Choice of CA

Ti Leggett leggett at mcs.anl.gov
Wed May 7 18:37:36 CDT 2003


Because I wasn't able to be in the meeting to discuss our role as a CA,
I thought I'd get discussion here. I'd like to hear the reason(s) why
we've decided to go with OpenCA. Below I'm listing pros and cons for
what I think are our two options.

OpenCA Pros:
Established base and community
Fairly feature rich

OpenCA Cons:
Someone else's perl code
Clumsy to use
Very poor documentation (even for an SSL program)

Roll-Your-Own Pros:
Build only what we need
Build what we need how we need it
using php should be more readable to future users

Roll-Your-Own Cons:
We have to build our own from scratch

As it stands now I'm not fully convinced that OpenCA will take less time
to configure to our needs than it would to build our own needs. And I'm
not convinced that if we get it close to what we want it'll ever do what
we want exactly.

That being said, I am forging ahead with OpenCA while this is discussed.

Please add pros and cons where needed or explain why you think one
listed shouldn't be as listed.




More information about the ag-dev mailing list