Add random serial# support.
authorRich Salz <rsalz@openssl.org>
Wed, 16 Aug 2017 19:49:25 +0000 (15:49 -0400)
committerRich Salz <rsalz@openssl.org>
Tue, 22 Aug 2017 13:00:04 +0000 (09:00 -0400)
commitffb46830e2dfd3203044e6190f50a20fec50162d
tree744d016ce5d6dea1aa48a36e95024d8333dff969
parent932c0df29b7a5a2902c52e2f536b5b83392e2d42
Add random serial# support.

Add -rand_serial to CA command and "serial_rand" config option.

Up RAND_BITS to 159, and comment why: now confirms to CABForum
guidelines (Ballot 164) as well as IETF RFC 5280 (PKIX).

Reviewed-by: Richard Levitte <levitte@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/4185)
apps/apps.c
apps/apps.h
apps/ca.c
doc/man1/ca.pod
test/recipes/80-test_ca.t