It seems to me, that openssl "ca" tool always forces "Valid after" attribute of new CRL to be current system date and time.
Is there any way to generate CRL with validity period that I desire ? Do I have to use some commercial tool for that ? Thank you in advance, -- - TOR Trade Company, IT Department, Konstantin Andreev. mailto:kostya@;defender.ru ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List [EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED]