[389-users] duplicate existing ssl crenentials on another server ?

Daniel Maher dma+389users at witbe.net
Tue Nov 9 16:06:22 UTC 2010


On 11/09/2010 04:27 PM, Gerrard Geldenhuis wrote:

> There is another document on the wiki which describes how to setup certificates for a vip.... that is similar to what you want to do. I can't find it at the moment but might be worth trolling through the wiki again.

Actually, the SSL howto has a section on VIPs (the only hit on a search, 
in fact) :
http://directory.fedoraproject.org/wiki/Howto:SSL#Using_Subject_Alt_Name

I gave it a second read-through, and it would seem to indicate that alt 
names can be IPs as well as hostnames (i thought it was only the latter 
that was possible).

It would therefore appear to be possible to create a certificate that 
with a series of alt names - in my scenario, there would literally be 
one hostname and two IP addresses.

Has anybody on the list done something similar ?  Any advice ?  Should 
this just work outright ?

(p.s. Angel Bosch Mora - turns out you may have been right the first 
time ! :) ).


-- 
Daniel Maher <dma + 389users AT witbe DOT net>



More information about the 389-users mailing list