[openssl.org #2732] Bug: verification fails if muliple certification path (EV/Verisign)

2012-03-06 Thread Dan Lukes via RT
Same problem apply for cross-certificates which create multiple paths also. Imagine the expiring CA (expiring within year or two, not expired already). The organization will create the new one, but want to maintain transition period for the users. So create two cross certificates - the public

[openssl.org #1588] Already resolved in other ticket, please close

2012-03-06 Thread Dan Lukes via RT
Same issue has been reported and resolved in #1624. This report can be closed. Dan __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.or

[openssl.org #2754] Ugly interaction of (openssl x509)'s option -x509toreq with -outform/-text/-noout

2012-03-05 Thread Dan Lukes via RT
About year ago, the apps/x509.c has been patched not to ignore -keyform during -x509toreq operation. IMHO it's proper time to patch not to ignore other options as well. All following text is related to "openssl req -x509toreq" call. Current behavior: 1. -outform is ignored, PEM format used all

[openssl.org #1588] Bug report with PATCH

2007-10-15 Thread Dan Lukes via RT
>Synopsis: /dev/crypto broken on FreeBSD >Class: sw-bug >OS Release: FreeBSD 6.2-RELEASE-p8 i386 >OpenSSL Release: All OpenSSL releases based on crypto/engine/eng_cryptodev.c v.1.5 and newer (tested on 0.9.8e) >Description: The problem check-in #11541 http://cvs

[openssl.org #912] Re: [PATCH] Back-translation of CA.pl into CA.sh

2004-07-04 Thread Dan Lukes via RT
Stephen Henson via RT wrote: >>I back-translated the current version of CA.pl back into CA.sh. ... >> there are no reason for using as strong tool as perl for this simple task > There is at least one reason for the perl translation. Some of the many > platforms OpenSSL compiles on have will h