Content-Type: text/plain Content-Disposition: inline Content-Transfer-Encoding: binary MIME-Version: 1.0 X-Mailer: MIME-tools 5.427 (Entity 5.427) From: tlyu@mit.edu Subject: git commit RT-Send-CC: X-RT-Original-Encoding: iso-8859-1 Content-Length: 850 Discuss cert expiry, no-key princs in PKINIT docs In pkinit.rst, add "-days" options to the example commands for creating certificate and briefly discuss the issue of expiration dates so that the administrator thinks about it. In troubleshoot.rst, add an entry for the "certificate has expired" error which results from PKINIT (when linked with OpenSSL) when a certificate has expired. (cherry picked from commit f3977b6883f0172a2af9006522a1b35546f86749) https://github.com/krb5/krb5/commit/1ce4c664b77ffd0363ed0d8a05f9cbc29507a932 Author: Greg Hudson Committer: Tom Yu Commit: 1ce4c664b77ffd0363ed0d8a05f9cbc29507a932 Branch: krb5-1.12 doc/admin/pkinit.rst | 32 ++++++++++++++++++++++++++------ doc/admin/troubleshoot.rst | 20 ++++++++++++++++++++ 2 files changed, 46 insertions(+), 6 deletions(-)