Hi,

I am still stuck on the phone cert creation, but I am inching closer!

How do I generate a cert with only the below data to be included in the certs? What should be openssl.cnf have? What should be my genrsa be? and do I need to do anything else? I have attached the asn1parse output of the ok cert:

I have noticed something about the utc time field - is this odd? If yes, how do I gen something like it? Also, I have noticed that this cert has a few repetitive object names

0:d=0 hl=4 l= 937 cons: SEQUENCE 4:d=1 hl=4 l= 657 cons: SEQUENCE 8:d=2 hl=2 l= 3 cons: cont [ 0 ] 10:d=3 hl=2 l= 1 prim: INTEGER :02
  13:d=2  hl=2 l=   1 prim: INTEGER           :05
16:d=2 hl=2 l= 13 cons: SEQUENCE 18:d=3 hl=2 l= 9 prim: OBJECT :sha1WithRSAEncryption 29:d=3 hl=2 l= 0 prim: NULL 31:d=2 hl=2 l= 121 cons: SEQUENCE 33:d=3 hl=2 l= 11 cons: SET 35:d=4 hl=2 l= 9 cons: SEQUENCE 37:d=5 hl=2 l= 3 prim: OBJECT :countryName
  42:d=5  hl=2 l=   2 prim: PRINTABLESTRING   :US
46:d=3 hl=2 l= 17 cons: SET 48:d=4 hl=2 l= 15 cons: SEQUENCE 50:d=5 hl=2 l= 3 prim: OBJECT :stateOrProvinceName
  55:d=5  hl=2 l=   8 prim: PRINTABLESTRING   :Illinois
65:d=3 hl=2 l= 21 cons: SET 67:d=4 hl=2 l= 19 cons: SEQUENCE 69:d=5 hl=2 l= 3 prim: OBJECT :localityName
  74:d=5  hl=2 l=  12 prim: PRINTABLESTRING   :Libertyville
88:d=3 hl=2 l= 21 cons: SET 90:d=4 hl=2 l= 19 cons: SEQUENCE 92:d=5 hl=2 l= 3 prim: OBJECT :organizationName
  97:d=5  hl=2 l=  12 prim: PRINTABLESTRING   :Motorola Inc
111:d=3 hl=2 l= 12 cons: SET 113:d=4 hl=2 l= 10 cons: SEQUENCE 115:d=5 hl=2 l= 3 prim: OBJECT :organizationalUnitName
 120:d=5  hl=2 l=   3 prim: PRINTABLESTRING   :PCS
125:d=3 hl=2 l= 27 cons: SET 127:d=4 hl=2 l= 25 cons: SEQUENCE 129:d=5 hl=2 l= 3 prim: OBJECT :commonName
 134:d=5  hl=2 l=  18 prim: PRINTABLESTRING   :Motorola Java CA40
154:d=2 hl=2 l= 30 cons: SEQUENCE 156:d=3 hl=2 l= 13 prim: UTCTIME :030821070000Z
 171:d=3  hl=2 l=  13 prim: UTCTIME           :180821070000Z
186:d=2 hl=2 l= 127 cons: SEQUENCE 188:d=3 hl=2 l= 11 cons: SET 190:d=4 hl=2 l= 9 cons: SEQUENCE 192:d=5 hl=2 l= 3 prim: OBJECT :countryName
 197:d=5  hl=2 l=   2 prim: PRINTABLESTRING   :US
201:d=3 hl=2 l= 17 cons: SET 203:d=4 hl=2 l= 15 cons: SEQUENCE 205:d=5 hl=2 l= 3 prim: OBJECT :stateOrProvinceName
 210:d=5  hl=2 l=   8 prim: PRINTABLESTRING   :Illinois
220:d=3 hl=2 l= 21 cons: SET 222:d=4 hl=2 l= 19 cons: SEQUENCE 224:d=5 hl=2 l= 3 prim: OBJECT :localityName
 229:d=5  hl=2 l=  12 prim: PRINTABLESTRING   :Libertyville
243:d=3 hl=2 l= 21 cons: SET 245:d=4 hl=2 l= 19 cons: SEQUENCE 247:d=5 hl=2 l= 3 prim: OBJECT :organizationName
 252:d=5  hl=2 l=  12 prim: PRINTABLESTRING   :Motorola Inc
266:d=3 hl=2 l= 12 cons: SET 268:d=4 hl=2 l= 10 cons: SEQUENCE 270:d=5 hl=2 l= 3 prim: OBJECT :organizationalUnitName
 275:d=5  hl=2 l=   3 prim: PRINTABLESTRING   :PCS
280:d=3 hl=2 l= 33 cons: SET 282:d=4 hl=2 l= 31 cons: SEQUENCE 284:d=5 hl=2 l= 3 prim: OBJECT :commonName
 289:d=5  hl=2 l=  24 prim: PRINTABLESTRING   :Manufacturer Domain 40-1
315:d=2 hl=4 l= 290 cons: SEQUENCE 319:d=3 hl=2 l= 13 cons: SEQUENCE 321:d=4 hl=2 l= 9 prim: OBJECT :rsaEncryption 332:d=4 hl=2 l= 0 prim: NULL 334:d=3 hl=4 l= 271 prim: BIT STRING 609:d=2 hl=2 l= 54 cons: cont [ 3 ] 611:d=3 hl=2 l= 52 cons: SEQUENCE 613:d=4 hl=2 l= 14 cons: SEQUENCE 615:d=5 hl=2 l= 3 prim: OBJECT :X509v3 Key Usage
 620:d=5  hl=2 l=   1 prim: BOOLEAN           :255
 623:d=5  hl=2 l=   4 prim: OCTET STRING      [HEX DUMP]:03020186
629:d=4 hl=2 l= 17 cons: SEQUENCE 631:d=5 hl=2 l= 9 prim: OBJECT :Netscape Cert Type
 642:d=5  hl=2 l=   4 prim: OCTET STRING      [HEX DUMP]:03020001
648:d=4 hl=2 l= 15 cons: SEQUENCE 650:d=5 hl=2 l= 3 prim: OBJECT :X509v3 Basic Constraints
 655:d=5  hl=2 l=   1 prim: BOOLEAN           :255
 658:d=5  hl=2 l=   5 prim: OCTET STRING      [HEX DUMP]:30030101FF
665:d=1 hl=2 l= 13 cons: SEQUENCE 667:d=2 hl=2 l= 9 prim: OBJECT :sha1WithRSAEncryption 678:d=2 hl=2 l= 0 prim: NULL 680:d=1 hl=4 l= 257 prim: BIT STRING
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    openssl-users@openssl.org
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to