Bug 742611

Summary: Make documentation more explicit about the difference between dogtag/self-signed/external CA
Product: Red Hat Enterprise Linux 6 Reporter: Benjamin Reed <ranger>
Component: doc-Identity_Management_GuideAssignee: Deon Ballard <dlackey>
Status: CLOSED CURRENTRELEASE QA Contact: ecs-bugs
Severity: high Docs Contact:
Priority: high    
Version: 6.1CC: dpal, jskeoch, mkosek, pkennedy, syeghiay
Target Milestone: rcKeywords: Documentation
Target Release: ---   
Hardware: All   
OS: All   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2012-01-06 22:07:20 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description Benjamin Reed 2011-09-30 18:37:44 UTC
The way the documentation is written, it's not clear that you have *3* choices when determining how to set up your CAs, rather than 2.  Not knowing what dogtag was, it was not clear that it was an alternative to a self-signed certificate.  So, I had interpreted this wording:

  For the FreeIPA server itself to work as a CA, it uses a self-signed certificate,
  meaning that it approved and issued its own certificate. This is done by using
  the --selfsign option with the ipa-server-install command.

...to mean that if I'm not using an external certificate from VeriSign or similar, that I would need to instead use the self-sign option, when what I should have done was provided no option at all.

It would be better if the documentation was clearer about CA options, ie:

* 2.3.3.2. Using Different CAs
** Example 1 Using Dogtag for Certificate Management (Recommended)
** Example 2 Using a self-signed certificate
** Example 3 Using a certificate from an External CA

Comment 2 Dmitri Pal 2011-09-30 18:58:15 UTC
I suggest we make the documentation clear about this. I also will open another bug to update man pages.

Comment 3 Deon Ballard 2011-09-30 19:05:03 UTC
The man page bug is bug 742616, for reference.

Comment 4 Deon Ballard 2011-10-20 20:33:11 UTC
*** Bug 747671 has been marked as a duplicate of this bug. ***