Song Yi wrote:
> 
> Hi,
> 
> But the old cert has expired, I should can sign a new cert with the same DN.
> If you revoke it, somebody said, it will make the CRL too big!

If the certificate is expired you should have no problem issuing
it: you have to mark it with the 'E' in place of the 'V' in the index.txt.

Also you could use the openssl ca -updatedb I added in the new
SNAPs of openssl.

C'you,

        Massimiliano Pala ([EMAIL PROTECTED])

S/MIME Cryptographic Signature

Reply via email to