From owner-freebsd-doc@FreeBSD.ORG Sat May 14 04:31:07 2005 Return-Path: Delivered-To: freebsd-doc@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 1CD2B16A4CE; Sat, 14 May 2005 04:31:07 +0000 (GMT) Received: from sccrmhc11.comcast.net (sccrmhc11.comcast.net [204.127.202.55]) by mx1.FreeBSD.org (Postfix) with ESMTP id 8E55343D1D; Sat, 14 May 2005 04:31:06 +0000 (GMT) (envelope-from brett@brettschroeder.name) Received: from anapurna.brettschroeder.name (c-24-20-125-129.hsd1.or.comcast.net[24.20.125.129]) by comcast.net (sccrmhc11) with ESMTP id <2005051404310501100jq70ae>; Sat, 14 May 2005 04:31:06 +0000 Received: from [192.168.0.7] (K2 [192.168.0.7]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (verified OK)) by Anapurna.brettschroeder.name (Postfix) with ESMTP id 6FC00612F; Fri, 13 May 2005 21:31:03 -0700 (PDT) Message-ID: <42857F0D.4040508@brettschroeder.name> Date: Fri, 13 May 2005 21:31:09 -0700 From: Brett Schroeder User-Agent: Mozilla Thunderbird 1.0.2 (X11/20050326) X-Accept-Language: en-us, en MIME-Version: 1.0 To: Ceri Davies References: <42804274.4050002@brettschroeder.name> <9cfae07f8f5c8f5d261e05f0d7355bdd@submonkey.net> In-Reply-To: <9cfae07f8f5c8f5d261e05f0d7355bdd@submonkey.net> X-Enigmail-Version: 0.90.0.0 X-Enigmail-Supports: pgp-inline, pgp-mime Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit cc: freebsd-doc@freebsd.org cc: Ceri Davies Subject: Re: OpenSSL: Handbook says "send *private* key to CA" ?? X-BeenThere: freebsd-doc@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Documentation project List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 14 May 2005 04:31:07 -0000 Ceri Davies wrote: > > On 10 May 2005, at 06:11, Brett Schroeder wrote: > >> # openssl req -new -nodes -out req.pem -keyout cert.pem >> >> and then a few lines later the text says >> >> "A cert.pem file should now exist in the directory which the >> aforementioned command was issued. This is the certificate which may be >> sent to any CA for signing." >> >>> From the "openssl req" man page >> >> >> -keyout filename >> this gives the filename to write the newly created private >> key to. >> If this option is not specified then the filename present >> in the >> configuration file is used. >> >> Thoughts? > > > [Liberal snippage in the above] > > Hi Brett, > > You're quite right about this; how do you find the attached diff? > > Ceri Ceri, Looks good. You gonna submit it? Brett