$ openssl ca -gencrl -config conf/req.cnf -out crl/revoke.pem -crldays 30$ openssl crl -in crl/revoke.pem -outform DER -out crl/revoke.crl$ openssl ca -revoke newCerts/01.pem -config conf/req.cnf$ openssl ca -config conf/req.cnf -in req.pem -extensions serverClientCertificate -out signedReq.pem