RE: error "unable to load PKCS7 object... wrong tag"

2013-07-19 Thread Dave Thompson
>From: owner-openssl-us...@openssl.org On Behalf Of likejiujitsu >Sent: Friday, 19 July, 2013 10:26 >openssl asn1parse -inform DER -in "D:\thawte_info\myCert.spc" >0:d=0 hl=2 l= 45 cons: >Error in encoding > 4048:error:0D07209B:asn1 encoding routines:ASN1_get_object: >too long:.\crypt

RE: SSL_connect:error in SSLv3 flush data - Certificate Verification: Error (20) when setting up replacement server

2013-07-19 Thread Dave Thompson
> From: owner-openssl-us...@openssl.org On Behalf Of Michel, Audrey > Sent: Friday, 19 July, 2013 11:41 > Thanks for the reply and good information as it helped clear > up some misunderstanding I had. Here is some additional > information based on your responses. > > -The two servers have diffe

openssl ca -revoke

2013-07-19 Thread redpath
The command openssl ca -revoke ./demoCA/newcerts/1008.pem -config myconfig.cnf -passin pass:password seems to just update a database, the 1008.pem is not touched. Can someone tell me what this command really does for revocation. Also why keep a list of revoked certs, just delete them and if not f

RE: SSL_connect:error in SSLv3 flush data - Certificate Verification: Error (20) when setting up replacement server

2013-07-19 Thread Michel, Audrey
Thanks for the reply and good information as it helped clear up some misunderstanding I had. Here is some additional information based on your responses. -The two servers have different DNS names and have two different servernames in their apache config files. Each server is stand alone and has

Re: error "unable to load PKCS7 object... wrong tag"

2013-07-19 Thread likejiujitsu
openssl asn1parse -inform DER -in "D:\thawte_info\myCert.spc"     0:d=0  hl=2 l=  45 cons: Error in encoding 4048:error:0D07209B:asn1 encoding routines:ASN1_get_object:too long:.\crypto\asn1\asn1_lib.c:142: From: Dave Thompson-5 [via OpenSSL] To: likejiujitsu

Re: End of the line for OpenSSL Fips?

2013-07-19 Thread Steve Marquess
On 07/18/2013 10:17 PM, Thomas J. Hruska wrote: > ... > I'm not seeing anywhere in the Q&A where it might suggest how much > funding would be required to meet the financial goals of upgrading > OpenSSL FIPS. Based on the "as low as" private label price tag of > $35,000 located elsewhere on the sit