easy-rsa
                                
                                 easy-rsa copied to clipboard
                                
                                    easy-rsa copied to clipboard
                            
                            
                            
                        init-pki: Option SOFT, keep certificate signing requests
This allows a new CA to sign certificates "in the field".
No matter how you renew a CA, this still requires that the client update their certificates.
However, all of the updates required here are public data and can be shared openly.
The idea of keeping CSR's is good but I think this may be better as (yet another) option:
- eg: easyrsa init-pki rebuild-pki
This is intended for use by a new CA, to sign valid certifcates "in the field".
The command above could simply be: easyrsa rebuild-pki