Louis LeBlanc wrote:
> 
> On 10/03/01 05:35 PM, Lukasz Jazgar sat at the `puter and typed:
> > Another question. How to create 2 certificates with the same name?
> > I need them for 2 web servers running on one computer with only one DNS
> > name.
> > Any advice?
> 
> I assume these servers are listening on different ports - if not you
> will have problems.

Yes. Of course.

> As for advice, why not use the same cert.  It is the same machine and
> the same CN will be on the certs after all.

I use iPlanet Webserver. Every instance of this server manages its own
secure database of keys/certificates. Key pairs are generated internally
by server and there is no possibility to import them from file.

> 
> If you can't do that for whatever reason, just change the OU name
> (organizational Unit) and make it relevant to the server you are
> running.

Yes. It's a solution.
But, if CA has a policy, which requires, that OU of certificate matches
OU of CA?
I rather looking for solution such as special parameter or
configuration.

If there's no such solution, I have another questions.
What's wrong in existance of two certificates, which differ only by
serial number and public key?
Why one entity cannot have two certificates?

Best regards
Lukasz Jazgar
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to