3 ms·
At every enterprise job I have been in, there was always a quagmire around renewing or exchanging certificates. The corresponding tasks always required disprop
by fzeindl 2y ago
At every enterprise job I have been in, there was always a quagmire around renewing or exchanging certificates.
The corresponding tasks always required disproportionately many high-level meetings and discussions for their actual simplicity.
I always attributed this directly to the complexity of the OpenSSL command and the fact that these tasks include hard deadlines because of certificate runtime.
The complex discussions which ultimately result in some simple commands mirror the OpenSSL CLI: you have to understand and articulate precisely what you need.
That being said I wonder some of the options (like "this file is a CER", PEM vs DER private key, etc.) couldn't be replaced by auto detection.