Re: About CRL

1999-09-19 Thread Sergio Rabellino
Chelo Malagon CSIC RedIRIS wrote: > > Hello all, > I'd like to know if there is any way to remove a certificate from a > CRL, for example when the validity time of a certificate which has > been revoked has expired. (like says in the RFC 2459 "An entry may be > removed from the CRL after appering

req in non interactive mode

1999-09-19 Thread Paul Khavkine
Hi I'm trying to set up req in non-interactive mode. Well not really non-interactive, i want to use input from a cgi script rather then from stdin Ho could i do it? I want to make a cgi fontend to the "openssl req" command Thanx Paul _

Re: Getting setup with DHE and RSA

1999-09-19 Thread Dr Stephen Henson
David Murphy wrote: > > > Any ideas? this is on windows NT. > Ah one more thing. You won't be able to run CA.sh under NT. Try copying CA.pl (in apps) somewhere on your path and doing: perl -S CA.pl wherever my original message said CA.sh Steve. -- Dr Stephen N. Henson. http://www.drh-con

Re: Getting setup with DHE and RSA

1999-09-19 Thread Dr Stephen Henson
David Murphy wrote: > > Steve - thanks a ton for this info.. However got a problem at 2 (generating > DSA cert) . It says :- > > "using configuration from /usr/local/ssl/openssl.cnf" then > "unable to load config info" even though I created the directory on Win NT > and put the OpenSSL.cnf into

Re: Getting setup with DHE and RSA

1999-09-19 Thread David Murphy
Steve - thanks a ton for this info.. However got a problem at 2 (generating DSA cert) . It says :- "using configuration from /usr/local/ssl/openssl.cnf" then "unable to load config info" even though I created the directory on Win NT and put the OpenSSL.cnf into it. Anyway it generates and displ

server/client authentication with stunnel

1999-09-19 Thread Herve Regad-Pellagru
Hi all ! After trying many hours to get client/server authentication via certificate to work with stunnell-3.4a (openssl-0.9.4), I require some help from enlightened people. Here's what I did: - create a certificate authority (openssl req -new -x509 -nodes -keyout keyCAcert.pem