SYNOPSIS

ipa-getcert request [options] ipa-getcert resubmit [options] ipa-getcert start-tracking [options] ipa-getcert status [options] ipa-getcert stop-tracking [options] ipa-getcert list [options] ipa-getcert list-cas [options] ipa-getcert refresh-cas [options]

DESCRIPTION

The ipa-getcert tool issues requests to a org.fedorahosted.certmonger service on behalf of the invoking user. It can ask the service to begin enrollment, optionally generating a key pair to use, it can ask the service to begin monitoring a certificate in a specified location for expiration, and optionally to refresh it when expiration nears, it can list the set of certificates that the service is already monitoring, or it can list the set of CAs that the service is capable of using.

If no command is given as the first command-line argument, ipa-getcert will print short usage information for each of its functions.

The ipa-getcert tool behaves identically to the generic getcert tool when it is used with the -c IPA option.

certmonger supports retrieving trusted certificates from IPA CAs. See getcert-request(1) and getcert-resubmit(1) for information about using the -F and -a options to specify where those certificates should be stored.

BUGS

Please file tickets for any that you find at https://fedorahosted.org/certmonger/

RELATED TO ipa-getcert…