> [[email protected] - Thu Dec 16 14:29:58 2010]: > > I was playing around with the 'nameopt' option of the x509 openssl > command and I think I've found a bug. I've read the man page for > x509 and can't see that I'm doign anything wrong... > > If I run "openssl x509 -text -noout -nameopt dn_rev -in AHam- > signed.pem" using the attached test certificate openssl starts to > prints out: > > Certificate: > Data: > Version: 3 (0x2) > Serial Number: 4126 (0x101e) > Signature Algorithm: sha1WithRSAEncryption > Issuer: > > stopping just before printing the issuer - presumably because > something is going wrong when using the dn_rev option. When I > remove the nameopt option, or use "-nameopt RFC2253" instead the > certificate text is printed out ok. > > I found the issue in version 0.9.8g but I've reproduced it in version > 1.0.0b. I've read the man page for x509 and can't see that I'm > doign anything wrong. >
The cause of this is that when you just use "dn_rev" you need to include a separator option (one of the sep_* options). This should be documented. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org ______________________________________________________________________ OpenSSL Project http://www.openssl.org Development Mailing List [email protected] Automated List Manager [email protected]
