> installed. I have tried SSLeay 0.90 and Openssl 0.92b, have used ca-fix, you shouldn't need ca-fix if you're working with openssl 0.9.2b > have tried commenting out nscerttype, or changing to the nscerttype set it to: nsCerttype = client, email > switch for client certs. What is special about version 4.04, and how can > I fix things for other versions? I have a working configuration for (at least) NS 4.08 and NS 4.05 (Linux/IRIX) - I found no problems... > Netscape Cert Type: > 0xA0 If this output was created by open-ssl-0.9.2b I think this should read as email or client - not as hex-number... Maybe it helps to take a look to ftp://lnx40.tfh-berlin.de/pub/ca theres a Makefile that knows about client certs (make filename.client), and a sample cgi to generate client cert requests (for Netscape only). oki, Steffen ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List [EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED]