Yo Richard! On Wed, 3 Apr 2019 15:54:39 -0500 Richard Laager via devel <devel@ntpsec.org> wrote:
> On 4/3/19 3:20 PM, Gary E. Miller via devel wrote: > >> Does it work with "ca chain.pem" (specifying a file, as opposed to > >> a directory)? If you already tested this earlier in the thread and > >> I missed it, ignore me. > > I just tried it, no joy. The cert.pem that worked when I hashed it > > and "ca /tmp" does not work with "ca /tmp/cert.pem". > > cert.pem did not work (and was not expected to work). Sorry, I mistyped. It was chain.pem that failed failed. > chain.pem > worked. Did you test with "ca /tmp/cert.pem" or "ca /tmp/chain.pem"? > The former should not work, while the latter should (and needs > testing). So, more methodically, using this prefix: server -4 pi3.rellim.com nts maxpoll 5 Fail - ca /tmp/cert.pem Fail - ca /tmp/chain.pem Fail - ca /tmp/fullchain.pem Fail - ca /tmp - with hash for cert.pem Fail - ca /tmp - with hash for chain.pem Fail - ca /tmp/ISRG_Root_X1.pem - the LE root Fail - ca /tmp - with hash for ISRG_Root_X1.pem Fail - ca /tmp/letsencryptauthorityx3.pem - LE intermediate Fail - ca /tmp/lets-encrypt-x3-cross-signed.pem - LE cross intermediate Fail - ca /tmp _ all the above hashed That is zero for ten... I can't say why the results differ from previous tests. RGDS GARY --------------------------------------------------------------------------- Gary E. Miller Rellim 109 NW Wilmington Ave., Suite E, Bend, OR 97703 g...@rellim.com Tel:+1 541 382 8588 Veritas liberabit vos. -- Quid est veritas? "If you can’t measure it, you can’t improve it." - Lord Kelvin
pgpP63Hf6yIYG.pgp
Description: OpenPGP digital signature
_______________________________________________ devel mailing list devel@ntpsec.org http://lists.ntpsec.org/mailman/listinfo/devel