Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

[Users] Certificate Tree

From: WIAME Jean-Robert <jrw(at)ngi.be>
Date: Tue Feb 25 2003 - 08:52:13 EST

Hi all,
I want to create a CA tree like the following

  RootCA



| \

  v v
SubCA ...

|

  v
Client Cert

I have a RootCA, with this RootCA, I can generate, Client certificate or another sub root ca. The second level sub root ca can generate client certificate or another sub CA.
I use openssl (OpenSSL 0.9.6c 21 dec 2001) Until now, I'm able to generate the RootCA, the SubCA and the Client Certificate.
But when I import (PKCS12 format) the client certificate on windows2000, I must also import the SubCa. I must do that because I don't import the SubCA but the RootCA and for the Client Cert, the issuer is the SubCA not the RootCA
I import the SubCA. When I check the SubCA on windows, I see that the private key of the SubCA was also imported. That's not the case of the RootCA private key.

On the openssl.cnf, in the [ usr_cert ] section, the basic constraints is : basicConstraints=critical,CA:TRUE
when I generate the the SubCA and is : basicConstraints=CA:FALSE for the client certificate.

How could I generate a Certificate Tree where I need only to import the SubCA and the Client certificate on windows and where the SubCA's PK is not also imported?

Regards

Jean-Robert Wiame
Belgium



Users mailing list
Users@lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/users Received on Tue Feb 25 12:13:14 2003
Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:00:22 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library