Skip to content

Lightweight CAs: add ability to configure CRLs for lightweight CAs #5233

@Bob131

Description

@Bob131

(A duplicate of #2186, as I'm not able to re-open that issue)

The inability to generate CRLs for sub-CAs is a bit of a problem for my use case. I'm attempting to migrate an ad-hoc CA for issuing VPN client certs to FreeIPA. Rotating credentials is a bit of a headache, so the current setup issues long-lived certificates and relies on CRLs to manage access. The plan was to have VPN certificates issued by a sub-CA, but the lack of support for issuing CRLs containing revoked sub-CA-issued certificates presents a problem.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions