<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Create an SSL Certificate Authority on Linux and Use It in Windows AD</title>
	<atom:link href="http://www.jwnetworkconsulting.com/windows/create-an-ssl-certificate-authority-on-linux-and-use-it-in-windows-ad/feed" rel="self" type="application/rss+xml" />
	<link>http://www.jwnetworkconsulting.com/windows/create-an-ssl-certificate-authority-on-linux-and-use-it-in-windows-ad</link>
	<description>Watching the network so you don't have to.</description>
	<lastBuildDate>Fri, 18 Dec 2009 21:26:16 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: Paul</title>
		<link>http://www.jwnetworkconsulting.com/windows/create-an-ssl-certificate-authority-on-linux-and-use-it-in-windows-ad/comment-page-1#comment-13</link>
		<dc:creator>Paul</dc:creator>
		<pubDate>Sun, 15 Nov 2009 09:29:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.sysadmins.info/?p=124#comment-13</guid>
		<description>hey great article, how do i reverse this and a) take a windows created root authority cert and install it on linux for openssl to use during secure sockets operations (not apache).</description>
		<content:encoded><![CDATA[<p>hey great article, how do i reverse this and a) take a windows created root authority cert and install it on linux for openssl to use during secure sockets operations (not apache).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tomas</title>
		<link>http://www.jwnetworkconsulting.com/windows/create-an-ssl-certificate-authority-on-linux-and-use-it-in-windows-ad/comment-page-1#comment-12</link>
		<dc:creator>Tomas</dc:creator>
		<pubDate>Tue, 10 Nov 2009 19:33:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.sysadmins.info/?p=124#comment-12</guid>
		<description>Hi,
is possible somehow use user-certificates in AD from linux CA?
I have linux CA, imported into AD, I have created user-certificates and want to add them to each user in AD .. is is possible or not?</description>
		<content:encoded><![CDATA[<p>Hi,<br />
is possible somehow use user-certificates in AD from linux CA?<br />
I have linux CA, imported into AD, I have created user-certificates and want to add them to each user in AD .. is is possible or not?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jason</title>
		<link>http://www.jwnetworkconsulting.com/windows/create-an-ssl-certificate-authority-on-linux-and-use-it-in-windows-ad/comment-page-1#comment-11</link>
		<dc:creator>Jason</dc:creator>
		<pubDate>Wed, 21 Oct 2009 03:52:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.sysadmins.info/?p=124#comment-11</guid>
		<description>Hi Robert,
The honest answer is that I don&#039;t know.  You are going a lot further with your deployment than I had to with mine.  I&#039;ve never tried to use the Windows Certificate Services, so while I can&#039;t see why you couldn&#039;t, I really don&#039;t know for sure.  I&#039;d have to play with that for a while to find out.  Or you can and let us know how it goes.  :)

Jason</description>
		<content:encoded><![CDATA[<p>Hi Robert,<br />
The honest answer is that I don&#8217;t know.  You are going a lot further with your deployment than I had to with mine.  I&#8217;ve never tried to use the Windows Certificate Services, so while I can&#8217;t see why you couldn&#8217;t, I really don&#8217;t know for sure.  I&#8217;d have to play with that for a while to find out.  Or you can and let us know how it goes.  <img src='http://www.jwnetworkconsulting.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Jason</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert</title>
		<link>http://www.jwnetworkconsulting.com/windows/create-an-ssl-certificate-authority-on-linux-and-use-it-in-windows-ad/comment-page-1#comment-10</link>
		<dc:creator>Robert</dc:creator>
		<pubDate>Tue, 20 Oct 2009 20:23:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.sysadmins.info/?p=124#comment-10</guid>
		<description>jason,

I would like to implement a PKI hierarchy that consists of 2 levels or more, a offline root CA and additional subordinate CA’s that require access to the root CA.  As the distance from the root CA increases more levels may be needed.  If my (offline) Root is a Linux CA server that works in Windows AD, and I copy the ca.crt to your Windows AD domain controller, rename the text file and change the extension to .cer so that it can be used as an SSL certificate, import the CA Certificate to Windows Active Directory, use Group Policy to make this certificate authority a trusted CA through out the domain, can online issuing subordinate CA’s be any additional domain controllers within the domain?</description>
		<content:encoded><![CDATA[<p>jason,</p>
<p>I would like to implement a PKI hierarchy that consists of 2 levels or more, a offline root CA and additional subordinate CA’s that require access to the root CA.  As the distance from the root CA increases more levels may be needed.  If my (offline) Root is a Linux CA server that works in Windows AD, and I copy the ca.crt to your Windows AD domain controller, rename the text file and change the extension to .cer so that it can be used as an SSL certificate, import the CA Certificate to Windows Active Directory, use Group Policy to make this certificate authority a trusted CA through out the domain, can online issuing subordinate CA’s be any additional domain controllers within the domain?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jason</title>
		<link>http://www.jwnetworkconsulting.com/windows/create-an-ssl-certificate-authority-on-linux-and-use-it-in-windows-ad/comment-page-1#comment-7</link>
		<dc:creator>Jason</dc:creator>
		<pubDate>Sat, 21 Mar 2009 16:22:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.sysadmins.info/?p=124#comment-7</guid>
		<description>Khalid,
I&#039;m not sure.  PHP isn&#039;t really my thing.  A guess would be that the command is waiting for user input, but since you have things setup in your openssl.conf file I&#039;m not sure if that would be the case.  I&#039;d ask one of the PHP forums to see what they think.

Good luck.</description>
		<content:encoded><![CDATA[<p>Khalid,<br />
I&#8217;m not sure.  PHP isn&#8217;t really my thing.  A guess would be that the command is waiting for user input, but since you have things setup in your openssl.conf file I&#8217;m not sure if that would be the case.  I&#8217;d ask one of the PHP forums to see what they think.</p>
<p>Good luck.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: khalid</title>
		<link>http://www.jwnetworkconsulting.com/windows/create-an-ssl-certificate-authority-on-linux-and-use-it-in-windows-ad/comment-page-1#comment-6</link>
		<dc:creator>khalid</dc:creator>
		<pubDate>Sat, 21 Mar 2009 12:09:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.sysadmins.info/?p=124#comment-6</guid>
		<description>hi. i am trying to use sudo to execute openssl commands in php program. the commands doesn&#039;t respond. while the same commands work well in the terminal. the command is as follow.
exec(&quot;openssl req -config /etc/pki_jungle/myCA/openssl.my.cnf -new -keyout /etc/pki_jungle/myCA/private/server.key -nodes -out /etc/pki_jungle/myCA/server.csr -days 365&quot;);
the configuration file openssl.my.cnf is modified so that the creation of the signing request is batched and no further input is needed. what is the problem?</description>
		<content:encoded><![CDATA[<p>hi. i am trying to use sudo to execute openssl commands in php program. the commands doesn&#8217;t respond. while the same commands work well in the terminal. the command is as follow.<br />
exec(&#8220;openssl req -config /etc/pki_jungle/myCA/openssl.my.cnf -new -keyout /etc/pki_jungle/myCA/private/server.key -nodes -out /etc/pki_jungle/myCA/server.csr -days 365&#8243;);<br />
the configuration file openssl.my.cnf is modified so that the creation of the signing request is batched and no further input is needed. what is the problem?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: syed</title>
		<link>http://www.jwnetworkconsulting.com/windows/create-an-ssl-certificate-authority-on-linux-and-use-it-in-windows-ad/comment-page-1#comment-5</link>
		<dc:creator>syed</dc:creator>
		<pubDate>Tue, 17 Feb 2009 17:12:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.sysadmins.info/?p=124#comment-5</guid>
		<description>works perfectly on red hat 5

so far so good</description>
		<content:encoded><![CDATA[<p>works perfectly on red hat 5</p>
<p>so far so good</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jason</title>
		<link>http://www.jwnetworkconsulting.com/windows/create-an-ssl-certificate-authority-on-linux-and-use-it-in-windows-ad/comment-page-1#comment-4</link>
		<dc:creator>Jason</dc:creator>
		<pubDate>Thu, 12 Feb 2009 08:15:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.sysadmins.info/?p=124#comment-4</guid>
		<description>Hello Swordfish.  Sure, you could do that.  I&#039;m not sure what advantage you would gain for having 10 different CAs for 10 different web servers, but you could just change the openssl command to use different file names for the key and other output files.  For example:

sudo openssl genrsa -des3 -out ca.key 4096

becomes

sudo openssl genrsa -des3 -out ca2.key 4096
sudo openssl genrsa -des3 -out ca3.key 4096
etc...

And:

sudo openssl req -new -x509 -days 365 -key ca.key -out ca.crt

Becomes:

sudo openssl req -new -x509 -days 365 -key ca2.key -out ca2.crt
sudo openssl req -new -x509 -days 365 -key ca3.key -out ca3.crt

I&#039;d use different common names in each CA certificate so you could tell them apart that way too.</description>
		<content:encoded><![CDATA[<p>Hello Swordfish.  Sure, you could do that.  I&#8217;m not sure what advantage you would gain for having 10 different CAs for 10 different web servers, but you could just change the openssl command to use different file names for the key and other output files.  For example:</p>
<p>sudo openssl genrsa -des3 -out ca.key 4096</p>
<p>becomes</p>
<p>sudo openssl genrsa -des3 -out ca2.key 4096<br />
sudo openssl genrsa -des3 -out ca3.key 4096<br />
etc&#8230;</p>
<p>And:</p>
<p>sudo openssl req -new -x509 -days 365 -key ca.key -out ca.crt</p>
<p>Becomes:</p>
<p>sudo openssl req -new -x509 -days 365 -key ca2.key -out ca2.crt<br />
sudo openssl req -new -x509 -days 365 -key ca3.key -out ca3.crt</p>
<p>I&#8217;d use different common names in each CA certificate so you could tell them apart that way too.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: swordfish</title>
		<link>http://www.jwnetworkconsulting.com/windows/create-an-ssl-certificate-authority-on-linux-and-use-it-in-windows-ad/comment-page-1#comment-3</link>
		<dc:creator>swordfish</dc:creator>
		<pubDate>Wed, 11 Feb 2009 21:38:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.sysadmins.info/?p=124#comment-3</guid>
		<description>hi i am swordfish, can i create more CA in the linux box which can be use on different web servers. example i have 10 webservers and i want to generate 10 CA so that each server have there own CA... 

thank you ,, very much and i could appreciate if you response asap ,,,</description>
		<content:encoded><![CDATA[<p>hi i am swordfish, can i create more CA in the linux box which can be use on different web servers. example i have 10 webservers and i want to generate 10 CA so that each server have there own CA&#8230; </p>
<p>thank you ,, very much and i could appreciate if you response asap ,,,</p>
]]></content:encoded>
	</item>
</channel>
</rss>
