About RIPE | Contact  | Search | Sitemap    
Homepage RIPE  
RIPE Community Mail Archives
search  
     
RIPE Navigation Ends
About RIPE Maillists
Maillists Archive
Global Lists
Non Active Lists
RIPE NCC Navigation Ends
Next Section
<<< Chronological >>> Author Index    Subject Index <<< Threads >>>

RE: [db-wg] Re: [ncc-services-wg] X.509 authentication in the RIPE Database

  • To: "'Patrik Fältström'" < >
    "'Kurt Erik Lindqvist'" < >
    < >
  • From: "Sanjaya" < >
  • Date: Mon, 14 Jul 2003 10:53:48 +1000

> On söndag, jul 13, 2003, at 10:48 Europe/Stockholm, Kurt Erik 
> Lindqvist 
> wrote:
> 
> >> In APNIC we use X.509 certificate to secure MyAPNIC (similar to LIR
> >> Portal). Having X.509 auth in the whois db would make a better
> >> integration with this facility.
> >
> > Is this then being widely used? No issues with client support and
> > configurations?
> 
> Do you have your own root-CA, or do you use someone else? If you have 
> your own, how do you distribute the certificate?
> 
>     paf

Hi Patrik,
Yes we run our own root-CA, and the first step is for the client
to install APNIC root CA in its trusted root store.

We're using the OpenCA software (www.openca.org) and modify
it to suit our purpose. When we issue a certificate, an e-mail
containing download url + instruction is sent to the requestor.

Cheers,
Sanjaya




  • Post To The List:
<<< Chronological >>> Author    Subject <<< Threads >>>
 

Next Section
     About RIPE | Site Map | LIR Portal | About the RIPE NCC | Contact | Copyright Statement
RIPE.NET Homepage LIR Portal RIPE Community