upgrade to 1.0.1r breaks script that worked for years. Config issue?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Wed, Feb 24, 2016, lists wrote:

> 
> extensions = x509v3
> 
> [ x509v3 ]
> keyUsage              = digitalSignature
> extendedKeyUsage      = clientAuth,emailProtection
> crlDistributionPoints = URI:http://ldap.secure-edge.com/secure-edge-ca.crl
> subjectAltName        = email:copy
> basicConstraints      = CA:false,pathlen:0

While this isn't the cause of your problem you should NOT use pathelen if you
have CA:false. An application might reject such a certificate due to
inconsistent extension values.

Steve.
--
Dr Stephen N. Henson. OpenSSL project core developer.
Commercial tech support now available see: http://www.openssl.org


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Index of Archives]     [Linux ARM Kernel]     [Linux ARM]     [Linux Omap]     [Fedora ARM]     [IETF Annouce]     [Security]     [Bugtraq]     [Linux]     [Linux OMAP]     [Linux MIPS]     [ECOS]     [Asterisk Internet PBX]     [Linux API]

  Powered by Linux