ovs-pki: Increase the validity days for self-signed certificates.
authorGurucharan Shetty <gshetty@nicira.com>
Mon, 15 Oct 2012 21:41:31 +0000 (14:41 -0700)
committerGurucharan Shetty <gshetty@nicira.com>
Mon, 15 Oct 2012 21:49:26 +0000 (14:49 -0700)
For self-signed certificates, increase validity from the default
30 days to 6 years.

Signed-off-by: Gurucharan Shetty <gshetty@nicira.com>
utilities/ovs-pki.in

index 2a67d53..bf40c29 100755 (executable)
@@ -512,7 +512,7 @@ elif test "$command" = self-sign; then
     # Create both the private key and certificate with restricted permissions.
     (umask 077 && \
      openssl x509 -in "$arg1-req.pem" -out "$arg1-cert.pem.tmp" \
-        -signkey "$arg1-privkey.pem" -req -text) 2>&3 || exit $?
+        -signkey "$arg1-privkey.pem" -req -days 2191 -text) 2>&3 || exit $?
 
     # Reset the permissions on the certificate to the user's default.
     cat "$arg1-cert.pem.tmp" > "$arg1-cert.pem"