What are the validity dates for the Issuer i.e.
Issuer: C=SK, L=Bratislava, O=Business Global Systems,
CN=Identity root Certificate [EMAIL PROTECTED]

compare the dates with the Server cert validity..
Server cert validity has to be within the issuer cert validity..

;>


> Hello!
> 
> I have problem with OpenSSL generated certificates. MSIE 4 and MSIE 5
> both say that this certificate has expored:
> 
> Certificate:
>     Data:
>         Version: 3 (0x2)
>         Serial Number: 2 (0x2)
>         Signature Algorithm: md5WithRSAEncryption
>         Issuer: C=SK, L=Bratislava, O=Business Global Systems,
> CN=Identity root Certificate [EMAIL PROTECTED]
>         Validity
>             Not Before: Jul 13 14:36:12 1999 GMT
>             Not After : Jul 12 14:36:12 2000 GMT
>         Subject: C=SK, O=Business Global Systems,
> [EMAIL PROTECTED]
>         Subject Public Key Info:
>             Public Key Algorithm: rsaEncryption
>             RSA Public Key: (2048 bit)
>                 Modulus (2048 bit):
>                     00:d5:77:3a:9f:69:2b:43:f7:07:30:ad:ff:68:c9:
>                     81:64:5e:88:da:2b:4e:43:b0:dd:4f:74:f8:68:e6:
> .......
>                     d0:6b
>                 Exponent: 65537 (0x10001)
>         X509v3 extensions:
>             X509v3 Basic Constraints:
>                 CA:FALSE
>             Netscape Cert Type:
>                 SSL Server
>             Netscape Comment:
>                 Identity Secure Server Certificate
>             X509v3 Subject Key Identifier:
>                
> 64:33:E7:99:17:0C:EA:B0:72:04:CA:1D:88:C9:64:57:06:C8:4E:34
>             X509v3 Authority Key Identifier:
>                
> keyid:D6:B5:26:0D:AA:CF:E4:F0:8A:63:5E:D9:28:20:84:B9:B8:5E:BF:76
>                 DirName:/C=SK/L=Bratislava/O=Business Global
> Systems/CN=Identity root Certificate
[EMAIL PROTECTED]
>                 serial:00
> 
>             X509v3 Subject Alternative Name:
>                 email:[EMAIL PROTECTED]
>             X509v3 Issuer Alternative Name:
>                 email:[EMAIL PROTECTED]
>             Netscape CA Revocation Url:
>                 http://identity.sk/ca-crl.pem
>     Signature Algorithm: md5WithRSAEncryption
>         9c:9b:b5:fe:57:fb:73:50:80:5d:41:82:92:b6:2b:e7:46:7a:
> ........
> 
> 
> What is the problem? Netscape works just fine ...
> 
> 
> -- 
>                              Radovan Semancik ([EMAIL PROTECTED])
>                          System Engineer, Business Global Systems a.s.
>                                    http://storm.alert.sk
> ______________________________________________________________________
> OpenSSL Project                                 http://www.openssl.org
> User Support Mailing List                    [EMAIL PROTECTED]
> Automated List Manager                           [EMAIL PROTECTED]
> 

______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to