Re: IPv6 address encoding in commonName

2019-08-14 Thread Richard Levitte
On Thu, 15 Aug 2019 00:47:41 +0200, Michael Richardson wrote: > > > Robert Moskowitz wrote: > > I am fiddling around with an intermediate CA signing cert that the CA's > > 'name' is it HIP (RFC 7401) HIT which is a valid IPv6 address. Actually > a > > Hierarchical HIT as in draft-mo

Re: openssl req error with DN having a / in it

2019-08-14 Thread Jakob Bohm via openssl-users
On 15/08/2019 00:33, Jordan Brown wrote: On 8/14/2019 2:11 PM, Robert Moskowitz wrote: [...]    commonName="/CN=IPv6::2001:24:28:24/64" [...] req: Hit end of string before finding the equals. problems making Certificate Request Some systems present distinguished names using slashes as separat

Re: IPv6 address encoding in commonName

2019-08-14 Thread Michael Richardson
Robert Moskowitz wrote: > I am fiddling around with an intermediate CA signing cert that the CA's > 'name' is it HIP (RFC 7401) HIT which is a valid IPv6 address. Actually a > Hierarchical HIT as in draft-moskowitz-hierarchical-hip (to be revised soon). > For a client cert, it w

Re: openssl req error with DN having a / in it

2019-08-14 Thread Jordan Brown
On 8/14/2019 2:11 PM, Robert Moskowitz wrote: > [...] >    commonName="/CN=IPv6::2001:24:28:24/64" > [...] > req: Hit end of string before finding the equals. > problems making Certificate Request Some systems present distinguished names using slashes as separators.  I assume that that's what you

openssl req error with DN having a / in it

2019-08-14 Thread Robert Moskowitz
Developing saga on creating an intermediate CA cert with only CN and said CN should be: CN=IPv6::2001:24:28:24/64 Note that / in CN that seems to be a challenge.    commonName="/CN=IPv6::2001:24:28:24/64"    DN=$commonName    echo $DN    openssl req -config $cadir/openssl-root.cnf\    -ke

Re: IPv6 address encoding in commonName

2019-08-14 Thread Robert Moskowitz
On 8/14/19 3:26 PM, Salz, Rich wrote: RFC 8002 (with a null subjectName), but a CA cert MUST have a non-empty subjectName. Non-empty subjectName or non-empty commonName within the subject name? Shrug. Doesn't matter, I guess. Just populate it with the string version of the HIT n

Re: IPv6 address encoding in commonName

2019-08-14 Thread Robert Moskowitz
On 8/14/19 11:21 AM, Jakob Bohm via openssl-users wrote: On 14/08/2019 04:55, Robert Moskowitz wrote: I am fiddling around with an intermediate CA signing cert that the CA's 'name' is it HIP (RFC 7401) HIT which is a valid IPv6 address. Actually a Hierarchical HIT as in draft-moskowitz-hiera

Re: IPv6 address encoding in commonName

2019-08-14 Thread Salz, Rich via openssl-users
RFC 8002 (with a null subjectName), but a CA cert MUST have a non-empty subjectName. Non-empty subjectName or non-empty commonName within the subject name? Shrug. Doesn't matter, I guess. Just populate it with the string version of the HIT name, something like CN=IP Address 20

Re: IPv6 address encoding in commonName

2019-08-14 Thread Jakob Bohm via openssl-users
On 14/08/2019 04:55, Robert Moskowitz wrote: I am fiddling around with an intermediate CA signing cert that the CA's 'name' is it HIP (RFC 7401) HIT which is a valid IPv6 address. Actually a Hierarchical HIT as in draft-moskowitz-hierarchical-hip (to be revised soon). For a client cert, it wo

Re: Convert eddsa public key fro PEM to DER

2019-08-14 Thread Robert Moskowitz
On 8/14/19 8:42 AM, Matt Caswell wrote: On 14/08/2019 13:21, Robert Moskowitz wrote: On 8/14/19 6:22 AM, Matt Caswell wrote: On 14/08/2019 11:06, Robert Moskowitz wrote: I googled how to convert a PEM public key to DER and only found examples for RSA keys.  Mine are ed25519.  I thought it

Re: Convert eddsa public key fro PEM to DER

2019-08-14 Thread Matt Caswell
On 14/08/2019 13:21, Robert Moskowitz wrote: > > > On 8/14/19 6:22 AM, Matt Caswell wrote: >> >> On 14/08/2019 11:06, Robert Moskowitz wrote: >>> I googled how to convert a PEM public key to DER and only found examples >>> for RSA >>> keys.  Mine are ed25519.  I thought it would be a simple a

Re: Convert eddsa public key fro PEM to DER

2019-08-14 Thread Robert Moskowitz
On 8/14/19 6:22 AM, Matt Caswell wrote: On 14/08/2019 11:06, Robert Moskowitz wrote: I googled how to convert a PEM public key to DER and only found examples for RSA keys.  Mine are ed25519.  I thought it would be a simple algorithm substitution: $ openssl ed25519 -pubin -inform PEM -in $di

Re: Convert eddsa public key fro PEM to DER

2019-08-14 Thread Matt Caswell
On 14/08/2019 11:06, Robert Moskowitz wrote: > I googled how to convert a PEM public key to DER and only found examples for > RSA > keys.  Mine are ed25519.  I thought it would be a simple algorithm > substitution: > > $ openssl ed25519 -pubin -inform PEM -in $dir/private/intermediate.key.pem

Convert eddsa public key fro PEM to DER

2019-08-14 Thread Robert Moskowitz
I googled how to convert a PEM public key to DER and only found examples for RSA keys.  Mine are ed25519.  I thought it would be a simple algorithm substitution: $ openssl ed25519 -pubin -inform PEM -in $dir/private/intermediate.key.pem\ >  -outform DER -out $dir/private/intermediate.key.der I