X-Git-Url: https://git.distorted.org.uk/~mdw/ca/blobdiff_plain/ca2cccd082ee593d1593cac40dd51eee98890707..7e0f58bf390f14e3ff92dd4d260b57bd45715643:/etc/config.tcl diff --git a/etc/config.tcl b/etc/config.tcl index 47e61b6..ee8dd31 100644 --- a/etc/config.tcl +++ b/etc/config.tcl @@ -14,19 +14,30 @@ set C(ca-name) { set P(tls-client) { extensions tls-client-extensions - issue-time "*-*-* 03:00:00" + issue-time "*-*-* 00:00:00" start-skew 1 - expire-interval 2 + expire-interval 32 } set P(tls-server) { extensions tls-server-extensions - issue-time "*-*-* 03:00:00" + issue-time "*-*-* 00:00:00" start-skew 1 - expire-interval 2 + expire-interval 32 +} + +set P(tls-server-longterm) { + extensions tls-server-extensions + issue-time "*-*-* 00:00:00" + start-skew 1 + expire-interval 43838 } proc update-hook {} { - exec 2>@stderr rsync -av --delete-after ca.cert crl cert req publish/ - exec 2>@stderr userv root publish-ca + global env + if {![info exists env(CA_BODGE)]} { + exec 2>@stderr rsync -rtv --delete-delay \ + ca.cert crl cert req archive \ + sysupl-ca@stratocaster.distorted.org.uk:files/ + } }