|
From: Johan E. <ejb...@pr...> - 2009-01-14 14:01:38
|
Pascal Vidal skrev: > HI, > > i'm looking for how to use cross-certificate issued by a CA from EJBCA. > > I have two CA which i want to cross-certify: > > RootCA1 & RootCA2 > > Each CA is hosted by a different EJBCA. I did the certification > request/process in the two IGC and I have the two cross-certificates: > > RootCA1 issued by RootCA2 > RootCA2 issued by RootCA1 > > I would like to know how can I use the two certificates. > > Q1: Do I specify some extensions in the certificate profile or something > else like AIA and others? > I believe this is client dependent. E.g. you install the cross-certificate as a any other sub-CA in the app that supports it. But I haven't seen any actual use of this in practice. > Q2: How can I use these certificates? > Well.. you did this cross-certification for some kind of purpose, right? Like federation of email signatures or something? You might want check the documentation of the end applications on their support for cross certification.. > I found some documents in the Internet but nothing very special... > > Best regards, > > Pascal > Maybe you can be a little bit more specific? Best Regards, Johan -- PrimeKey Solutions offers a commercial EJBCA support subscription and training for EJBCA. Please see www.primekey.se or contact in...@pr... for more information. http://download.primekey.se/documents/ejbca_subscription.pdf http://download.primekey.se/documents/ejbca_training.pdf |