I've just spent a while trying to figure out how to get a signed applet using my own CA instead of thawte or verisign. I noticed there were lots of questions I had on this list (like why keytool was saying "Input not an X.509 certificate"), but no real answers. Well, the whole process is now documented at http://gilgamesh.silentmedia.com/java/ Hopefully this will save other people from wasting 3 days in confusion. :) ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List [EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED]