> hmm.. well, I actually have two different CA certs but my > understanding is that I goofed there, you don't need to have > 2 different CAs, only 1 will do. 2 server certs, 1 CA cert. > > at least, you've to change the cn= when you generate the > server cert. THen sign both certs with the same CA cert. > Yes...I use m fqdn for that...and I tried to sign both with the same CA and different CA Alex