RE: howto be my own CA for my new certificates

2011-08-04 Thread Tomas Macek
On Thu, 4 Aug 2011, Dave Thompson wrote: From: owner-openssl-us...@openssl.org On Behalf Of Alan Buxey Sent: Thursday, 04 August, 2011 03:54 Thank you! But now I'm spending my time with another issue with this: I cannot create certificate longer than I month: The server certificate was

RE: howto be my own CA for my new certificates

2011-08-04 Thread Dave Thompson
> From: owner-openssl-us...@openssl.org On Behalf Of Alan Buxey > Sent: Thursday, 04 August, 2011 03:54 > > Thank you! But now I'm spending my time with another issue > with this: I > > cannot create certificate longer than I month: > > The server certificate was created by command: > > ope

Re: howto be my own CA for my new certificates

2011-08-04 Thread Erwin Himawan
When you are creating a CA and issuing certificate you are building a PKI (Public Key Infrastructure). In operating a PKI, you might want to consider crafting a certification policy, specifying the process for managing the lifecycle of your certificates, securing the CA's private key, securing th

Re: howto be my own CA for my new certificates

2011-08-04 Thread Tomas Macek
On Thu, 4 Aug 2011, Bernhard Fröhlich wrote: Am 04.08.2011 08:23, schrieb Tomas Macek: We have some web servers and I want to create self signed certificates for them. What do I want: - I want to create my own certification authority keys and certificate, that will be imported to all web b

Re: howto be my own CA for my new certificates

2011-08-04 Thread Bernhard Fröhlich
Am 04.08.2011 08:23, schrieb Tomas Macek: We have some web servers and I want to create self signed certificates for them. What do I want: - I want to create my own certification authority keys and certificate, that will be imported to all web browsers of our employees - I want to create certi

Re: howto be my own CA for my new certificates

2011-08-04 Thread Tomas Macek
On Thu, 4 Aug 2011, Alan Buxey wrote: Hi, Thank you! But now I'm spending my time with another issue with this: I cannot create certificate longer than I month: This is my CA certificate validity: ... Not Before: Aug 3 10:07:14 2011 GMT Not After : Aug 2 1

Re: howto be my own CA for my new certificates

2011-08-04 Thread Alan Buxey
Hi, > Thank you! But now I'm spending my time with another issue with this: I > cannot create certificate longer than I month: > > This is my CA certificate validity: > ... > Not Before: Aug 3 10:07:14 2011 GMT > Not After : Aug 2 10:07:14 2012 GMT > ... >

Re: howto be my own CA for my new certificates

2011-08-04 Thread Tomas Macek
Thank you! But now I'm spending my time with another issue with this: I cannot create certificate longer than I month: This is my CA certificate validity: ... Not Before: Aug 3 10:07:14 2011 GMT Not After : Aug 2 10:07:14 2012 GMT ... This is my server'

Re: howto be my own CA for my new certificates

2011-08-04 Thread yyy
Everything seems to be fine, only for new installations it is recomended to use at least 2048 bit keyand, at least some time ago, openssl used to default to MD5 for certificate signatures,check, if it is not the case.   Citējot Tomas Macek : We have some web servers and I want to create self signe

howto be my own CA for my new certificates

2011-08-03 Thread Tomas Macek
We have some web servers and I want to create self signed certificates for them. What do I want: - I want to create my own certification authority keys and certificate, that will be imported to all web browsers of our employees - I want to create certificates, that will be signed by my own cer