Re: How to rotate cert when only first matching cert been verified

2020-12-23 Thread David von Oheimb
定平袁 you are welcome. The OpenSSL version you are using is way too old! Do not use version 1.1.0, 1.0.x, and anything older - those versions are unsupported and must be considered insecure. Yet since both your old and new server cert are not expired and have the same subject, keyIdentifier, and se

RE: How to rotate cert when only first matching cert been verified

2020-12-23 Thread Michael Wojcik
> From: 定平袁 > Sent: Tuesday, 22 December, 2020 20:08 > To: Michael Wojcik Please do not send messages regarding OpenSSL to me directly. Send them to the openss-users list. That is where the discussion belongs. > > Why are you appending it to the file containing the existing certificate? > I a

Re: private key not available for client_cert_cb

2020-12-23 Thread Jan Just Keijser
Hi, On 20/12/20 09:39, George wrote: Hi,    I tried running the "s_client" command and it appears to be working. I guess there must be something wrong in my code. it is good news that the s_client command is working - it means there is something wrong with your code but you have everything

Re: Format error in certificate´s notAfter field

2020-12-23 Thread Matt Caswell
On 22/12/2020 17:43, Raúl Uría Elices wrote: > Hi, > > I´m trying to connect to my vpn server, using tunnelblick, but thinking > this is a openssl stuff... may be I am wrong. > > > When connecting I got (XX is a placeholder) :  > > 2020-12-22 17:32:49.423703 VERIFY ERROR: depth=0, error=form