Creating an X25519 client certificate

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



I have created my X25519 pub/priv keypair with:

openssl genpkey -algorithm X25519\
    -out $dir/private/$clientemail-X.key.$format

And displays properly with:

openssl pkey -in $dir/private/$clientemail-X.key.$format -text -noout


So now to make the csr with:

openssl req -config $dir/openssl-intermediate.cnf\
    -key $dir/private/$clientemail-X.key.$format \
    -subj "$DN" -new -out $dir/csr/$clientemail-X.csr.$format

which is what I used for ED25519 client certs.  But I get an error:

140487683954496:error:0608D096:digital envelope routines:EVP_PKEY_sign_init:operation not supported for this keytype:crypto/evp/pmeth_fn.c:39:

I can't figure out from my config file why this error.  and googling the error has not helped.  yet.

Can someone point me to what I am missing?

Oh, and I am ASSuMEing that a CA cert of ED25519 signs an X25519 client cert.  Haven't found instructions on this, but it seems reasonable...

thanks





[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Index of Archives]     [Linux ARM Kernel]     [Linux ARM]     [Linux Omap]     [Fedora ARM]     [IETF Annouce]     [Security]     [Bugtraq]     [Linux]     [Linux OMAP]     [Linux MIPS]     [ECOS]     [Asterisk Internet PBX]     [Linux API]

  Powered by Linux