Re: how to sign CRMF/SPKAC using openssl

2009-05-29 Thread tito
hii thanx a lot Georgi... im new to php..just for my info , > $keyreq = "SPKAC=".str_replace(str_split(" \t\n\r\0\x0B"), '', $key); > this code removes newline chars ?? i did generate the spkac string and put in openssl bin directory..but im getting some error..probably due to my openssl CA set

Re: how to sign CRMF/SPKAC using openssl

2009-05-29 Thread Georgi Guninski
On Fri, May 29, 2009 at 01:09:13PM +0530, tito wrote: > plz see my command here.. > C:\OpenSSL\bin>openssl ca -config openssl.cnf -verbose -days 180 -notext > > -batch -spkac spak1.txt -out spaksign.pem -passin pass:mypass > > Using configuration from openssl.cnf > > error loading the config file '

Re: how to sign CRMF/SPKAC using openssl

2009-05-29 Thread tito
thank you for the info.. 2009/5/29 Georgi Guninski > On Fri, May 29, 2009 at 01:09:13PM +0530, tito wrote: > > plz see my command here.. > > C:\OpenSSL\bin>openssl ca -config openssl.cnf -verbose -days 180 -notext > > > -batch -spkac spak1.txt -out spaksign.pem -passin pass:mypass > > > Using co

Re: Roots that are identical except for signature algorithm and serial number

2009-05-29 Thread Nelson B Bolyard
On 2009-05-28 13:09 PDT, Frank Hecker wrote: > Nelson B Bolyard wrote: >> An SSL server that sends out a full chain with a SHA256 root could >> conceivably cause a problem for a remote SSL client that does not understand >> SHA256 signatures and that chooses to check the signature on the received >

Re: how to sign CRMF/SPKAC using openssl

2009-05-29 Thread Nelson B Bolyard
On 2009-05-28 21:51 PDT, tito wrote: > I am making a CA site for my college project purpose.I learned that > different browsers use different methods to generate CSR.Making CSR in > IE was easy.For vista systems I used CertEnroll.dll methods and for > non-vista IE i used xenroll.dll.I generated CS

Re: Roots that are identical except for signature algorithm and serial number

2009-05-29 Thread Rick Andrews
On May 28, 3:12 pm, Nelson B Bolyard wrote: > On 2009-05-28 10:52 PDT, Kathleen Wilson wrote: > > > Just to make sure I understand… > > > In the VeriSign case the MD2 roots expire on 2028-08-01, and the SHA1 > > roots expire on 2028-08-02, so the SHA1 roots would take precedence in > > NSS.  There

Re: Finnish Population Register Root Inclusion Request

2009-05-29 Thread Nelson Bolyard
On 2009-05-28 14:02 PDT, Kyle Hamilton wrote: > Nelson, a question for you: Which extendedKeyUsage OIDs are checked > for each of the three trust bits? Is this part of PSM, or NSS? The answer is found in this web page: http://www.mozilla.org/projects/security/pki/nss/tech-notes/tn3.html Since t

Re: Roots that are identical except for signature algorithm and serial number

2009-05-29 Thread Nelson B Bolyard
On 2009-05-29 09:22 PDT, Rick Andrews wrote: > On May 28, 3:12 pm, Nelson B Bolyard wrote: >> On 2009-05-28 10:52 PDT, Kathleen Wilson wrote: >> >>> Just to make sure I understand… >>> In the VeriSign case the MD2 roots expire on 2028-08-01, and the SHA1 >>> roots expire on 2028-08-02, so the SHA1