Thread (47 messages) 47 messages, 12 authors, 2013-03-19

Re: Wrong system clock vs X.509 date specifiers

From: Tomas Mraz <hidden>
Date: 2012-09-25 18:39:31
Also in: lkml

On Tue, 2012-09-25 at 18:31 +0100, David Howells wrote: 
Tomas Mraz [off-list ref] wrote:
quoted
You can use openssl ca that allows to set arbitrary start date to
generate selfsigned certs as well (-selfsign option).
That seems to require some stuff I don't have installed:

warthog>openssl ca -in signing_key.priv -extensions v3_ca -out newcert.pem
Using configuration from /etc/pki/tls/openssl.cnf
Error opening CA private key /etc/pki/CA/private/cakey.pem
140244246955872:error:0200100D:system library:fopen:Permission denied:bss_file.c:398:fopen('/etc/pki/CA/private/cakey.pem','r')
140244246955872:error:20074002:BIO routines:FILE_CTRL:system lib:bss_file.c:400:
unable to load CA private key
unable to write 'random state'

(the /etc/pki/CA/private/ dir is inaccessible if not root and doesn't in any
case contain cakey.pem).

Do I need to start with all the CA stuff in the right places to use it?
You can configure it to point to a different directories. But yes, you
have to create a CA cert and so on. 
-- 
Tomas Mraz
No matter how far down the wrong road you've gone, turn back.
                                              Turkish proverb
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help