Properly manage CA-signed certificates that have expired

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 




> Yep, and give the new ones a slightly different "full" 
> distinguished name (important for CRL and "ca" database).
> My approach is to include the year-month as an extra OU e.g.
>
>? CN=foo.example.private,OU=isonetwork,OU=2016-03,O=YourCompany Inc,L=YourTown,C=XX

Ooh, that's neat advice!


--  
Senior Architect, Akamai Technologies
IM: richsalz at jabber.at Twitter: RichSalz


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Index of Archives]     [Linux ARM Kernel]     [Linux ARM]     [Linux Omap]     [Fedora ARM]     [IETF Annouce]     [Security]     [Bugtraq]     [Linux]     [Linux OMAP]     [Linux MIPS]     [ECOS]     [Asterisk Internet PBX]     [Linux API]

  Powered by Linux