Hi all,

I just want to check and make sure that I'm doing this right:

The situation is that I want to encode an arbitrary AKI value into a 
certificate for test purposes. If I understand everything correctly, the 
following should work:

[ user_with_bad_aki ]
authorityKeyIdentifier = @bad_aki

[ bad_aki ]
keyid = DER:01:02:03:04:05:06:07:08:09:0A


However, when I try this, it appears that I can't override the default 
behaviour of copying the SKI from the Signing CA Certificate.

Any thoughts?

---
Patrick Patterson
Chief PKI Architect
Carillon Information Security Inc.
http://www.carillon.ca





______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    openssl-users@openssl.org
Automated List Manager                           majord...@openssl.org

Reply via email to