The following tasks will be provided by this package:
-
Generate CA certificate hierarchy and initials CRLs
-
Generate certificate requests with widely used web browsers
-
Search tool for client certificates in the OpenSSL certificate database
-
Download of client certificates / certificate revocation lists with appropriate MIME types
-
Online-validation of certificates
-
Storing all certificate data in LDAP repositories
-
Scripts for the handling of the certification process on a
non-networked system holding the CA's private key(s)
-
Fairly easy configuration based on the OpenSSL configuration file
(most times called openssl.cnf).
See the roadmap for a detailed list of what is still
to be done.