Re: Importing a root CA as a name-constrained CA

2016-04-10 Thread Ángel González
On 2016-04-04 at 16:06 +0530, Geetika Kapoor wrote: > Hi, > > I think your missing on -. > > command should be > certutil -A -d . -n foo -i TooatCA.pem --extNC -t "C,C,C" > > Thanks Indeed. Thanks Geetika. Still, albeit this makes a certificate generation to prompt for the name contraints (I'd

Re: Importing a root CA as a name-constrained CA

2016-04-04 Thread Geetika Kapoor
Hi, I think your missing on -. command should be certutil -A -d . -n foo -i TooatCA.pem --extNC -t "C,C,C" Thanks On 04/04/2016 05:20 AM, Ángel González wrote: Hello all I have an unrestricted CA I would like to trust for *some* domains. The NSS seems to support this. It should be possible

Importing a root CA as a name-constrained CA

2016-04-03 Thread Ángel González
Hello all I have an unrestricted CA I would like to trust for *some* domains. The NSS seems to support this. It should be possible to use certutil with the -extNC parameter  (missing from [1], btw) to add the name constraint [2] to the legit subtree(s) So I tried with a command like:   certutil -