I tried installing CA on fedora 20 with customized parameters for SSL Server Cert and it failed to get the SSl Service up since the nickname of the certificate was customized by me and the serverCertNick.conf file was updated with the default nickname of the SSLServer Certificate which is specified in the /etc/pki/default.cfg file.
Per email discussions, propose Milestone 10.2 (July).
After changing the pki_ssl_server_subject_dn=cn=ipaqa64vmg.idmqe.lab.eng.bos.redhat.com,o=Redhat to this, from pki_ssl_server_subject_dn=cn=Pki SSL Server Cert,o=Redhat, I could customize the other parameters like the nickname, signing algorithm, etc. The constraint for the SSL Server Certificate is that for the subject dn, the common name should always be the hostname, after which you can customize the other parameters.
Metadata Update from @saipandi: - Issue assigned to vakwetu - Issue set to the milestone: 10.2 - 08/14 (August)
Dogtag PKI is moving from Pagure issues to GitHub issues. This means that existing or new issues will be reported and tracked through Dogtag PKI's GitHub Issue tracker.
This issue has been cloned to GitHub and is available here: https://github.com/dogtagpki/pki/issues/1617
If you want to receive further updates on the issue, please navigate to the GitHub issue and click on Subscribe button.
Subscribe
Thank you for understanding, and we apologize for any inconvenience.