CA process and "old" cert.id

Hi,

We use hte CA process. Now I wonder how I can prevent the adminstrators from using the cert.id. We hava alot of people that stores the cert.id on different places (disket, fileserver, local on workstation maybe on USB … only God knows where). How can I just make these cert.id not working?

And if Shiu-Fun Poon will read this. Thanks for your demonstration “Domino 6 Certificate Authority” on 19 mars 2004. It was good.

My regards

Lars Öster

Subject: CA process and “old” cert.id

Thank you for attending it. :slight_smile:

We will consider this as an enhancement for future release (no promise here). Unfortunately, there is no way to prevent administrator from using cert.id after the certifier has been migrated to ca process today. :frowning:

ShiuFun

Subject: RE: CA process and “old” cert.id

Ok, there’s no way to prevent administrators from using the cert.id instead of the CA, but is there simply a way to prevent administrators from using an old cert.id? For a user it’s quite easy you can play with the password checking or the public key verification. Therefore there should be such a possibility within Domino, otherwise an ex administrator would be able to put a mess on your server as soon as he has access to your network (in the case of a server “open” on the net). I’m considering this possibility as a nonsense but I’ve been looking for an answer since quite a long time :frowning:

Thanks for you help on this point.

Best,

Thierry Soubestre

Subject: RE: CA process and “old” cert.id

Thanks for your quick answer!What I understand it’s important to not use the cert.id after it’s migrated to ca process. Why?

Regards

Lars Öster