Invalid signature on CSR when finalizing

Looks good:

# openssl req -noout -text -verify
-----BEGIN CERTIFICATE REQUEST-----
MIIBMDCB1QIBADAjMQswCQYDVQQGEwJTVjEUMBIGA1UEAwwLc21ha2Rldi5uZXQwWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAASrjUcTneMlpvzNZ59jcOXQqk2gqF3dO7SOuF4/45ZiHbWekhJK9EFlAwH0G0dWDzysYsQgOGHr/aTmLKAKJk+AoFAwTgYJKoZIhvcNAQkOMUEwPzA9BgNVHREENjA0ggtzbWFrZGV2Lm5ldIIPd3d3LnNtYWtkZXYubmV0ghRsYXVuY2hlci5zbWFrZGV2Lm5ldDAMBggqhkjOPQQDAgUAA0gAMEUCIQCjm0q0WlCfjTQyLH6Zgn0XqLRPHU4T/eJc3FSa4E2cYQIgQf7PrYTHGfyhT7hdImt+tiec39mpVnUF8vAYOtojclk=
-----END CERTIFICATE REQUEST-----
verify OK
1 Like