If I have multiple CA's, will openvpn understand a --crl-verify
"file", where the file contains the CRL's from all of the CA's
concatenated together?  Or will it accept multiple --crl-verify
entries?

It looks like if I use the --crl-verify "file" dir method, I will run
into trouble if I have serial number collisions between CA's.

It seems like the "right" way to do it is to use the --capath method,
but I want to understand all my options.

I seem to have painted myself into a corner and am trying to find the
least-painful way to get out.

Thanks all!


_______________________________________________
Openvpn-users mailing list
Openvpn-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/openvpn-users

Reply via email to