Re: [openssl-users] "nmake install" attempts to write outside of prefix

2016-09-27 Thread Jaroslav Imrich
On 26 September 2016 at 22:04, Braden McDaniel wrote: > After configuring with a prefix (other than "C:\Program Files"), it seems > that "nmake install" still attempts to write to "C:\Program Files\Common > Files\SSL". Is there some other way to suppress this, or is this a

Re: [openssl-users] [openssl-dev] Ubsec and Chil engines

2016-02-20 Thread Jaroslav Imrich
On 20 February 2016 at 21:40, Sander Temme wrote: > However, I’m intrigued by the notion of a PKCS#11 Engine in OpenSSL: it’s > a standard (an OASIS standard now); it’s fairly fully featured; everyone in > the industry supports it including Thales; and you can build a program

Re: [openssl-users] [openssl-dev] Ubsec and Chil engines

2016-02-19 Thread Jaroslav Imrich
Hello Matt, If I don't hear from anyone I will remove these. > I can confirm that CHIL engine is actively used with OpenSSL 1.0.* by the owners of nCipher/THALES nShield HSMs. I have notified vendor support about this thread. Regards, Jaroslav -- openssl-users mailing list To unsubscribe:

Re: id-smime-aa-signingCertificate - attribute definition

2013-01-22 Thread Jaroslav Imrich
It is defined in RFC 2634. -- Kind Regards / S pozdravom Jaroslav Imrich http://www.jimrich.sk On Wed, Jan 16, 2013 at 2:22 PM, kapetr kap...@mizera.cz wrote: m sorry - I was blind ?! :-/ The both ESSCertIDs are in same Signing Certificate entity. But -I'm still interesting to find RFC

Re: id-smime-aa-signingCertificate - attribute definition

2013-01-22 Thread Jaroslav Imrich
RFC 2630 page 8: Attribute ::= SEQUENCE { attrType OBJECT IDENTIFIER, attrValues SET OF AttributeValue } -- Kind Regards / S pozdravom Jaroslav Imrich http://www.jimrich.sk On Tue, Jan 22, 2013 at 10:25 AM, kapetr kap...@mizera.cz wrote: Hello, I can not see

Re: possible Bug in OpenSSL - rfc 3161 - TSA service

2013-01-13 Thread Jaroslav Imrich
the signature. -- Kind Regards / S pozdravom Jaroslav Imrich http://www.jimrich.sk On Sat, Jan 12, 2013 at 7:23 PM, kapetr kap...@mizera.cz wrote: Hello, My CA Authority (Europe Union qualified!) claims - there is Bug in OpenSSL = verifying digi. timestamp fails. The CA says (my bad

Re: HELP!!!! mod_tsa:could not load X.509 certificate

2011-02-22 Thread Jaroslav Imrich
Hello Yessica, please post new certificate and exact error you're getting. -- Kind Regards / S pozdravom Jaroslav Imrich http://www.jariq.sk On Mon, Feb 21, 2011 at 4:41 PM, Yessica De Ascencao yessima...@gmail.comwrote: hello!!! Thanks for the response! Yes I needed the extension

Re: HELP!!!! mod_tsa:could not load X.509 certificate

2011-02-22 Thread Jaroslav Imrich
Hello Yessica, you are almost there :) Try only Non Repudiation as key usage: X509v3 Key Usage: Non Repudiation X509v3 Extended Key Usage: critical Time Stamping -- Kind Regards / S pozdravom Jaroslav Imrich http://www.jariq.sk

Re: Two questions about OpenSSL TSA Tool?

2011-02-22 Thread Jaroslav Imrich
months ago I've submitted patch that allows users to specify signing algorithm - http://rt.openssl.org/Ticket/Display.html?id=2145user=guestpass=guest -- Kind Regards / S pozdravom Jaroslav Imrich http://www.jariq.sk

Re: HELP!!!! mod_tsa:could not load X.509 certificate

2011-02-18 Thread Jaroslav Imrich
Hello Yessica, error may be caused by incorrect extensions in TSA certificate. Could you please post output of following command: openssl x509 -in /root/tssCRT.pem -text -- Kind Regards / S pozdravom Jaroslav Imrich http://www.jariq.sk

Re: HELP!!!! mod_tsa:could not load X.509 certificate

2011-02-18 Thread Jaroslav Imrich
/ S pozdravom Jaroslav Imrich http://www.jariq.sk