Franco Fichtner
17cdb97707
src: strip all $FreeBSD$ tags to follow src.git
2023-09-06 08:20:29 +02:00
kulikov-a
f4f05f23d5
OpenSSL: follow RFC on basicConstraints too ( #6018 )
2022-09-13 13:24:54 +02:00
kulikov-a
7a06f387ca
OpenSSL: add keyUsage extension in CA config ( #6017 )
...
see https://www.rfc-editor.org/rfc/rfc5280.html#section-4.2.1.3
2022-09-12 19:42:56 +02:00
Josh Soref
20a3c3da38
Spelling ( #5885 )
2022-07-18 13:59:03 +02:00
vnxme
faf71c7e70
Fix nsComment inconsistency in OpenSSL config ( #3955 )
...
Read more about the Netscape extensions status:
https://www.openssl.org/docs/man1.0.2/man5/x509v3_config.html
2020-03-10 09:48:53 +01:00
Franco Fichtner
f7b87dfc43
system: 825 days is the current maximum so use it
...
Learned this the hard way on macOS Catalina behaviour. Since this
is a new policy enforced since 2019 it's safe to increase the defaults
(which were 10 years before) as well. Likely makes a few users
happy that had VPN certificates run out over the years.
2019-12-16 18:56:06 +01:00
Ad Schellevis
2f919443dc
cherry-pick https://github.com/opnsense/core/pull/3234
2019-03-01 18:35:50 +01:00
Franco Fichtner
d8579502b7
system: remove some fluff from OpenSSL config
2019-01-14 09:49:03 +00:00
Michael Steenbeek
ea8dce33ba
Add option to create combined client and server certificate, closes #2800 ( #3130 )
2019-01-14 10:16:09 +01:00
Michael Steenbeek
4d69429c30
Fix passing SANs to OpenSSL when generating CSRs ( #2967 )
2018-11-23 17:45:06 +01:00
Franco Fichtner
aac5b9eca0
trust: add "IP security IKE intermediate" to server key usage
2016-04-01 11:40:02 +02:00
Ad Schellevis
b57cdb64fe
(ssl) add template tag to v3_ca section
2015-12-15 11:01:03 +01:00
Ad Schellevis
025c096b70
(ssl) add server_cert section to openssl config
2015-12-15 10:57:48 +01:00
Ad Schellevis
9b432e836f
(legacy) openssl template for https://github.com/opnsense/core/issues/81
2015-12-14 20:53:43 +01:00
Franco Fichtner
966f6cee46
src: whitespace sweep
2015-08-19 07:43:13 +02:00
Franco Fichtner
c88a4f7fcf
certificates: use our own ssl config from now on for #280
...
Fixes LibreSSL shipping a not so usable openssl.cnf that gets picked
up by php-openssl for mostly random reasons.
2015-08-18 16:31:38 +02:00