Re: [Openca-Users] OpenCA and security vulnerability in Debian

2008-05-21 Thread Dominique Lohez
Maciej Szuba a écrit : Hello! What should I have do? I use Debian for subca, rootca is working on Fedora. I generated 400 cert on subca and distributed to clients. Last week I saw message about openssl vulnerability in Debian: Luciano Bello discovered that the random number generator in

Re: [Openca-Users] OpenCA and security vulnerability in Debian

2008-05-21 Thread Maciej Szuba
Hello Dominique!! Ok thx for answer. But I don't understand one thing. I think the way to do this is: So first step is revoked user certs on subca and these serials I can find in subca crl , next is revoked subca cert, and root crl include this information. So next step is new generete new cert

[Openca-Users] How to use ECC algorithm instead of RSA in OpenCA?

2008-05-21 Thread Karl
Hi, I wonder how to use ECC algorithm instead of RSA in OpenCA. I want to use ECC to sign the certificate instead of RSA encryption. I know we can select RSA or DSA during CA initialization, Phase One, at that time we can select a algorithm to encrypt a CA private key. After we chose the RSA