dropped -selfsign option; revoke certificates that are re-generated but not expired...
authorale <ale@9de0ac56-b551-4d3d-a58d-d429de429fdc>
Thu, 7 Dec 2006 09:39:27 +0000 (09:39 +0000)
committerale <ale@9de0ac56-b551-4d3d-a58d-d429de429fdc>
Thu, 7 Dec 2006 09:39:27 +0000 (09:39 +0000)
lib/cfg.pyc
lib/gen.py
lib/newca.py
lib/utils.pyc

index a86d8be..ad590fa 100644 (file)
Binary files a/lib/cfg.pyc and b/lib/cfg.pyc differ
index 526e52f..42795fe 100644 (file)
@@ -33,6 +33,10 @@ def gen(tag):
            ans = raw_input('This certificate seems to exist already (in %s).\nAre you really sure that you want to re-create it? [y/N]  ' % crt_file)
            if not ans or ans[0].lower() != 'y':
                sys.exit(0)
+           print 'Revoking previous certificate...'
+            openssl('ca', '-config', conf_file, 
+                    '-revoke', public_crt_file)
+           
 
     # create custom config file
     template(conf_file,
index f036552..7519b31 100644 (file)
@@ -47,7 +47,7 @@ def newca():
        openssl('ca', 
                '-config', conf_file, '-batch',
                '-keyfile', ca_key_file,
-               '-extensions', 'v3_ca', '-selfsign',
+               '-extensions', 'v3_ca', 
                '-out', ca_file,
                '-infiles', ca_csr_file)
        openssl('ca', 
index fe39ff8..dbfbb24 100644 (file)
Binary files a/lib/utils.pyc and b/lib/utils.pyc differ