Leaf certificate for "Step Online CA" #418
-
Subject of the issueWhen step-ca is started, it seems to generate a new leaf certificate for itself. The subject is "Step Online CA" and it is issued by the intermediate cert. Can we influence the generation of this certificate at all? For example changing the subject, or the validity (valid from / valid to) dates? I have already configured |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 4 replies
-
Hi there, Yes, the Could you give me a bit more context on your situation, and why you're wanting to change the CA's TLS certificate parameters? If your subscribers trust the CA certificate, the short-lived leaf certificate generated by the CA should always be trusted. |
Beta Was this translation helpful? Give feedback.
-
@Jcpetrucci the duration of the Right now you cannot configure the duration, and you cannot pre-create a certificate to use. If you think any of those are important, I'll suggest creating an enhancement issue. |
Beta Was this translation helpful? Give feedback.
Hi there,
Yes, the
claims
andminTLSCertDuration
only apply to certificates created by the provisioner.Could you give me a bit more context on your situation, and why you're wanting to change the CA's TLS certificate parameters?
If your subscribers trust the CA certificate, the short-lived leaf certificate generated by the CA should always be trusted.