>From: owner-openssl-us...@openssl.org On Behalf Of Erwann Abalea >Sent: Tuesday, 29 May, 2012 10:13
>Yes to everything. Minor caveat: OpenSSL supports signatures using SHA256 *with RSA and ECDSA* back to 0.9.8 and I think 0.9.7, but SHA256 (and SHA224) with DSA only since 1.0.0. (As I recall SHA2-RSA schemes were defined when SHA2 first came out in early noughties, and SHA2-ECDSA when ECDSA came out roughly the same time, but SHA2-DSA only when DSA was increased above 1024 by FIPS 186-3 in 2008.) >As your question is not about the development of OpenSSL, >but instead about its use, it should have been better in >the openssl-users mailing list. Yes. >Le 28/05/2012 15:43, Manas Ranjan Lenka a écrit : <snip: want X509v3 RFC5280 with KU, BC, AKI, SKI, SHA256> ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List openssl-users@openssl.org Automated List Manager majord...@openssl.org