mirror of
https://github.com/openssl/openssl.git
synced 2024-11-27 05:21:51 +08:00
18d7158809
is required by client or server. An application can decide which certificate chain to present based on arbitrary criteria: for example supported signature algorithms. Add very simple example to s_server. This fixes many of the problems and restrictions of the existing client certificate callback: for example you can now clear existing certificates and specify the whole chain. |
||
---|---|---|
.. | ||
apps | ||
ca.cnf | ||
mkcerts.sh | ||
README |
There is often a need to generate test certificates automatically using a script. This is often a cause for confusion which can result in incorrect CA certificates, obsolete V1 certificates or duplicate serial numbers. The range of command line options can be daunting for a beginner. This is a simple example of how to generate certificates automatically using scripts. Example creates a root CA, a server certificate signed by the root, an intermediate CA signed by the root and finally a client certificate signed by the intermediate CA.