libressl on OpenBSD7.3 - x509_extensions crlDistributionPoints being ignored

2023-09-26 Thread stephane Tranchemer
Synopsis:  Creating certificates with a config file declaring x509_extensions crlDistributionPoints option is being ignored >Category:  libressl >Environment:     System  : OpenBSD 7.3     Details : OpenBSD 7.3 (GENERIC.MP) #1125: Sat Mar 25 10:36:29 MDT 2023 dera...@amd64.o

Re: libressl on OpenBSD7.3 - x509_extensions crlDistributionPoints being ignored

2023-09-26 Thread Theo Buehler
> >Description: >     I have a config file for SSL certificates that declares to use the > x509_extensions crlDistributionPoints with this syntax: > crlDistributionPoints = URI:http://192.168.1.5/crl/root.crl > > however when generation the certificate against this config a check of the > gene

Re: libressl on OpenBSD7.3 - x509_extensions crlDistributionPoints being ignored

2023-09-26 Thread stephane Tranchemer
Hello, How-To-Repeat: Create a config file for SSL certificates that declares to use the x509_extensions crlDistributionPoints with a RUL target. Generate a certificate against this config, there should be the CRL options declared. As far as I can see, the problem is this: your crldp URI conta

Re: libressl on OpenBSD7.3 - x509_extensions crlDistributionPoints being ignored

2023-09-26 Thread Theo Buehler
On Wed, Sep 27, 2023 at 09:06:58AM +0900, stephane Tranchemer wrote: > Hello, > > > > How-To-Repeat: > > > Create a config file for SSL certificates that declares to use the > > > x509_extensions crlDistributionPoints with a RUL target. > > > > > > Generate a certificate against this config, there

Re: libressl on OpenBSD7.3 - x509_extensions crlDistributionPoints being ignored

2023-09-26 Thread stephane Tranchemer
Another trouble I found, maybe it's my conf again(?) is that I am unable to use a section to call out to define common options for x509extensions. Example, this does not work: [ ca ] default_ca = Domain-CA [ Domain-CA ] ... x509_extensions = common_options [ common_options ] crlDistributionPo