I'm having a problem signing a server certificate request from an Oracle web server. The problem is the organisationname field of the request is coming in as T61STRING and therefore failing the mandatory o match I've set in my openssl.cnf file even though it is correct when displayed as plain text. Setting organizationname as optional works but this violates my companies security policy so can't be done on the live CA. Any suggestions of another way to force "openssl ca -in ..." to recognise the strings as matching would be greatly appreciated. Heath Kitchin E-Commerce Infrastructure Dresdner Kleinwort Benson mailto:[EMAIL PROTECTED] -------------------------------------------------------------------------------- This email and any files transmitted with it are intended solely for the addressee(s) and may be legally privileged and/or confidential. If you have received this email in error please destroy it and contact the sender, via our switchboard on +44 (0)20 7623 8000 or via return e-mail. You should not copy, forward or use the contents, attachments or information in any way. Any unauthorised use or disclosure may be unlawful. Dresdner Kleinwort Benson gives no warranty as to the accuracy or completeness of this email after it is sent over the Internet and accepts no responsibility for changes made after it was sent. Any opinion expressed in this email may be personal to the author and may not necessarily reflect the opinions of the Bank or its affiliates. They may also be subject to change without notice. -------------------------------------------------------------------------------- ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List [EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED]