Re: [openssl-users] Revocation with a renewed/rekeyed Root CA

2011-10-17 Thread Erwann Abalea
I forgot to tell that I did these tests with version 1.0.0e. Le 17/10/2011 14:14, Erwann Abalea a écrit : Bonjour, While testing Apache-trunk (which will become apache 2.3.15), including the patch to use OpenSSL CRL validation, I've come to disagree with what OpenSSL does. My scheme is: -

Re: [openssl-users] RE: Revocation with a renewed/rekeyed Root CA

2011-10-17 Thread Erwann Abalea
Le 17/10/2011 16:09, Jakob Bohm a écrit : On 10/17/2011 3:47 PM, Erwann Abalea wrote: Le 17/10/2011 14:34, Eisenacher, Patrick a écrit : Hi Erwann, -Original Message- From: Erwann Abalea Bonjour, While testing Apache-trunk (which will become apache 2.3.15), including the patch to us

Re: [openssl-users] RE: Revocation with a renewed/rekeyed Root CA

2011-10-17 Thread Jakob Bohm
On 10/17/2011 3:47 PM, Erwann Abalea wrote: Le 17/10/2011 14:34, Eisenacher, Patrick a écrit : Hi Erwann, -Original Message- From: Erwann Abalea Bonjour, While testing Apache-trunk (which will become apache 2.3.15), including the patch to use OpenSSL CRL validation, I've come to disa

Re: [openssl-users] RE: Revocation with a renewed/rekeyed Root CA

2011-10-17 Thread Erwann Abalea
Le 17/10/2011 14:34, Eisenacher, Patrick a écrit : Hi Erwann, -Original Message- From: Erwann Abalea Bonjour, While testing Apache-trunk (which will become apache 2.3.15), including the patch to use OpenSSL CRL validation, I've come to disagree with what OpenSSL does. My scheme is:

RE: Revocation with a renewed/rekeyed Root CA

2011-10-17 Thread Eisenacher, Patrick
Hi Erwann, > -Original Message- > From: Erwann Abalea > > Bonjour, > > While testing Apache-trunk (which will become apache 2.3.15), > including > the patch to use OpenSSL CRL validation, I've come to > disagree with what > OpenSSL does. > > My scheme is: > - CA1 is a root (trust anchor)

Revocation with a renewed/rekeyed Root CA

2011-10-17 Thread Erwann Abalea
Bonjour, While testing Apache-trunk (which will become apache 2.3.15), including the patch to use OpenSSL CRL validation, I've come to disagree with what OpenSSL does. My scheme is: - CA1 is a root (trust anchor), which is now in its first generation (lets call it CA1g1) - U1, U2, U3 are

Re: Truststore

2011-10-17 Thread Jakob Bohm
On 10/14/2011 7:14 PM, Hopkins, Nathan wrote: Hi, what is a trustore please and how could I read one? A TrustStore is a list of trusted CA certificates, stored in a place where bad people cannot change it against your will. Different crypto libraries use different ways to store their truststo