PKI 9 Installing CA with Random Serial Numbers v1 - dogtagpki/pki GitHub Wiki

Overview

This page describes the process to install a CA subsystem with Random Serial Numbers v1 in PKI 9.

Installation Procedure

  • Run pkicreate

  • Stop CA

  • Update CA’s CS.cfg file by setting:

dbs.enableSerialManagement=true
dbs.enableRandomSerialNumbers=true
dbs.randomSerialNumberCounter=0
  • Start CA

  • Run CA’s configuration wizard

Random certificate serial numbers are inherited via CA cloning, so CA clones require no special configuration.

CA with Random Serial Numbers
⚠️ **GitHub.com Fallback** ⚠️