Skip to content
Discussion options

You must be logged in to vote

Hi @dopey

I'll try and elaborate, let me know if you need more info.

  1. I have three groups of servers. On three different networks.
  2. I want each group of servers to have an intermediate authority (IA) server, issuing certificates. (server cert can be 1 week, then renew etc)
  3. I want a single certificate authority (CA) that has a lifespan of 20 years, which will only create certificates for the IAs (lifespan 10 years).

I will therefore have 1 x CA (mostly offline), 3 x IA's (always online), ? x number of server certificates.

Now from my understanding the CA will use a self signed certificate (one it creates itself), but the IA should be created with a certificate made from the CA.

Q: How do I…

Replies: 2 comments 8 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
8 replies
@Rapt88
Comment options

@tashian
Comment options

tashian Oct 9, 2020
Collaborator

@Rapt88
Comment options

@bonedaddy
Comment options

@Rapt88
Comment options

Answer selected by Rapt88
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
4 participants