Re: Renew/extend CA created with ikectl

2018-12-12 Thread Kim Zeitler
Hello Stuart thanks for the reply, already suspected something along those lines. On 12/10/18 7:14 PM, Stuart Henderson wrote: It's a bit awkward but can be done, you'll find some information at https://serverfault.com/questions/306345/certification-authority-root-certificate-expiry-and-renewa

Re: Renew/extend CA created with ikectl

2018-12-10 Thread Stuart Henderson
On 2018-12-07, Kim Zeitler wrote: > This is a cryptographically signed message in MIME format. > > --ms050605050209090609050606 > Content-Type: text/plain; charset=utf-8; format=flowed > Content-Language: en-GB > Content-Transfer-Encoding: 7bit > > Hello, > > before I start getting cre

Renew/extend CA created with ikectl

2018-12-07 Thread Kim Zeitler
Hello, before I start getting creative with openssl(1) on my ikectl(8) created ca. Yesterday my ca certificate expired and I need to renew it (without loosing all the client certificates) Is there a recommended way of renewing the ca.crt created using ikectl ca create? I didn't find anything