X-Git-Url: https://git.distorted.org.uk/~mdw/ca/blobdiff_plain/a0eb4b7ff6c91bc31b185345e9057a85c7efcb12..4e62e2005e4f253e988a3e8b15486f23b606f207:/etc/config.tcl diff --git a/etc/config.tcl b/etc/config.tcl index 47e61b6..ad98137 100644 --- a/etc/config.tcl +++ b/etc/config.tcl @@ -14,19 +14,30 @@ set C(ca-name) { set P(tls-client) { extensions tls-client-extensions - issue-time "*-*-* 03:00:00" + issue-time "*-*-* 00:00:00" start-skew 1 - expire-interval 2 + expire-interval 32 } set P(tls-server) { extensions tls-server-extensions - issue-time "*-*-* 03:00:00" + issue-time "*-*-* 00:00:00" start-skew 1 - expire-interval 2 + expire-interval 32 +} + +set P(tls-server-longterm) { + extensions tls-server-extensions + issue-time "*-03-01 00:00:00" + start-skew 1 + expire-interval 43838 } proc update-hook {} { - exec 2>@stderr rsync -av --delete-after ca.cert crl cert req publish/ - exec 2>@stderr userv root publish-ca + global env + if {![info exists env(CA_BODGE)]} { + exec 2>@stderr rsync -rtl --delete-delay \ + ca.cert crl cert req archive \ + sysupl-ca@stratocaster.distorted.org.uk:files/ + } }