hi, what is the trick that java plugin 1.3.0_02 recognizes the demoCA generated by "CA.pl -newca" as a valid CA? i included the demoCA-cert file "/usr/local/ssl/misc/demoCA/cacert.pem" into the global JDK keystore "jdk1.3.0_02\jre\lib\security\cacerts" as a trusted party. nevertheless keys generated by JDK keytool and signed by this trusted CA are not accepted by java plugin. what am i making wrong? doesn't it suffice to simply include the CA certificate "cacert.pem" as a trusted party which begins like this?: -----BEGIN CERTIFICATE----- MIIDjz... do i need another kind of CA certificate to include into the java key system in order to have a valid root CA? if yes how do i get that from my demoCA? thank you very much, michael ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List [EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED]