Skip to content
Discussion options

You must be logged in to vote

What is your service using? I would expect a service to use one of the APIs of EJBCA. Most APIs have built in renewal support, i.e. CMP have key update, SCEP has renewal, EST have renewal. Using REST or WS, manual status swapping is not needed, but then renewal is performed by an RA so not the same use case.

Status "generated" is there in order to make the enrollment code a one-time code. Otherwise enrollment/renewal depends on the secrecy of the enrollment code, which is not the most secure way. You can configure EJBCA to not change NEW->GENERATED in several ways. One is "number of allowed request" in the EE profile, and the other is to uncheck "finish user" in the CA setting. In the las…

Replies: 2 comments 6 replies

Comment options

You must be logged in to vote
3 replies
@twardy103
Comment options

@twardy103
Comment options

@twardy103
Comment options

Answer selected by twardy103
Comment options

You must be logged in to vote
3 replies
@twardy103
Comment options

@primetomas
Comment options

@twardy103
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants