Re: distinguished name order
Jochen Bern <[email protected]> Wed, 30 Jul 2025 09:54:09 +0200
| Newsgroups | gmane.comp.encryption.openssl.user |
|---|---|
| Organization | Binect GmbH |
| Message-ID | <[email protected]> |
On 30.07.25 00:19, Mike wrote: [about ordering of elements within the DN] > Is this correct as is? Is it a known issue? The manual pages don't really > talk about it. I'm not familiar with the historical LDAP usages. All talk about *current* standards aside, if you plan to run things in the long term, you'll need to be prepared to see these standards change. The current two *nominal* root CA certs of our company both have ultimately been created with OpenSSL (of their time), and lo: > $ ChainCat RootCA-?/root_ca.crt > > ### RootCA-A/root_ca.crt ### > > CERTIFICATE: > subject=CN=Root CA, O=pawisda systems GmbH, L=Weiterstadt, ST=Hessen, C=DE > issuer=CN=Root CA, O=pawisda systems GmbH, L=Weiterstadt, ST=Hessen, C=DE > notBefore=Oct 18 22:00:00 2012 GMT > notAfter=Oct 5 22:00:00 2028 GMT > > ### RootCA-B/root_ca.crt ### > > CERTIFICATE: > subject=C=DE, ST=Hessen, L=Weiterstadt, O=Binect GmbH, CN=Root CA - B, [email protected] > issuer=C=DE, ST=Hessen, L=Weiterstadt, O=Binect GmbH, CN=Root CA - B, [email protected] > notBefore=Oct 7 16:19:21 2020 GMT > notAfter=Sep 26 16:19:21 2036 GMT Kind regards, -- Jochen Bern Systemingenieur Binect GmbH -- You received this message because you are subscribed to the Google Groups "openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/acba6d99-7e57-4d2f-ad1f-66a965abc3f1%40binect.de.
smime.p7s
(application/pkcs7-signature, 4.2 KB) - not displayed