2010/1/4 Rich Megginson <rmeggins@xxxxxxxxxx>: > muzzol wrote: > Did you specify the FQDN with the -h argument? What hostname did you give? > The real hostname or the subjectAltName? i've used FQDN for CN and additional DNS entry for subjectAltName. anyway, i've found that i get a diferent cert when signing it with OpenSSL (openssl -req) and certutil (-C). i've created a sample CA with certutil and repeated all process. now i dont get that error anymore. is this a known behaviour? is there any limitations with subjectAltName and OpenSSL signing? anyone using OpenSSL to sign their DS certs? -- ======================== ^ ^ O O (_ _) muzzol(a)muzzol.com ======================== jabber id: muzzol(a)jabber.dk ======================== No atribueixis qualitats humanes als ordinadors. No els hi agrada. ======================== "El gobierno español sólo habla con terroristas, homosexuales y catalanes, a ver cuando se decide a hablar con gente normal" Jiménez Losantos ======================== <echelon spamming> bomb terrorism bush aznar teletubbies </echelon spamming> -- 389 users mailing list 389-users@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/fedora-directory-users