Re: [openssl.org #3097] Incorrect revocation status with indirect CRL

2013-12-20 Thread Kent Watsen via RT
Hi Craig, Just wanted to thank you for sharing all that - I was able to get my own code working off it. For posterity, I also had to set the indirect CRL Issuer's SubjectName to be the same as its CA, for which it's issuing the CRLs for. This is OK for my use-case, but it does restrict the

Re: [openssl.org #3097] Incorrect revocation status with indirect CRL

2013-11-26 Thread Kent Watsen via RT
Hi Craig, I'm trying to do the same - can you share either the openssl.cnf files or the cert/crl files the enabled you to get this working? The examples you provided in the thread were for Stephen Henson's, but I want to try the more official route... Thanks, Kent I also managed to get my