Content-Type: text/plain Content-Disposition: inline Content-Transfer-Encoding: binary MIME-Version: 1.0 X-Mailer: MIME-tools 5.427 (Entity 5.427) From: tlyu@mit.edu Subject: git commit X-RT-Original-Encoding: iso-8859-1 Content-Length: 850 Discuss cert expiry, no-key princs in PKINIT docs In pkinit.rst, add "-days" options to the example commands for creating certificate and briefly discuss the issue of expiration dates so that the administrator thinks about it. In troubleshoot.rst, add an entry for the "certificate has expired" error which results from PKINIT (when linked with OpenSSL) when a certificate has expired. (cherry picked from commit f3977b6883f0172a2af9006522a1b35546f86749) https://github.com/krb5/krb5/commit/6d46afa0ea1283b7b85d1f0075ff274fa15aae60 Author: Greg Hudson Committer: Tom Yu Commit: 6d46afa0ea1283b7b85d1f0075ff274fa15aae60 Branch: krb5-1.11 doc/admin/pkinit.rst | 32 ++++++++++++++++++++++++++------ doc/admin/troubleshoot.rst | 20 ++++++++++++++++++++ 2 files changed, 46 insertions(+), 6 deletions(-)