isaacpittman-hitachi / rpms / openssl

Forked from rpms/openssl 2 years ago
Clone
727bdf
diff --git a/test/certs/embeddedSCTs1_issuer.pem b/test/certs/embeddedSCTs1_issuer.pem
727bdf
index 1fa449d5a098..6aa9455f09ed 100644
727bdf
--- a/test/certs/embeddedSCTs1_issuer.pem
727bdf
+++ b/test/certs/embeddedSCTs1_issuer.pem
727bdf
@@ -1,18 +1,18 @@
727bdf
 -----BEGIN CERTIFICATE-----
727bdf
-MIIC0DCCAjmgAwIBAgIBADANBgkqhkiG9w0BAQUFADBVMQswCQYDVQQGEwJHQjEk
727bdf
+MIIC0jCCAjugAwIBAgIBADANBgkqhkiG9w0BAQsFADBVMQswCQYDVQQGEwJHQjEk
727bdf
 MCIGA1UEChMbQ2VydGlmaWNhdGUgVHJhbnNwYXJlbmN5IENBMQ4wDAYDVQQIEwVX
727bdf
-YWxlczEQMA4GA1UEBxMHRXJ3IFdlbjAeFw0xMjA2MDEwMDAwMDBaFw0yMjA2MDEw
727bdf
-MDAwMDBaMFUxCzAJBgNVBAYTAkdCMSQwIgYDVQQKExtDZXJ0aWZpY2F0ZSBUcmFu
727bdf
-c3BhcmVuY3kgQ0ExDjAMBgNVBAgTBVdhbGVzMRAwDgYDVQQHEwdFcncgV2VuMIGf
727bdf
-MA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDVimhTYhCicRmTbneDIRgcKkATxtB7
727bdf
-jHbrkVfT0PtLO1FuzsvRyY2RxS90P6tjXVUJnNE6uvMa5UFEJFGnTHgW8iQ8+EjP
727bdf
-KDHM5nugSlojgZ88ujfmJNnDvbKZuDnd/iYx0ss6hPx7srXFL8/BT/9Ab1zURmnL
727bdf
-svfP34b7arnRsQIDAQABo4GvMIGsMB0GA1UdDgQWBBRfnYgNyHPmVNT4DdjmsMEk
727bdf
-tEfDVTB9BgNVHSMEdjB0gBRfnYgNyHPmVNT4DdjmsMEktEfDVaFZpFcwVTELMAkG
727bdf
-A1UEBhMCR0IxJDAiBgNVBAoTG0NlcnRpZmljYXRlIFRyYW5zcGFyZW5jeSBDQTEO
727bdf
-MAwGA1UECBMFV2FsZXMxEDAOBgNVBAcTB0VydyBXZW6CAQAwDAYDVR0TBAUwAwEB
727bdf
-/zANBgkqhkiG9w0BAQUFAAOBgQAGCMxKbWTyIF4UbASydvkrDvqUpdryOvw4BmBt
727bdf
-OZDQoeojPUApV2lGOwRmYef6HReZFSCa6i4Kd1F2QRIn18ADB8dHDmFYT9czQiRy
727bdf
-f1HWkLxHqd81TbD26yWVXeGJPE3VICskovPkQNJ0tU4b03YmnKliibduyqQQkOFP
727bdf
-OwqULg==
727bdf
+YWxlczEQMA4GA1UEBxMHRXJ3IFdlbjAgFw0yMjA2MDExMDM4MDJaGA8yMTIyMDUw
727bdf
+ODEwMzgwMlowVTELMAkGA1UEBhMCR0IxJDAiBgNVBAoTG0NlcnRpZmljYXRlIFRy
727bdf
+YW5zcGFyZW5jeSBDQTEOMAwGA1UECBMFV2FsZXMxEDAOBgNVBAcTB0VydyBXZW4w
727bdf
+gZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBANWKaFNiEKJxGZNud4MhGBwqQBPG
727bdf
+0HuMduuRV9PQ+0s7UW7Oy9HJjZHFL3Q/q2NdVQmc0Tq68xrlQUQkUadMeBbyJDz4
727bdf
+SM8oMczme6BKWiOBnzy6N+Yk2cO9spm4Od3+JjHSyzqE/HuytcUvz8FP/0BvXNRG
727bdf
+acuy98/fhvtqudGxAgMBAAGjga8wgawwHQYDVR0OBBYEFF+diA3Ic+ZU1PgN2Oaw
727bdf
+wSS0R8NVMH0GA1UdIwR2MHSAFF+diA3Ic+ZU1PgN2OawwSS0R8NVoVmkVzBVMQsw
727bdf
+CQYDVQQGEwJHQjEkMCIGA1UEChMbQ2VydGlmaWNhdGUgVHJhbnNwYXJlbmN5IENB
727bdf
+MQ4wDAYDVQQIEwVXYWxlczEQMA4GA1UEBxMHRXJ3IFdlboIBADAMBgNVHRMEBTAD
727bdf
+AQH/MA0GCSqGSIb3DQEBCwUAA4GBAD0aYh9OkFYfXV7kBfhrtD0PJG2U47OV/1qq
727bdf
++uFpqB0S1WO06eJT0pzYf1ebUcxjBkajbJZm/FHT85VthZ1lFHsky87aFD8XlJCo
727bdf
+2IOhKOkvvWKPUdFLoO/ZVXqEVKkcsS1eXK1glFvb07eJZya3JVG0KdMhV2YoDg6c
727bdf
+Doud4XrO
727bdf
 -----END CERTIFICATE-----
727bdf
diff --git a/test/certs/sm2-ca-cert.pem b/test/certs/sm2-ca-cert.pem
727bdf
index 5677ac6c9f6a..70ce71e43091 100644
727bdf
--- a/test/certs/sm2-ca-cert.pem
727bdf
+++ b/test/certs/sm2-ca-cert.pem
727bdf
@@ -1,14 +1,14 @@
727bdf
 -----BEGIN CERTIFICATE-----
727bdf
-MIICJDCCAcqgAwIBAgIJAOlkpDpSrmVbMAoGCCqBHM9VAYN1MGgxCzAJBgNVBAYT
727bdf
+MIICJzCCAcygAwIBAgIJAOlkpDpSrmVbMAoGCCqBHM9VAYN1MGgxCzAJBgNVBAYT
727bdf
 AkNOMQswCQYDVQQIDAJMTjERMA8GA1UEBwwIU2hlbnlhbmcxETAPBgNVBAoMCFRl
727bdf
-c3QgT3JnMRAwDgYDVQQLDAdUZXN0IE9VMRQwEgYDVQQDDAtUZXN0IFNNMiBDQTAe
727bdf
-Fw0xOTAyMTkwNzA1NDhaFw0yMzAzMzAwNzA1NDhaMGgxCzAJBgNVBAYTAkNOMQsw
727bdf
-CQYDVQQIDAJMTjERMA8GA1UEBwwIU2hlbnlhbmcxETAPBgNVBAoMCFRlc3QgT3Jn
727bdf
-MRAwDgYDVQQLDAdUZXN0IE9VMRQwEgYDVQQDDAtUZXN0IFNNMiBDQTBZMBMGByqG
727bdf
-SM49AgEGCCqBHM9VAYItA0IABHRYnqErofBdXPptvvO7+BSVJxcpHuTGnZ+UPrbU
727bdf
-5kVEUMaUnNOeMJZl/vRGimZCm/AkReJmRfnb15ESHR+ssp6jXTBbMB0GA1UdDgQW
727bdf
-BBTFjcWu/zJgSZ5SKUlU5Vx4/0W5dDAfBgNVHSMEGDAWgBTFjcWu/zJgSZ5SKUlU
727bdf
-5Vx4/0W5dDAMBgNVHRMEBTADAQH/MAsGA1UdDwQEAwIBBjAKBggqgRzPVQGDdQNI
727bdf
-ADBFAiEAs6byi1nSQtFELOw/2tQIv5AEsZFR5MJ/oB2ztXzs2LYCIEfIw4xlUH6X
727bdf
-YFhs4RnIa0K9Ng1ebsGPrifYkudwBIk3
727bdf
+c3QgT3JnMRAwDgYDVQQLDAdUZXN0IE9VMRQwEgYDVQQDDAtUZXN0IFNNMiBDQTAg
727bdf
+Fw0yMjA2MDIxNTQ5MzlaGA8yMTIyMDUwOTE1NDkzOVowaDELMAkGA1UEBhMCQ04x
727bdf
+CzAJBgNVBAgMAkxOMREwDwYDVQQHDAhTaGVueWFuZzERMA8GA1UECgwIVGVzdCBP
727bdf
+cmcxEDAOBgNVBAsMB1Rlc3QgT1UxFDASBgNVBAMMC1Rlc3QgU00yIENBMFkwEwYH
727bdf
+KoZIzj0CAQYIKoEcz1UBgi0DQgAEdFieoSuh8F1c+m2+87v4FJUnFyke5Madn5Q+
727bdf
+ttTmRURQxpSc054wlmX+9EaKZkKb8CRF4mZF+dvXkRIdH6yynqNdMFswHQYDVR0O
727bdf
+BBYEFMWNxa7/MmBJnlIpSVTlXHj/Rbl0MB8GA1UdIwQYMBaAFMWNxa7/MmBJnlIp
727bdf
+SVTlXHj/Rbl0MAwGA1UdEwQFMAMBAf8wCwYDVR0PBAQDAgEGMAoGCCqBHM9VAYN1
727bdf
+A0kAMEYCIQC3c2TkO6Lyxt5GNZqoZNuMEphjL9K7W1TsX6mHzlhHDwIhAICXy2XC
727bdf
+WsTzdrMZUXLtrDDFOq+3FaD4pe1HP2LZFNpu
727bdf
 -----END CERTIFICATE-----
727bdf
diff --git a/test/certs/sm2-root.crt b/test/certs/sm2-root.crt
727bdf
index 5677ac6c9f6a..70ce71e43091 100644
727bdf
--- a/test/certs/sm2-root.crt
727bdf
+++ b/test/certs/sm2-root.crt
727bdf
@@ -1,14 +1,14 @@
727bdf
 -----BEGIN CERTIFICATE-----
727bdf
-MIICJDCCAcqgAwIBAgIJAOlkpDpSrmVbMAoGCCqBHM9VAYN1MGgxCzAJBgNVBAYT
727bdf
+MIICJzCCAcygAwIBAgIJAOlkpDpSrmVbMAoGCCqBHM9VAYN1MGgxCzAJBgNVBAYT
727bdf
 AkNOMQswCQYDVQQIDAJMTjERMA8GA1UEBwwIU2hlbnlhbmcxETAPBgNVBAoMCFRl
727bdf
-c3QgT3JnMRAwDgYDVQQLDAdUZXN0IE9VMRQwEgYDVQQDDAtUZXN0IFNNMiBDQTAe
727bdf
-Fw0xOTAyMTkwNzA1NDhaFw0yMzAzMzAwNzA1NDhaMGgxCzAJBgNVBAYTAkNOMQsw
727bdf
-CQYDVQQIDAJMTjERMA8GA1UEBwwIU2hlbnlhbmcxETAPBgNVBAoMCFRlc3QgT3Jn
727bdf
-MRAwDgYDVQQLDAdUZXN0IE9VMRQwEgYDVQQDDAtUZXN0IFNNMiBDQTBZMBMGByqG
727bdf
-SM49AgEGCCqBHM9VAYItA0IABHRYnqErofBdXPptvvO7+BSVJxcpHuTGnZ+UPrbU
727bdf
-5kVEUMaUnNOeMJZl/vRGimZCm/AkReJmRfnb15ESHR+ssp6jXTBbMB0GA1UdDgQW
727bdf
-BBTFjcWu/zJgSZ5SKUlU5Vx4/0W5dDAfBgNVHSMEGDAWgBTFjcWu/zJgSZ5SKUlU
727bdf
-5Vx4/0W5dDAMBgNVHRMEBTADAQH/MAsGA1UdDwQEAwIBBjAKBggqgRzPVQGDdQNI
727bdf
-ADBFAiEAs6byi1nSQtFELOw/2tQIv5AEsZFR5MJ/oB2ztXzs2LYCIEfIw4xlUH6X
727bdf
-YFhs4RnIa0K9Ng1ebsGPrifYkudwBIk3
727bdf
+c3QgT3JnMRAwDgYDVQQLDAdUZXN0IE9VMRQwEgYDVQQDDAtUZXN0IFNNMiBDQTAg
727bdf
+Fw0yMjA2MDIxNTQ5MzlaGA8yMTIyMDUwOTE1NDkzOVowaDELMAkGA1UEBhMCQ04x
727bdf
+CzAJBgNVBAgMAkxOMREwDwYDVQQHDAhTaGVueWFuZzERMA8GA1UECgwIVGVzdCBP
727bdf
+cmcxEDAOBgNVBAsMB1Rlc3QgT1UxFDASBgNVBAMMC1Rlc3QgU00yIENBMFkwEwYH
727bdf
+KoZIzj0CAQYIKoEcz1UBgi0DQgAEdFieoSuh8F1c+m2+87v4FJUnFyke5Madn5Q+
727bdf
+ttTmRURQxpSc054wlmX+9EaKZkKb8CRF4mZF+dvXkRIdH6yynqNdMFswHQYDVR0O
727bdf
+BBYEFMWNxa7/MmBJnlIpSVTlXHj/Rbl0MB8GA1UdIwQYMBaAFMWNxa7/MmBJnlIp
727bdf
+SVTlXHj/Rbl0MAwGA1UdEwQFMAMBAf8wCwYDVR0PBAQDAgEGMAoGCCqBHM9VAYN1
727bdf
+A0kAMEYCIQC3c2TkO6Lyxt5GNZqoZNuMEphjL9K7W1TsX6mHzlhHDwIhAICXy2XC
727bdf
+WsTzdrMZUXLtrDDFOq+3FaD4pe1HP2LZFNpu
727bdf
 -----END CERTIFICATE-----
727bdf
diff --git a/test/certs/sm2.pem b/test/certs/sm2.pem
727bdf
index 189abb137625..daf12926aff9 100644
727bdf
--- a/test/certs/sm2.pem
727bdf
+++ b/test/certs/sm2.pem
727bdf
@@ -1,13 +1,14 @@
727bdf
 -----BEGIN CERTIFICATE-----
727bdf
-MIIB6DCCAY6gAwIBAgIJAKH2BR6ITHZeMAoGCCqBHM9VAYN1MGgxCzAJBgNVBAYT
727bdf
-AkNOMQswCQYDVQQIDAJMTjERMA8GA1UEBwwIU2hlbnlhbmcxETAPBgNVBAoMCFRl
727bdf
-c3QgT3JnMRAwDgYDVQQLDAdUZXN0IE9VMRQwEgYDVQQDDAtUZXN0IFNNMiBDQTAe
727bdf
-Fw0xOTAyMTkwNzA1NDhaFw0yMzAzMzAwNzA1NDhaMG8xCzAJBgNVBAYTAkNOMQsw
727bdf
-CQYDVQQIDAJMTjERMA8GA1UEBwwIU2hlbnlhbmcxETAPBgNVBAoMCFRlc3QgT3Jn
727bdf
-MRAwDgYDVQQLDAdUZXN0IE9VMRswGQYDVQQDDBJUZXN0IFNNMiBTaWduIENlcnQw
727bdf
-WTATBgcqhkjOPQIBBggqgRzPVQGCLQNCAAQwqeNkWp7fiu1KZnuDkAucpM8piEzE
727bdf
-TL1ymrcrOBvv8mhNNkeb20asbWgFQI2zOrSM99/sXGn9rM2/usM/MlcaoxowGDAJ
727bdf
-BgNVHRMEAjAAMAsGA1UdDwQEAwIGwDAKBggqgRzPVQGDdQNIADBFAiEA9edBnAqT
727bdf
-TNuGIUIvXsj6/nP+AzXA9HGtAIY4nrqW8LkCIHyZzhRTlxYtgfqkDl0OK5QQRCZH
727bdf
-OZOfmtx613VyzXwc
727bdf
+MIICNDCCAdugAwIBAgIUOMbsiFLCy2BCPtfHQSdG4R1+3BowCgYIKoEcz1UBg3Uw
727bdf
+aDELMAkGA1UEBhMCQ04xCzAJBgNVBAgMAkxOMREwDwYDVQQHDAhTaGVueWFuZzER
727bdf
+MA8GA1UECgwIVGVzdCBPcmcxEDAOBgNVBAsMB1Rlc3QgT1UxFDASBgNVBAMMC1Rl
727bdf
+c3QgU00yIENBMCAXDTIyMDYwMjE1NTU0OFoYDzIxMjIwNTA5MTU1NTQ4WjBvMQsw
727bdf
+CQYDVQQGEwJDTjELMAkGA1UECAwCTE4xETAPBgNVBAcMCFNoZW55YW5nMREwDwYD
727bdf
+VQQKDAhUZXN0IE9yZzEQMA4GA1UECwwHVGVzdCBPVTEbMBkGA1UEAwwSVGVzdCBT
727bdf
+TTIgU2lnbiBDZXJ0MFkwEwYHKoZIzj0CAQYIKoEcz1UBgi0DQgAEMKnjZFqe34rt
727bdf
+SmZ7g5ALnKTPKYhMxEy9cpq3Kzgb7/JoTTZHm9tGrG1oBUCNszq0jPff7Fxp/azN
727bdf
+v7rDPzJXGqNaMFgwCQYDVR0TBAIwADALBgNVHQ8EBAMCBsAwHQYDVR0OBBYEFNPl
727bdf
+u8JjXkhQPiJ5bYrrq+voqBUlMB8GA1UdIwQYMBaAFMWNxa7/MmBJnlIpSVTlXHj/
727bdf
+Rbl0MAoGCCqBHM9VAYN1A0cAMEQCIG3gG1D7T7ltn6Gz1UksBZahgBE6jmkQ9Sp9
727bdf
+/3aY5trlAiB5adxiK0avV0LEKfbzTdff9skoZpd7vje1QTW0l0HaGg==
727bdf
 -----END CERTIFICATE-----
727bdf
diff --git a/test/smime-certs/mksmime-certs.sh b/test/smime-certs/mksmime-certs.sh
727bdf
index 12e8a7305402..109b9c4abc28 100644
727bdf
--- a/test/smime-certs/mksmime-certs.sh
727bdf
+++ b/test/smime-certs/mksmime-certs.sh
727bdf
@@ -15,23 +15,23 @@ export OPENSSL_CONF
727bdf
 
727bdf
 # Root CA: create certificate directly
727bdf
 CN="Test S/MIME RSA Root" $OPENSSL req -config ca.cnf -x509 -noenc \
727bdf
-	-keyout smroot.pem -out smroot.pem -newkey rsa:2048 -days 3650
727bdf
+	-keyout smroot.pem -out smroot.pem -newkey rsa:2048 -days 36501
727bdf
 
727bdf
 # EE RSA certificates: create request first
727bdf
 CN="Test S/MIME EE RSA #1" $OPENSSL req -config ca.cnf -noenc \
727bdf
 	-keyout smrsa1.pem -out req.pem -newkey rsa:2048
727bdf
 # Sign request: end entity extensions
727bdf
-$OPENSSL x509 -req -in req.pem -CA smroot.pem -days 3600 \
727bdf
+$OPENSSL x509 -req -in req.pem -CA smroot.pem -days 36500 \
727bdf
 	-extfile ca.cnf -extensions usr_cert -CAcreateserial >>smrsa1.pem
727bdf
 
727bdf
 CN="Test S/MIME EE RSA #2" $OPENSSL req -config ca.cnf -noenc \
727bdf
 	-keyout smrsa2.pem -out req.pem -newkey rsa:2048
727bdf
-$OPENSSL x509 -req -in req.pem -CA smroot.pem -days 3600 \
727bdf
+$OPENSSL x509 -req -in req.pem -CA smroot.pem -days 36500 \
727bdf
 	-extfile ca.cnf -extensions usr_cert -CAcreateserial >>smrsa2.pem
727bdf
 
727bdf
 CN="Test S/MIME EE RSA #3" $OPENSSL req -config ca.cnf -noenc \
727bdf
 	-keyout smrsa3.pem -out req.pem -newkey rsa:2048
727bdf
-$OPENSSL x509 -req -in req.pem -CA smroot.pem -days 3600 \
727bdf
+$OPENSSL x509 -req -in req.pem -CA smroot.pem -days 36500 \
727bdf
 	-extfile ca.cnf -extensions usr_cert -CAcreateserial >>smrsa3.pem
727bdf
 
727bdf
 # Create DSA parameters
727bdf
@@ -40,15 +40,15 @@ $OPENSSL dsaparam -out dsap.pem 2048
727bdf
 
727bdf
 CN="Test S/MIME EE DSA #1" $OPENSSL req -config ca.cnf -noenc \
727bdf
 	-keyout smdsa1.pem -out req.pem -newkey dsa:dsap.pem
727bdf
-$OPENSSL x509 -req -in req.pem -CA smroot.pem -days 3600 \
727bdf
+$OPENSSL x509 -req -in req.pem -CA smroot.pem -days 36500 \
727bdf
 	-extfile ca.cnf -extensions usr_cert -CAcreateserial >>smdsa1.pem
727bdf
 CN="Test S/MIME EE DSA #2" $OPENSSL req -config ca.cnf -noenc \
727bdf
 	-keyout smdsa2.pem -out req.pem -newkey dsa:dsap.pem
727bdf
-$OPENSSL x509 -req -in req.pem -CA smroot.pem -days 3600 \
727bdf
+$OPENSSL x509 -req -in req.pem -CA smroot.pem -days 36500 \
727bdf
 	-extfile ca.cnf -extensions usr_cert -CAcreateserial >>smdsa2.pem
727bdf
 CN="Test S/MIME EE DSA #3" $OPENSSL req -config ca.cnf -noenc \
727bdf
 	-keyout smdsa3.pem -out req.pem -newkey dsa:dsap.pem
727bdf
-$OPENSSL x509 -req -in req.pem -CA smroot.pem -days 3600 \
727bdf
+$OPENSSL x509 -req -in req.pem -CA smroot.pem -days 36500 \
727bdf
 	-extfile ca.cnf -extensions usr_cert -CAcreateserial >>smdsa3.pem
727bdf
 
727bdf
 # Create EC parameters
727bdf
@@ -58,16 +58,17 @@ $OPENSSL ecparam -out ecp2.pem -name K-283
727bdf
 
727bdf
 CN="Test S/MIME EE EC #1" $OPENSSL req -config ca.cnf -noenc \
727bdf
 	-keyout smec1.pem -out req.pem -newkey ec:ecp.pem
727bdf
-$OPENSSL x509 -req -in req.pem -CA smroot.pem -days 3600 \
727bdf
+$OPENSSL x509 -req -in req.pem -CA smroot.pem -days 36500 \
727bdf
 	-extfile ca.cnf -extensions usr_cert -CAcreateserial >>smec1.pem
727bdf
 CN="Test S/MIME EE EC #2" $OPENSSL req -config ca.cnf -noenc \
727bdf
 	-keyout smec2.pem -out req.pem -newkey ec:ecp2.pem
727bdf
-$OPENSSL x509 -req -in req.pem -CA smroot.pem -days 3600 \
727bdf
+$OPENSSL x509 -req -in req.pem -CA smroot.pem -days 36500 \
727bdf
 	-extfile ca.cnf -extensions usr_cert -CAcreateserial >>smec2.pem
727bdf
-CN="Test S/MIME EE EC #3" $OPENSSL req -config ca.cnf -noenc \
727bdf
-	-keyout smec3.pem -out req.pem -newkey ec:ecp.pem
727bdf
-$OPENSSL x509 -req -in req.pem -CA smroot.pem -days 3600 \
727bdf
-	-extfile ca.cnf -extensions usr_cert -CAcreateserial >>smec3.pem
727bdf
+# Do not renew this cert as it is used for legacy data decrypt test
727bdf
+#CN="Test S/MIME EE EC #3" $OPENSSL req -config ca.cnf -noenc \
727bdf
+#	-keyout smec3.pem -out req.pem -newkey ec:ecp.pem
727bdf
+#$OPENSSL x509 -req -in req.pem -CA smroot.pem -days 36500 \
727bdf
+#	-extfile ca.cnf -extensions usr_cert -CAcreateserial >>smec3.pem
727bdf
 # Create X9.42 DH parameters.
727bdf
 $OPENSSL genpkey -genparam -algorithm DHX -out dhp.pem
727bdf
 # Generate X9.42 DH key.
727bdf
@@ -77,7 +78,7 @@ $OPENSSL pkey -pubout -in smdh.pem -out dhpub.pem
727bdf
 CN="Test S/MIME EE DH #1" $OPENSSL req -config ca.cnf -noenc \
727bdf
 	-keyout smtmp.pem -out req.pem -newkey rsa:2048
727bdf
 # Sign request but force public key to DH
727bdf
-$OPENSSL x509 -req -in req.pem -CA smroot.pem -days 3600 \
727bdf
+$OPENSSL x509 -req -in req.pem -CA smroot.pem -days 36500 \
727bdf
 	-force_pubkey dhpub.pem \
727bdf
 	-extfile ca.cnf -extensions usr_cert -CAcreateserial >>smdh.pem
727bdf
 # Remove temp files.