dogtagpki / pki

The Dogtag Certificate System is an enterprise-class Certificate Authority (CA) which supports all aspects of certificate lifecycle management, including key archival, OCSP and smartcard management.
https://www.dogtagpki.org
GNU General Public License v2.0
374 stars 137 forks source link

Support Lightweight CA key replication with non-RSA host authority #2411

Open pki-bot opened 4 years ago

pki-bot commented 4 years ago

This issue was migrated from Pagure Issue #2291. Originally filed by ftweedal (@frasertweedale) on 2016-04-21 05:53:22:


JSS only supports RSA key wrapping, therefore lightweight CA key replication will only work with RSA host authority.

We eventually need to support lightweight CA key replication with EC host authority. Some potential approaches:

pki-bot commented 4 years ago

Comment from ftweedal (@frasertweedale) at 2017-02-27 14:09:27

Metadata Update from @frasertweedale: