[ssl_mgmt] Ensure version 3 certificate are used
This commit is contained in:
parent
df4dc8863e
commit
87f906c6a7
|
@ -22,6 +22,9 @@ nameopt = default_ca
|
||||||
certopt = default_ca
|
certopt = default_ca
|
||||||
policy = policy_match
|
policy = policy_match
|
||||||
copy_extensions = copy
|
copy_extensions = copy
|
||||||
|
# We want those extensions only to generate the root certificates, so
|
||||||
|
# we specify it on the command line:
|
||||||
|
x509_extensions = v3_ca
|
||||||
|
|
||||||
[ policy_match ]
|
[ policy_match ]
|
||||||
countryName = match
|
countryName = match
|
||||||
|
@ -43,9 +46,6 @@ string_mask = nombstr
|
||||||
prompt = no
|
prompt = no
|
||||||
distinguished_name = req_distinguished_name
|
distinguished_name = req_distinguished_name
|
||||||
req_extensions = v3_req
|
req_extensions = v3_req
|
||||||
# We want those extensions only to generate the root certificates, so
|
|
||||||
# we specify it on the command line:
|
|
||||||
x509_extensions = v3_ca
|
|
||||||
|
|
||||||
[ req_distinguished_name ]
|
[ req_distinguished_name ]
|
||||||
organizationName = @ORG@
|
organizationName = @ORG@
|
||||||
|
|
|
@ -0,0 +1,3 @@
|
||||||
|
keyId= cnfFilePath=./ssl_mgmt.conf ../ssl_mgmt renew foo \
|
||||||
|
&& openssl x509 -in destdir/certs/foo-cert.pem -text -noout \
|
||||||
|
| grep "Version: 3"
|
|
@ -0,0 +1,2 @@
|
||||||
|
echo
|
||||||
|
echo "y"
|
|
@ -0,0 +1 @@
|
||||||
|
../restore_foo_fini
|
|
@ -0,0 +1 @@
|
||||||
|
../save_foo_init
|
Loading…
Reference in New Issue