Multiple CAs and CRLs
Easy-RSA 3.0 fairly easily supports multiple root CAs. By creating a separate CA directory under EASYRSA root, and having different vars files for each, each individual CA can be managed with Easy-RSA.
Currently, ssl-admin does not support multiple root CAs, but creation of intermediate CAs is supported.
With OpenVPN, a single server instance can support multiple root CAs, with client connections that have been signed by either CA being accepted. To enable such support, the CA certificate for each authorized CA needs to be concatenated together into a single file that can be called with the --ca OpenVPN option. The same can be done with the certificate revocation list.
Generally, it is not recommended to use multiple CA certificates ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access