Skip to content

step certificate lint errors on out-of-the-box certs #1302

Answered by maraino
MacWeber asked this question in Q&A
Discussion options

You must be logged in to vote

Hi @MacWeber, the lint functionality is mainly intended for Web PKI, the public web, not an internal one like step-ca is used for. But it is possible to alleviate some of those errors or warnings with templates.

If you create the root and intermediates yourself using step certificate create with a template that contains some of the recommended fields like the subject.country. Others, like OCSP, are only supported in our commercial offering, but there are ways to convert a CRL that is supported to an OCSP responder, so you can implement those and set the proper template. The CRL is supported for leaf certificates only, but it is not enabled as default, but if enabled, leaf certificates wil…

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by MacWeber
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants