Re: Multiple CAs

2009-07-21 Thread Kobus Bensch
Title: Fullnet Solutions Limited Hi Thank you for all the help. You have been most kind Kobus javierm wrote: Very good. In case you need a CA outside of your company saying "we know those guys" (instead of "I know myself") you can count on our company (energiash.com) of course without an

Re: Multiple CAs

2009-07-21 Thread javierm
Very good. In case you need a CA outside of your company saying "we know those guys" (instead of "I know myself") you can count on our company (energiash.com) of course without any cost involved, or buy your first CA with signing attributes from a well known source that is already in the browsers

Re: Multiple CAs

2009-07-21 Thread javierm
I thought I should be specific about cert creation because I've seen big corporations issueing pure CA certs for all, and they actually never create a client cert. And no matter how many approaches one take to explain that such thing is not right, they keep issueing CA'sCerts for all purposes, (i

Re: Multiple CAs

2009-07-21 Thread Kobus Bensch
Title: Fullnet Solutions Limited No this is great thanks. My ultimate aim is to create certs for a site. Then to distribute the certs to only those I want to be able to access the site, any other attempted access need to be denied and do this for each virt host. Sounds like it is possible, bu

Re: Multiple CAs

2009-07-21 Thread javierm
Hi Again: Not exactly to associate one CA pero virtual host. This all can be done by only one virtual host, even though you can have all the VH you need. Apache allows you to do many things with just one virtual host. For example, If you notice the directive SSL_Require, it is inside a LOCATIO

Re: Multiple CAs

2009-07-21 Thread Kobus Bensch
Title: Fullnet Solutions Limited Hi Thank you for this, this is great. So to recap. I have on CA That one CA can generate multiple Certs that can then be used per apache virtual host to allow only that one client to connect to that virtual host with a specified port number? End result = bet

Re: Multiple CAs

2009-07-21 Thread javierm
Kobus Bensch - No Sig wrote: > > They want a unique ca per client to be able to sign certs for each client > using their own CA. > Hi Kobus: CA allow CA chains, this is, only one CA being a true root signing sub-CA certs. Having many root CA's create the feeling of disorganization, though