Hi Gert, >> I tried >> $OPENSSL ca -gencrl -days $SA_EXPIRE -out "$CRL" -config "$KEY_CONFIG" >> but that still generated a crl file for one month. > > Make that "-crldays $SA_EXPIRE"
Thanks, after fixing my own type ($CA_EXPIRE, not $SA_...) it works like expected. Now I have a crl file that is valid untill after my CA expires, that's long enough. ;-) Bonno Bloksma _______________________________________________ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users