Hi Gert,

>> I tried
>>      $OPENSSL ca -gencrl -days $SA_EXPIRE -out "$CRL" -config "$KEY_CONFIG"
>> but that still generated a crl file for one month.
>
> Make that "-crldays $SA_EXPIRE"

Thanks, after fixing my own type ($CA_EXPIRE, not $SA_...) it works like 
expected.
Now I have a crl file that is valid untill after my CA expires, that's long 
enough. ;-)

Bonno Bloksma



_______________________________________________
Openvpn-users mailing list
Openvpn-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/openvpn-users

Reply via email to