From: Mark Wooding Date: Sat, 1 Dec 2012 20:01:05 +0000 (+0000) Subject: Configuration for production. X-Git-Url: https://git.distorted.org.uk/~mdw/ca/commitdiff_plain/c4e3d3a6add39811cbae3ce697c1a5d9f7246d6a Configuration for production. --- diff --git a/etc/config.tcl b/etc/config.tcl index c471518..47e61b6 100644 --- a/etc/config.tcl +++ b/etc/config.tcl @@ -1,23 +1,32 @@ ### -*-tcl-*- -set C(ca-owner) "mdw" -set C(ca-group) "mdw" -set C(ca-user) "mdw" +set C(ca-owner) "root" +set C(ca-group) "ca" + +set C(ca-name) { + countryName "GB" + stateOrProvinceName "Cambridgeshire" + localityName "Cambridge" + organizationName "distorted.org.uk" + commonName "distorted.org.uk Certificate Authority" + emailAddress "ca@distorted.org.uk" +} set P(tls-client) { extensions tls-client-extensions issue-time "*-*-* 03:00:00" start-skew 1 - expire-interval 28 + expire-interval 2 } set P(tls-server) { extensions tls-server-extensions issue-time "*-*-* 03:00:00" start-skew 1 - expire-interval 28 + expire-interval 2 } proc update-hook {} { - exec rsync -av --delete-after crl ca.cert cert req test/publish 2>@stderr + exec 2>@stderr rsync -av --delete-after ca.cert crl cert req publish/ + exec 2>@stderr userv root publish-ca } diff --git a/etc/openssl.conf b/etc/openssl.conf index 4fa74a5..1accc80 100644 --- a/etc/openssl.conf +++ b/etc/openssl.conf @@ -5,7 +5,7 @@ ###-------------------------------------------------------------------------- ### Defaults. -RANDFILE = /dev/urandom +RANDFILE = /dev/random db_suffix = ###--------------------------------------------------------------------------