From: Mark Wooding Date: Sat, 1 Dec 2012 20:01:27 +0000 (+0000) Subject: Merge branch 'master' of git://git.distorted.org.uk/~mdw/ca X-Git-Url: https://git.distorted.org.uk/~mdw/ca/commitdiff_plain/ca2cccd082ee593d1593cac40dd51eee98890707?hp=16a2848ca54c479a6121d7864efb1f935761bbe8 Merge branch 'master' of git://git.distorted.org.uk/~mdw/ca * 'master' of git://git.distorted.org.uk/~mdw/ca: lib/func.tcl: Hack output of `openssl dgst -hex'. etc/openssl.conf: Allow `keyEncipherment' for TLS clients. --- diff --git a/etc/config.tcl b/etc/config.tcl index c471518..47e61b6 100644 --- a/etc/config.tcl +++ b/etc/config.tcl @@ -1,23 +1,32 @@ ### -*-tcl-*- -set C(ca-owner) "mdw" -set C(ca-group) "mdw" -set C(ca-user) "mdw" +set C(ca-owner) "root" +set C(ca-group) "ca" + +set C(ca-name) { + countryName "GB" + stateOrProvinceName "Cambridgeshire" + localityName "Cambridge" + organizationName "distorted.org.uk" + commonName "distorted.org.uk Certificate Authority" + emailAddress "ca@distorted.org.uk" +} set P(tls-client) { extensions tls-client-extensions issue-time "*-*-* 03:00:00" start-skew 1 - expire-interval 28 + expire-interval 2 } set P(tls-server) { extensions tls-server-extensions issue-time "*-*-* 03:00:00" start-skew 1 - expire-interval 28 + expire-interval 2 } proc update-hook {} { - exec rsync -av --delete-after crl ca.cert cert req test/publish 2>@stderr + exec 2>@stderr rsync -av --delete-after ca.cert crl cert req publish/ + exec 2>@stderr userv root publish-ca } diff --git a/etc/openssl.conf b/etc/openssl.conf index 847b1f5..1fe673a 100644 --- a/etc/openssl.conf +++ b/etc/openssl.conf @@ -5,7 +5,7 @@ ###-------------------------------------------------------------------------- ### Defaults. -RANDFILE = /dev/urandom +RANDFILE = /dev/random db_suffix = ###--------------------------------------------------------------------------