File: certmonger-ipa-submit.8.in

package info (click to toggle)
certmonger 0.75.14-3
  • links: PTS, VCS
  • area: main
  • in suites: jessie, jessie-kfreebsd
  • size: 8,540 kB
  • ctags: 2,176
  • sloc: ansic: 41,340; sh: 9,551; makefile: 528; python: 207; xml: 190; sed: 16
file content (104 lines) | stat: -rw-r--r-- 3,685 bytes parent folder | download
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
.TH certmonger 8 "7 June 2010" "certmonger Manual"

.SH NAME
ipa-submit

.SH SYNOPSIS
ipa-submit [-h serverHost] [-H serverURL] [-c cafile] [-C capath]
[[-K]  | [-t keytab] [-k submitterPrincipal]] [-P principalOfRequest] [csrfile]

.SH DESCRIPTION
\fIipa-submit\fR is the helper which \fIcertmonger\fR uses to make
requests to IPA-based CAs.  It is not normally run interactively,
but it can be for troubleshooting purposes.  The signing request which is
to be submitted should either be in a file whose name is given as an argument,
or fed into \fIipa-submit\fR via stdin.

\fBcertmonger\fR supports retrieving trusted certificates from IPA CAs.  See
\fBgetcert-request\fR(1) and \fBgetcert-resubmit\fR(1) for information about
specifying where those certificates should be stored on the local system.
Trusted certificates are retrieved from the \fBcaCertificate\fR attribute of
entries present at and below \fIcn=cacert,cn=ipa,cn=etc,\fR$BASE in the IPA
LDAP server's directory tree, where $BASE defaults to the value of the
\fBbasedn\fR setting in \fB/etc/ipa/default.conf\fR.

.SH OPTIONS
.TP
\fB\-P\fR csrPrincipal
Identifies the principal name of the service for which the certificate is being
issued.  This setting is required by IPA and must always be specified.
.TP
\fB\-h\fR serverHost
Submit the request to the IPA server running on the named host.  The default is
to read the location of the host from \fB/etc/ipa/default.conf\fR.
.TP
\fB\-H\fR serverURL
Submit the request to the IPA server at the specified location.  The default is
to read the location of the host from \fB/etc/ipa/default.conf\fR.
.TP
\fB\-c\fR cafile
The server's certificate was issued by the CA whose certificate is in the named
file.  The default value is \fI/etc/ipa/ca.crt\fR.
.TP
\fB\-C\fR capath
Trust the server if its certificate was issued by a CA whose certificate is in
a file in the named directory.  There is no default for this option, and it
is not expected to be necessary.
.TP
\fB\-t\fR keytab
Authenticate to the IPA server using credentials derived from keys stored in
the named keytab.  The default value can vary, but it is usually
\fI/etc/krb5.keytab\fR.
This option conflicts with the \fB-K\fR option.
.TP
\fB\-k\fR authPrincipal
Authenticate to the IPA server using credentials derived from keys stored in
the named keytab for this principal name.  The default value is the \fBhost\fR
service for the local host in the local realm.
This option conflicts with the \fB-K\fR option.
.TP
\fB\-K\fR
Authenticate to the IPA server using credentials derived from the default
credential cache rather than a keytab.
This option conflicts with the \fB-k\fR option.

.SH EXIT STATUS
.TP
0
if the certificate was issued. The certificate will be printed.
.TP
1
if the CA is still thinking.  A cookie value will be printed.
.TP
2
if the CA rejected the request.  An error message may be printed.
.TP
3
if the CA was unreachable.  An error message may be printed.
.TP
4
if critical configuration information is missing.  An error message may be printed.

.SH FILES
.TP
.I /etc/ipa/default.conf
is the IPA client configuration file.  This file is consulted to determine
the URL for the IPA server's XML-RPC interface.

.SH BUGS
Please file tickets for any that you find at https://fedorahosted.org/certmonger/

.SH SEE ALSO
\fBcertmonger\fR(8)
\fBgetcert\fR(1)
\fBgetcert-list\fR(1)
\fBgetcert-list-cas\fR(1)
\fBgetcert-request\fR(1)
\fBgetcert-refresh-ca\fR(1)
\fBgetcert-resubmit\fR(1)
\fBgetcert-start-tracking\fR(1)
\fBgetcert-status\fR(1)
\fBgetcert-stop-tracking\fR(1)
\fBcertmonger-dogtag-ipa-renew-agent-submit\fR(8)
\fBcertmonger-certmaster-submit\fR(8)
\fBcertmonger_selinux\fR(8)