> You must generate new private key (longer) for CA > and self certify. Next you should publish your new > CA certificate.
As a transition aide, you might want to have your old root also sign the new CA key. /r$ -- SOA Appliances Application Integration Middleware ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List openssl-users@openssl.org Automated List Manager [EMAIL PROTECTED]