Download (untitled) / with headers
Improve PKINIT certificate documentation
Describe how to use a commercially-issued server certificate for
anonymous PKINIT. Separate the KDC and client configuration
instructions so that the steps necessary for anonymous PKINIT are not
combined with the additional steps necessary for regular PKINIT.
Describe kpServerAuth as the EKU used in commercially issued server
certificates, not as the value used by Microsoft (which does not
appear to be true according to [MS-PKCA]).
Author: Greg Hudson <email@example.com>
doc/admin/conf_files/krb5_conf.rst | 3 +-
doc/admin/pkinit.rst | 117 ++++++++++++++++++++++++++----------
2 files changed, 86 insertions(+), 34 deletions(-)