CVSROOT:        /cvs
Module name:    src
Changes by:     [email protected]   2023/11/17 07:43:36

Modified files:
        usr.sbin/ikectl: ikeca.cnf 

Log message:
Set "unique_subject = no" to allow renewing expired certificates.
Without this, openssl throws an error when creating a second req for
the same subject which leads to ikectl deleting the old cert without
creating a new one.

Reported by Ryan Kavanagh in openiked-portable here:
https://github.com/openiked/openiked-portable/issues/125

discussed with tb@
ok patrick@

Reply via email to