[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] [RaQ3] Newbie 128 bit cert query (UK)



On Thu, 2 Nov 2000, Jeff Lasman wrote:

> andy.hughes@xxxxxxxxxxxxxxxxx wrote:
> 
> > *** Background:
> >  Key, CSR and certificate generated using openSSL.
> >  (Certificate originally intended for another server).
> 
> Server name has to be the same (if it used to be called
> "secure.domain.com" on the old server, it must be "secure.domain.com" on
> the new server as well).
> 
> Graeme pointed out that the IP# has to be the same as well.  While I've
> heard this is true, I'm not positive that it's indeed the case; are you
> positive, Graeme?
No Jeff, IP's doesn't have to be the same, if you used the FQDN when
registgering the certificate, but if you entered the IP instead of FQDN
then yes, then you can't change IP-address either...

Stupid? Yes, but then, that's SSL (all implementations you can think
off!) for you... believe me! I've tested almost any combination of
settings when it comes to SSL domain-name and ip-address...

Best regards,

Rickard Osser
Manager
-----------------------------------------------------------------------
|Osser Lindist AB		Distributor of Cobalt Networks servers|
-----------------------------------------------------------------------
|Osser Brosoft AB		Computer Consultants                  |
-----------------------------------------------------------------------
|Maria Bangata 6		S-118 63 Stockholm, Sweden 	      |
|Tel: +46-8-798 29 27		E-mail: ricky@xxxxxxxx		      |
|Fax: +46-8-668 89 10		http://www.lindist.com   	      |
-----------------------------------------------------------------------