From d614e8aa11f9520416f7ef10f93a29670efe1505 Mon Sep 17 00:00:00 2001 From: Stephen Gallagher Date: Thu, 21 Sep 2017 14:55:16 -0400 Subject: Require sscg 2.2.0 for creating service and CA certificates together Signed-off-by: Stephen Gallagher --- httpd-ssl-gencerts | 7 ++----- 1 file changed, 2 insertions(+), 5 deletions(-) (limited to 'httpd-ssl-gencerts') diff --git a/httpd-ssl-gencerts b/httpd-ssl-gencerts index 67b6d9a..371a838 100755 --- a/httpd-ssl-gencerts +++ b/httpd-ssl-gencerts @@ -5,18 +5,15 @@ set -e FQDN=`hostname` if test -f /etc/pki/tls/certs/localhost.crt -o \ - -f /etc/pki/tls/private/localhost.key -o \ - -f /etc/pki/tls/certs/localhost-ca.crt; then + -f /etc/pki/tls/private/localhost.key; then exit 1 fi sscg -q \ --cert-file /etc/pki/tls/certs/localhost.crt \ --cert-key-file /etc/pki/tls/private/localhost.key \ - --ca-file /etc/pki/tls/certs/localhost-ca.crt \ + --ca-file /etc/pki/tls/certs/localhost.crt \ --lifetime 365 \ --hostname $FQDN \ --email root@$FQDN -# mod_ssl will send the CA cert if it's appended to the server cert. -cat /etc/pki/tls/certs/localhost-ca.crt >> /etc/pki/tls/certs/localhost.crt -- cgit