Hi,

There are two self-signed root CAs (e.g. rootCA1 and rootCA2) in the organization I work for, and both have sub-CAs. For instance,

The sub-CAs of rootCA1 are :-
1. subCA1
2. subCA2

The sub-CAs of rootCA2 are :-
1. subCA3
2. subCA4

As the number of PCs are many, it is too difficult, if not impossible, to install the self-signed certificates of both rootCA1 and rootCA2 as trusted root CAs on every PCs.

Is there any better way that to cross-certify both rootCA1 and rootCA2, such that the machines with certificate signed by subCA1 would trust the certificates signed by subCA3? and vice versa.

Thanks a lot.

John Mok

______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    openssl-users@openssl.org
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to