Skip to content

Import private key for external Certification Authorities #717

Answered by primetomas
oliviermartin asked this question in Q&A
Discussion options

You must be logged in to vote

Yes External really means that the CA is operated somewhere else. It is just an imported CA certificate to be able to use that to verify certificate chains (such as externally issued administrator certificates). As it's only a certificate you can naturally not use that to sign other certificates.
If you really want to migrate in a Ca, including the private key into EJBCA you use "importca". There are examples here. https://docs.keyfactor.com/ejbca/latest/migrating-from-other-cas-to-ejbca

If you plan to run everything in EJBCA I would recommend to separate User certificates from PKI administrator certificates. It makes for good role and trust separation. It is easy as you can set up as man…

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by oliviermartin
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants