Project

General

Profile

Actions

Bug #4860

closed
CB RB

CRLs missing authorityKeyIdentifier

Bug #4860: CRLs missing authorityKeyIdentifier

Added by Chris Buechler about 11 years ago. Updated about 11 years ago.

Status:
Resolved
Priority:
Normal
Category:
Certificates
Target version:
Start date:
07/21/2015
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
All
Affected Architecture:

Description

CRLs generated by the built-in certificate manager should include authorityKeyIdentifier. This was changed in openssl.cnf, but isn't getting picked up when creating CRLs in the built-in cert manager. The openssl_crl* functions don't seem to take an args array the way the other openssl_* functions do (where "x509_extensions" => "crl_ext" in $args array would suffice).

RB Updated by Renato Botelho about 11 years ago Actions #1

  • Assignee set to Renato Botelho

Checking

RB Updated by Renato Botelho about 11 years ago Actions #2

  • Status changed from Confirmed to Feedback
  • % Done changed from 0 to 100

Fixed, please try next snaps

CB Updated by Chris Buechler about 11 years ago Actions #3

looks good, works with IPsec now, and still works with OpenVPN. want to get additional feedback and testing before closing out.

CB Updated by Chris Buechler about 11 years ago Actions #4

  • Status changed from Feedback to Resolved

fixed

Actions

Also available in: Atom