Dogtag PKI is much simpler to set up, and it has a nice web interface that OpenSSL doesn't have. It's available in the normal repositories of Debian/Ubuntu and CentOS, but under different package names. In the Debian/Ubuntu repositories, the package name is dogtag-pki. In the CentOS repositories, the name is pki-ca. (For some reason that I don't understand, you'll never see Red Hat folk use the "Dogtag" name.)
Before we install the Dogtag packages, we need to do a couple of simple chores:
- Set a Fully Qualified Domain Name (FQDN) on the server
- Either create a record in a local DNS server for the Dogtag server, or create an entry for it in its own /etc/hosts file
This procedure should theoretically work ...