On Mon, Jul 29, 2002 at 05:41:20PM +0200,  Jim Beasley  via RT wrote:
> The syntax I am using for the Verify follows:
> 
> openssl verify -CApath /etc/httpd/ssl.crt -CAfile
> /etc/httpd/ssl.crt/ca-bundle.crt -purpose sslserver -verbose
> ssl.crt/server.crt

Yes, and it is working fine, isn't it?
(the issuer_checks output is a warning, not an error)

> The server.crt is a super-cert from Thawte which we have just recently
> purchased.

So when using openssl s_client, you also have to specify -CAfile ...
-CApath... and it should work as well.

-- 
Lutz Jaenicke                             [EMAIL PROTECTED]
http://www.aet.TU-Cottbus.DE/personen/jaenicke/
BTU Cottbus, Allgemeine Elektrotechnik
Universitaetsplatz 3-4, D-03044 Cottbus

______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to