문제

i would like to simulate cross certification with XCA [0].

Like

Contoso Root CA

-> Contoso InterCA

-> Bob

Super Root

-> Bridge CA

-> X-Cert Contoso Root CA

-> Contoso InterCA

-> Bob

Creating single certs are not the problem, but im stucking at the point 'Contoso InterCA', because this ICA has two issuers - 'Contoso Root CA' and 'X-Cert Contoso Root CA'.

I really dont know how to realise this.

Thank you in advance!

best regards, Markus

[0] http://xca.sourceforge.net/

도움이 되었습니까?

해결책

There is no such things as two issuers in a certificate. The simple answer is that your ICA can have two certificates. One issued from 'Contoso Root CA' and one issued from 'X-Cert Contoso Root CA'. When clients are verifying the certificate chain, they will/should use the certificate that chains up to their trusted root, be it 'Contoso Root CA' or 'Super Root'.

라이센스 : CC-BY-SA ~와 함께 속성
제휴하지 않습니다 StackOverflow
scroll top