Hi Craig,
Just wanted to thank you for sharing all that - I was able to get my own code working off it. For posterity, I also had to set the indirect CRL Issuer's SubjectName to be the same as its CA, for which it's issuing the CRLs for. This is OK for my use-case, but it does restrict the ability to have a CRL Issuer for more than one CA, as others may need. Cheers, Kent ______________________________________________________________________ OpenSSL Project http://www.openssl.org Development Mailing List [email protected] Automated List Manager [email protected]
