Re: [Openca-Users] Certificate Renewal Question

2003-02-07 Thread silverhairbp
Lutz Jaenicke wrote: > Hi! > > I am using OpenCA 0.9.1 (RC something). The first certificates created > with OpenCA (an older version) are going to expire soon. How do I handle > certificate renewal? If I supply a new request for the same key, OpenCA > does not allow generation of a new certific

Re: [Openca-Users] Certificate Renewal Question

2003-02-07 Thread Michael Bell
Lutz Jaenicke wrote: On Fri, Feb 07, 2003 at 05:39:21PM +0100, Michael Bell wrote: ... I think the following about the options: - 3 and 4 are obsolete - 2 is the best way but you have to patch OpenSSL - 1 is the default way if you can accept another DN for the new certs I hope one of these

[Openca-Users] CA initialization

2003-02-07 Thread Cecilia Cabrera
Hi, i installed openca-0.9.1 in a NEtBSD. When i want to initialize the CA i can't generate the pair of keys. It asks the encription algorithm and the key size but after that does nothing. I did the database initialization befor this, but i had to copy the DB.conf that comes with the source in /u

Re: [Openca-Users] Certificate Renewal Question

2003-02-07 Thread Lutz Jaenicke
On Fri, Feb 07, 2003 at 05:39:21PM +0100, Michael Bell wrote: > OpenCA includes a mechanism to be protected against keycompromising by > bad random numbergenerators. If you need a new cert for the same key > then please go to the old request (now archived request). There is a > renew button. Ah

Re: [Openca-Users] Certificate Renewal Question

2003-02-07 Thread Michael Bell
Lutz Jaenicke wrote: I am using OpenCA 0.9.1 (RC something). The first certificates created with OpenCA (an older version) are going to expire soon. How do I handle certificate renewal? If I supply a new request for the same key, OpenCA does not allow generation of a new certificate... OpenCA i

[Openca-Users] Certificate Renewal Question

2003-02-07 Thread Lutz Jaenicke
Hi! I am using OpenCA 0.9.1 (RC something). The first certificates created with OpenCA (an older version) are going to expire soon. How do I handle certificate renewal? If I supply a new request for the same key, OpenCA does not allow generation of a new certificate... Best regards, Lutz

Re: [Openca-Users] Strange behavior using X.509 certificates andSSHSentinel

2003-02-07 Thread Michael Bell
Jason A. Pattie wrote: While upgrading a client to use OpenCA to generate certificates, we ran into a problem. The OpenCA certificates that were generated for the users did not contain e-mail addresses in the Subject. We used the batch processor available in OpenCA to generate certificates for