chiark / gitweb /
Merge branch 'master' of git://git.distorted.org.uk/~mdw/ca
authorMark Wooding <mdw@distorted.org.uk>
Thu, 6 Dec 2012 03:43:25 +0000 (03:43 +0000)
committerMark Wooding <mdw@distorted.org.uk>
Thu, 6 Dec 2012 03:43:25 +0000 (03:43 +0000)
* 'master' of git://git.distorted.org.uk/~mdw/ca:
  lib/func.tcl: Stupid long-standing typo in `sync-profiles'.
  test/update: Run `bin/update' before adding requests.
  bin/add: Don't allow adding requests with defunct profiles.
  bin/update: Refresh the profiles in the database from the configuration.
  lib/func.tcl, test/unit: Fix spin in `next-matching-date' and test.
  test/{init->update}: Less mad name for this test.

etc/config.tcl
etc/openssl.conf

index c47151844db7ae0e496a439b4f0df629923f839f..812b1d3187412dc6615f7030f42fc6c7011976ea 100644 (file)
@@ -1,23 +1,32 @@
 ### -*-tcl-*-
 
-set C(ca-owner) "mdw"
-set C(ca-group) "mdw"
-set C(ca-user) "mdw"
+set C(ca-owner) "root"
+set C(ca-group) "ca"
+
+set C(ca-name) {
+  countryName "GB"
+  stateOrProvinceName "Cambridgeshire"
+  localityName "Cambridge"
+  organizationName "distorted.org.uk"
+  commonName "distorted.org.uk Certificate Authority"
+  emailAddress "ca@distorted.org.uk"
+}
 
 set P(tls-client) {
   extensions tls-client-extensions
-  issue-time "*-*-* 03:00:00"
+  issue-time "*-*-* 00:00:00"
   start-skew 1
-  expire-interval 28
+  expire-interval 32
 }
 
 set P(tls-server) {
   extensions tls-server-extensions
-  issue-time "*-*-* 03:00:00"
+  issue-time "*-*-* 00:00:00"
   start-skew 1
-  expire-interval 28
+  expire-interval 32
 }
 
 proc update-hook {} {
-  exec rsync -av --delete-after crl ca.cert cert req test/publish 2>@stderr
+  exec 2>@stderr rsync -av --delete-after ca.cert crl cert req publish/
+  exec 2>@stderr userv root publish-ca
 }
index 847b1f5295376605fbbafe4d495e5a851f4061de..1fe673a7fa5e126169c5a80d5b415d3794dc274b 100644 (file)
@@ -5,7 +5,7 @@
 ###--------------------------------------------------------------------------
 ### Defaults.
 
-RANDFILE = /dev/urandom
+RANDFILE = /dev/random
 db_suffix =
 
 ###--------------------------------------------------------------------------