Configuration for production.
authorMark Wooding <mdw@distorted.org.uk>
Sat, 1 Dec 2012 20:01:05 +0000 (20:01 +0000)
committerMark Wooding <mdw@distorted.org.uk>
Sat, 1 Dec 2012 20:01:05 +0000 (20:01 +0000)
etc/config.tcl
etc/openssl.conf

index c471518..47e61b6 100644 (file)
@@ -1,23 +1,32 @@
 ### -*-tcl-*-
 
-set C(ca-owner) "mdw"
-set C(ca-group) "mdw"
-set C(ca-user) "mdw"
+set C(ca-owner) "root"
+set C(ca-group) "ca"
+
+set C(ca-name) {
+  countryName "GB"
+  stateOrProvinceName "Cambridgeshire"
+  localityName "Cambridge"
+  organizationName "distorted.org.uk"
+  commonName "distorted.org.uk Certificate Authority"
+  emailAddress "ca@distorted.org.uk"
+}
 
 set P(tls-client) {
   extensions tls-client-extensions
   issue-time "*-*-* 03:00:00"
   start-skew 1
-  expire-interval 28
+  expire-interval 2
 }
 
 set P(tls-server) {
   extensions tls-server-extensions
   issue-time "*-*-* 03:00:00"
   start-skew 1
-  expire-interval 28
+  expire-interval 2
 }
 
 proc update-hook {} {
-  exec rsync -av --delete-after crl ca.cert cert req test/publish 2>@stderr
+  exec 2>@stderr rsync -av --delete-after ca.cert crl cert req publish/
+  exec 2>@stderr userv root publish-ca
 }
index 4fa74a5..1accc80 100644 (file)
@@ -5,7 +5,7 @@
 ###--------------------------------------------------------------------------
 ### Defaults.
 
-RANDFILE = /dev/urandom
+RANDFILE = /dev/random
 db_suffix =
 
 ###--------------------------------------------------------------------------