You're doing it exactly right, and using a private CA for good reasons. Your initial post failed to explain that it was for a private enterprise use.
You can pre-load your CA into your company browsers as part of installing their PC's. Details depend on browser; a floppy or CDROM with the cert often works, e.g. /r$ -- Zolera Systems, http://www.zolera.com Information Integrity, XML Security ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List [EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED]