cert_chain_nickname)s pki_external_pkcs12_path=%(pki_pkcs12_path)s pki_external_pkcs12_password=%(pki_pkcs12_password)s pki_import_admin_cert=False |