Latest Release‎ > ‎

CA Options

The GridShib-CA comes with a simple OpenSSL-based CA, which is the easiest route for testing.

For production deployments you will probably want to deploy and configuration MyProxy on a different host as a CA. This will give you some protection in the event your web front end is compromised.

After installation, to complete deployment of the OpenSSL-based CA, you need to install the CA certificate and private key for the GridShib CA. Running the script utils/create-openssl-ca.pl will generate these automatically for you, creating a CA based on some defaults or the options you provided to configure.

After deploying a CA, proceed to Testing.
Subpages (1): MyProxy CA
Comments