BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.devconf.info//devconf-cz-2026//talk//DJRXRD
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-devconf-cz-2026-DJRXRD@pretalx.devconf.info
DTSTART;TZID=CET:20260618T123000
DTEND;TZID=CET:20260618T135000
DESCRIPTION:X.509 certificates are vital for Internet security\, yet their 
 inner workings often remain a mystery. This intermediate workshop moves be
 yond the "black box" to provide practical skills in Public Key Infrastruct
 ure (**PKI**) and certificate management using **FreeIPA**.\n\nAttendees w
 ill explore diverse use cases\, including WebPKI\, Smart Card auth\, Kerbe
 ros PKINIT\, and 802.1X EAP\, essential for system administrators or DevOp
 s engineers.\n\n**Hands-on topics include:**\n* PKI fundamentals and X.509
  anatomy.\n* Using **OpenSSL** to generate keys and CSRs.\n* **ACME** (Let
 's Encrypt) and FreeIPA issuance.\n* Configuring certificate profiles\, su
 b-CAs\, and enabling ACME.\n* External signing and renewal of the FreeIPA 
 CA.\n* Linux Smart Card authentication and host configuration.\n* Future t
 rends: Certificate Transparency and Post-Quantum cryptography.\n\n**Prereq
 uisites:** Participants will access a cloud lab and will only need an **SS
 H client** and to be comfortable with the **Unix command line**.
DTSTAMP:20260430T130932Z
LOCATION:C228 (capacity 24)
SUMMARY:Practical PKI: A hands-on X.509 workshop - Alessandro Garagnani
URL:https://pretalx.devconf.info/devconf-cz-2026/talk/DJRXRD/
END:VEVENT
END:VCALENDAR
