aboutsummaryrefslogtreecommitdiffstats
path: root/apps/openssl.cnf
Commit message (Collapse)AuthorAgeFilesLines
* Show an example of moving the emailAddress object from the subkect DNRichard Levitte2001-04-111-0/+3
| | | | to subjectAltName when signing a certificate.
* Add copy_extensions option to 'ca' utility.Dr. Stephen Henson2001-03-161-0/+3
|
* Add 'align' option to nameopt.Dr. Stephen Henson2001-03-151-0/+5
| | | | | | | Add default values for display by the 'ca' utility to openssl.cnf Update docs.
* increase emailAddress_maxBodo Möller2001-03-041-1/+1
|
* Initial automation changes to 'req' and X509_ATTRIBUTE functions.Dr. Stephen Henson2000-01-061-4/+3
|
* Fix some of the command line password stuff. New functionDr. Stephen Henson2000-01-011-1/+3
| | | | | | | that can automatically determine the type of a DER encoded "traditional" format private key and change some of the d2i functions to use it instead of requiring the application to work out the key type.
* Allow passwords to be included on command line for a fewDr. Stephen Henson1999-12-241-0/+7
| | | | more utilities.
* Continued multibyte character support.Dr. Stephen Henson1999-10-271-0/+11
| | | | | | | Add a bunch of functions to simplify the creation of X509_NAME structures. Change the X509_NAME_entry_add stuff in req/ca so it no longer uses X509_NAME_entry_count(): passing -1 has the same effect.
* Allow extensions to be added to certificate requests, update the sampleDr. Stephen Henson1999-08-251-3/+14
| | | | config file (change RAW to DER).
* consistent styleRalf S. Engelschall1999-08-081-1/+1
|
* Include some notes on basic extension usage and change openssl.cnf to usuallyDr. Stephen Henson1999-05-191-19/+27
| | | | do sensible things with extensions.
* Rename "openssl x509" option "-config" to "-extfile", because itBodo Möller1999-05-171-1/+1
| | | | | doesn't have a default value like the "-config" options of other openssl subprograms.
* Added a comment pointing out the behaviour of "openssl x509 -conf ...",Bodo Möller1999-05-161-0/+7
| | | | which cost me some time to find out about.
* Added support for adding extensions to CRLs, also fix a memory leak andDr. Stephen Henson1999-03-061-0/+9
| | | | | make 'req' check the config file syntax before it adds extensions. Added info in the documentation as well.
* Redo the way 'req' and 'ca' add objects: add support for oid_section.Dr. Stephen Henson1999-02-231-1/+10
|
* Add more functionality to issuer alt name and subject alt name. New optionsDr. Stephen Henson1999-02-211-0/+12
| | | | | to include email addresses from DN and copy details from issuer certificate. Include examples in openssl.cnf, update Win32 ordinals.
* Oops! Remeber to include the other patches this time...Dr. Stephen Henson1999-02-171-0/+6
|
* Add support for raw extensions. This means that you can include the DER encodingDr. Stephen Henson1999-02-141-0/+5
| | | | | | | | of an arbitrary extension: e.g. 1.3.4.5=critical,RAW:12:34:56 Using this technique currently unsupported extensions can be generated if you know their DER encoding. Even if the extension is supported in future the raw extension will still work: that is the raw version can always be used even if it is a supported extension.
* More extension code. Incomplete support for subject and issuer altDr. Stephen Henson1999-02-101-0/+5
| | | | | | | name, issuer and authority key id. Change the i2v function parameters and add an extra 'crl' parameter in the X509V3_CTX structure: guess what that's for :-) Fix to ASN1 macro which messed up IMPLICIT tag and add f_enum.c which adds a2i, i2a for ENUMERATED.
* Still more X509 V3 stuff. Modify ca.c to work with the new code and modifyDr. Stephen Henson1999-01-261-11/+36
| | | | openssl.cnf for the new syntax.
* More X509 V3 stuff. Add support for extensions in the 'req' applicationDr. Stephen Henson1999-01-251-0/+9
| | | | | | | so that: openssl req -x509 -new -out cert.pem will take extensions from openssl.cnf a sample for a CA is included. Also change the directory order so pem is nearer the end. Otherwise 'make links' wont work because pem.h can't be built.
* First cut of a cleanup for apps/. First the `ssleay' program is now namedRalf S. Engelschall1999-01-021-3/+3
| | | | | | | | | `openssl' and second, the shortcut symlinks for the `openssl <command>' are no longer created. This way we have a single and consistent command line interface `openssl <command>', similar to `cvs <command>'. Notice, the openssl.cnf, openssl.c and progs.pl files were changed after a repository copy, i.e. they still contain the complete file history.
* Import of old SSLeay release: SSLeay 0.9.1b (unreleased)Ralf S. Engelschall1998-12-211-0/+3
|
* Import of old SSLeay release: SSLeay 0.8.1bRalf S. Engelschall1998-12-211-0/+116