The reason for the breakage is that something in the behaviour of openssl has changed between versions 0.9.7e-3, which is part of Sarge, and 0.9.7g-1 and newer.
This leads not only to an infinite loop at startup (which is fixed by at least one of the submitted patches) but also to a problem dealing with CRLs: Revoked certificates remain "valid" in the TinyCA UI, although they are in fact revoked. I will soon prepare a package for TinyCA 0.7.0 which thoroughly fixes this bug. uLI -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]