CVSROOT:        /cvs
Module name:    src
Changes by:     [email protected]   2014/03/11 09:25:34

Modified files:
        sbin/isakmpd   : isakmpd.8 

Log message:
For CA generation, go back to using a two-step procedure to create a CSR and
then self-sign it rather than using the "openssl req" shortcut. This allows
us to specify -extfile and thus set the correct certificate extensions so
that stricter SSL implementations will trust this as a CA cert, and matches
how things are done in ssl(8). This is basically a partial revert of r1.77.

Researched by chrisz@, tweak/ok jmc@ ok beck@

Reply via email to