Commit Graph

6 Commits

Author SHA1 Message Date
Chris Buechler
68ebb88416 Add IPsec IKE Intermediate EKU to server certificates. The serverAuth EKU already added suffices for Windows clients, though strongswan docs suggest setting this as well. 2015-07-20 23:46:07 -05:00
Chris Buechler
b27567ca40 Specify keyUsage and extendedKeyUsage in openssl.cnf, use crl_ext. 2015-07-20 20:20:49 -05:00
yarick123
3cb773da77 cherry pic from 'hotfix/3347-Certificate_Authority_SAN_names_not_working':
bugfix #3347: Certificate Authority SAN names not working in 2.1

subjectAltName can be set _only_ via configuration file - created three extra sections in openssl.cnf to use in case of existing subjectAltName.

Unfortunately it is not possible to assign empty value to subjectAltName in openssl.cnf
2014-08-14 02:18:32 +02:00
Chris Buechler
fe3553d16d default openssl to 2048 2014-03-06 16:10:33 -06:00
jim-p
7aaabd69b0 When creating an internal certificate, offer the user a choice of what constraints to place upon the certificate (CA, Server, or User). 2011-11-09 15:43:49 -05:00
Scott Ullrich
13128695a8 Create certificate for HTTP Server option 2004-11-17 22:59:17 +00:00