Welcome to Linux Forums!

With a comprehensive Linux Forum, information on various types of Linux software and many Linux Reviews articles, we have all the knowledge you need a click away, or accessible via our knowledgeable members.

Linux Forum ArticlesLinux ForumsLinux Forum DownloadsLinux Hosts
Home|Register|FAQ|Member List|Calendar|Unanswered Posts|Forum Rules|Today's Posts|Advanced Search|
SEARCH FOR IN
Go Back   Linux Forums > GNU Linux Zone > Linux Security
Reload this Page OpenSSL for PKI for large deployments
Linux Forums
Linux Forums
Welcome To The Linux Forums!
Welcome to Linux Forums. We pride ourselves in being one of the largest Linux communities on the web, we encourage you to REGISTER on our forums and participate in the community. There are over 150,000 members ready to answer your questions. JOINING US today will allow you to make new posts, get support, send messages to other members and submit downloads to our downloads directory and many other great features!

Linux Security Discussion about keeping your machines secure, and the crackers out.

Reply
 
Thread Tools Display Modes
Old 06-06-2008   #1 (permalink)
docrice
Just Joined!
 
Join Date: Jun 2008
Posts: 1
OpenSSL for PKI for large deployments

I apologize in advance if this has been already thoroughly answered elsewhere, so please point me to a link if that's the case. I'm under the impression that OpenSSL isn't a scalable solution for managing a PKI for a large number of clients (10,000+) since it's primarily a crypto library and there aren't any real tools for managing certificates.

I only have a superficial understanding of certificates / asymmetric crypto / hashes / signatures, etc.. However, I read some old articles which mentions that it doesn't compare with other PKI management solutions (Red Had Certificate System?). Why is this so? Can one not set up scripts for making revocations, CSR generations, signing, etc. easier?

My plan is to build a root CA, create some intermediary signing CAs, then offline the root for security. I'm assuming that's a common implementation.

Sorry for the ignorance on my part. Thanks for any help you can lend.
docrice is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT. The time now is 09:59 AM.




© 2000 - 2008 - All Rights Reserved - Property of  MAS Media

Content Relevant URLs by vBSEO 3.0.0