Create a certificate request with a SN field

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
2 messages Options
Reply | Threaded
Open this post in threaded view
|

Create a certificate request with a SN field

Miguel García-3
Hello,

I am trying to create a certicate request with a SN field, but i am not able to
find the method for do this.

I use the command below to create the certificate request:

openssl req -new -key client.key -out client.csr

This certificate request has the next fields:

"CN=Name, OU=Department,O=Company, L=Valencia, S=Comunidad Valenciana"

But i would like generate a request with the fields:

"CN=Name, OU=Department,O=Company, L=Valencia, S=Comunidad Valenciana, SN=11111111H"

I have read the openssl documentation, and the sintaxis
of the openssl configuration file, but i can not find
the right way.

Could yo help me? I would be grateful if you could give
me any idea



LLama Gratis a cualquier PC del Mundo.
Llamadas a fijos y móviles desde 1 céntimo por minuto.
http://es.voice.yahoo.com
Reply | Threaded
Open this post in threaded view
|

Re: Create a certificate request with a SN field

Takaaki Ishii
Hi,

Miguel-san wrote:
>  This certificate request has the next fields:
>  
>  "CN=Name, OU=Department,O=Company, L=Valencia, S=Comunidad Valenciana"
>  
>  But i would like generate a request with the fields:
>  
>  "CN=Name, OU=Department,O=Company, L=Valencia, S=Comunidad Valenciana, SN=
11111111H"
>  
>  I have read the openssl documentation, and the sintaxis
>  of the openssl configuration file, but i can not find
>  the right way.

CHANGES file in openssl source distribution has following description:
(at least openssl-0.9.7g)

---- quotation begin ----
  *) Make object definitions compliant to LDAP (RFC2256): SN is the short
     form for "surname", serialNumber has no short form.
---- quotation end ----

So, if you aim "SN" as serialNumber (not surname),
how about to add serialNumber naming attribute to openssl.cnf file,
like:
--------------
[ policy_anything ]
countryName             = optional
        :
emailAddress            = optional
serialNumber            = optional (*)
        :
emailAddress                    = Email Address
emailAddress_max                = 64

serialNumber                    = Serial Number (*)
--------------
(*) - added line

(I do not know surely *right* way...)
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [hidden email]
Automated List Manager                           [hidden email]