On Sun, May 27, 2007 at 12:13:38AM +0100, Mick wrote: > On Saturday 26 May 2007 21:38, Victor Duchovni wrote: > > On Sat, May 26, 2007 at 10:11:08PM +0200, Marek Marcola wrote: > > > $ openssl x509 -in cert.pem -text -noout > > > . > > > . > > > X509v3 extensions: > > > X509v3 Basic Constraints: > > > CA:FALSE > > > X509v3 Key Usage: > > > Digital Signature, Non Repudiation, Key Encipherment > > > . > > > > Perhaps a mini-ca will help. See "ca.sh", "cert.sh" and "openssl.cnf" > > used as follows: > [snip] > > Thanks Victor, > > Can you see anything amiss with my attached openssl.cnf? >
Sorry, for me openssl.cnf is a write-only interface... Perhaps someone else can help you. I find the files easier to write than read. -- Viktor. ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List openssl-users@openssl.org Automated List Manager [EMAIL PROTECTED]