End-to-end HTTPS kickstart process with custom internal CAs
Hello Group,
We use an internal root & intermediate CA infrastructure for our SSL needs, rather than buying public root CA signed certs for all of our hosts. I suspect this is a rather common practice for other small-to-midsize enterprises using RedHat RHN Satellite, so I figured I'd ask a question and offer a howto if there exists the need:
Question: Is there a 'standard' (or automated) way of integrating custom CAs into the HTTPS kickstart process that I missed in the main documentation?
(This includes the initrd.img on the boot ISO/CD, and the install.img in the kickstart build tree)
Follow up offer: If there is not already a documented how-to for enabling end-to-end SSL kickstart builds with custom CA infra, post a reply so that I know there is interest enough in putting together a howto and I'll post how we're doing it at my organization.
Thanks,
- Kodiak Firesmith
Responses