Yo Richard! On Wed, 3 Apr 2019 00:35:07 -0500 Richard Laager via devel <devel@ntpsec.org> wrote:
> > If I delete the hash to chain.pem then it fails again. So the hash > > to cert.pem does not help. > > Perfect. That's exactly how it should work. The "ca" option specifies > CAs, not end certificates. Fine, but I want and need a way to anchor to end certificates. > Does it work with "ca chain.pem" (specifying a file, as opposed to a > directory)? If you already tested this earlier in the thread and I > missed it, ignore me. I just tried it, no joy. The cert.pem that worked when I hashed it and "ca /tmp" does not work with "ca /tmp/cert.pem". > > > Of the things I'd like to force, cert.pem is > > the top of my list. > > Pinning the end cert is a separate issue. Yes, but what I want is in addition, or in place of, pinning. RGDS GARY --------------------------------------------------------------------------- Gary E. Miller Rellim 109 NW Wilmington Ave., Suite E, Bend, OR 97703 g...@rellim.com Tel:+1 541 382 8588 Veritas liberabit vos. -- Quid est veritas? "If you can’t measure it, you can’t improve it." - Lord Kelvin
pgpYBh4ek01O3.pgp
Description: OpenPGP digital signature
_______________________________________________ devel mailing list devel@ntpsec.org http://lists.ntpsec.org/mailman/listinfo/devel