From 9ab899a660b30d80d844c5d1be9998180c91149a Mon Sep 17 00:00:00 2001 From: Richard Levitte Date: Sun, 26 Feb 2006 10:48:40 +0000 Subject: [PATCH] Synchronise with openss.cnf --- apps/openssl-vms.cnf | 9 ++++----- 1 file changed, 4 insertions(+), 5 deletions(-) diff --git a/apps/openssl-vms.cnf b/apps/openssl-vms.cnf index 6685cf1df1..c8e1a61a11 100644 --- a/apps/openssl-vms.cnf +++ b/apps/openssl-vms.cnf @@ -115,13 +115,12 @@ x509_extensions = v3_ca # The extentions to add to the self signed cert # This sets a mask for permitted string types. There are several options. # default: PrintableString, T61String, BMPString. -# pkix : PrintableString, BMPString. -# utf8only: only UTF8Strings. +# pkix : PrintableString, BMPString (PKIX recommendation before 2004) +# utf8only: only UTF8Strings (PKIX recommendation after 2004). # nombstr : PrintableString, T61String (no BMPStrings or UTF8Strings). # MASK:XXXX a literal mask value. -# WARNING: current versions of Netscape crash on BMPStrings or UTF8Strings -# so use this option with caution! -string_mask = nombstr +# WARNING: ancient versions of Netscape crash on BMPStrings or UTF8Strings. +string_mask = utf8only # req_extensions = v3_req # The extensions to add to a certificate request -- 2.34.1