I'm having a problem signing a server certificate request from an Oracle web
server.  The problem is the organisationname field of the request is coming
in as T61STRING and therefore failing the mandatory o match I've set in my
openssl.cnf file even though it is correct when displayed as plain text.

Setting organizationname as optional works but this violates my companies
security policy so can't be done on the live CA.  

Any suggestions of another way to force "openssl ca -in ..." to recognise
the strings as matching would be greatly appreciated.

Heath Kitchin
E-Commerce Infrastructure
Dresdner Kleinwort Benson
mailto:[EMAIL PROTECTED]


--------------------------------------------------------------------------------
This email and any files transmitted with it are intended solely for the
addressee(s) and may be legally privileged and/or confidential. If you have
received this email in error please destroy it and contact the sender, via
our switchboard on +44 (0)20 7623 8000 or via return e-mail. You should not
copy, forward or use the contents, attachments or information in any way.
Any unauthorised use or disclosure may be unlawful. Dresdner Kleinwort
Benson gives no warranty as to the accuracy or completeness of this email
after it is sent over the Internet and accepts no responsibility for changes
made after it was sent. Any opinion expressed in this email may be personal
to the author and may not necessarily reflect the opinions of the Bank or
its affiliates. They may also be subject to change without notice.
--------------------------------------------------------------------------------
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to