Hi Rob,
I understand your arguments, however I also do not recommend using a 
self-signed CA either. For me it is a choice between a not-usable solution and 
something I can work with. 

I do wonder however how this will work when the serials slowly increase and get 
to such a large number. Apparently this has not happened in 10 yrs. How can we 
otherwise work around the issue that Firefox blocks the site? You cannot remove 
the certificate from the store, it is hidden somewhere deep inside...

Curious for other suggestions...
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam on the list, report it: 
https://pagure.io/fedora-infrastructure

Reply via email to