CVSROOT: /cvs
Module name: src
Changes by: [email protected] 2023/11/17 07:43:36
Modified files:
usr.sbin/ikectl: ikeca.cnf
Log message:
Set "unique_subject = no" to allow renewing expired certificates.
Without this, openssl throws an error when creating a second req for
the same subject which leads to ikectl deleting the old cert without
creating a new one.
Reported by Ryan Kavanagh in openiked-portable here:
https://github.com/openiked/openiked-portable/issues/125
discussed with tb@
ok patrick@