Hi,

I'm setting up an OpenVPN client-server using OpenSSL 1.0.0 for cert
generation.

How do I set the nsCertType attribute to "server" in the server cert? I
mean, without using automated scripts like easy-rsa.

This is what I'm doing:

openssl genrsa -out serverkey.pem 4096

cd ..

openssl req -new -keyserverkey.pem -config $MYCONFDIR/openssl.cnf -subj
'/CN=myservername' -days 36500 -sha512 -out req.pem

openssl ca -config $MYCONFDIR/openssl.cnf -policy policy_anything -out
servercert.pem -md sha512 -cert cacert.pem -keyfile private/cakey.pem
-infiles req.pem
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [email protected]
Automated List Manager                           [email protected]

Reply via email to