Hands-on lab – setting up a Dogtag CA

Dogtag PKI is much simpler to set up, and it has a nice web interface that OpenSSL doesn't have. It's available in the normal repositories of Debian/Ubuntu and CentOS, but under different package names. In the Debian/Ubuntu repositories, the package name is dogtag-pki. In the CentOS repositories, the name is pki-ca. (For some reason that I don't understand, you'll never see Red Hat folk use the "Dogtag" name.)

Before we install the Dogtag packages, we need to do a couple of simple chores:

  • Set a Fully Qualified Domain Name (FQDN) on the server
  • Either create a record in a local DNS server for the Dogtag server, or create an entry for it in its own /etc/hosts file

This procedure should theoretically work ...

Get Mastering Linux Security and Hardening - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.