====== Usage CA ====== ===== CRL ===== * Generate CRL : ''$ openssl ca -gencrl -config conf/req.cnf -out crl/revoke.pem -crldays 30'' * Convert to DER format (used by browsers) : ''$ openssl crl -in crl/revoke.pem -outform DER -out crl/revoke.crl'' ===== Revoke a certificate ===== * ''$ openssl ca -revoke newCerts/01.pem -config conf/req.cnf'' ===== Sign with different predefined extensions ===== * ''$ openssl ca -config conf/req.cnf -in req.pem -extensions serverClientCertificate -out signedReq.pem''