Skip to content

On initial generation, a self-signed cert should be generated #3

@arusso

Description

@arusso

Initially, before a signed cert is installed, a self-signed cert should be installed to allow for things depending on it's existence to still run (ie. Apache, Stunnel, etc). Since we submit the CSR generated by this class, under normal circumstances, we will never have a cert ready for the apache/stunnel/etc to read and load. This causes the puppet runs to fail if the service depends on it, and it is managed in puppet.

An option for also generating a loadable intermediate cert should be available as well, even if it's just copying the self-signed cert to the intermediate.crt.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions