The command 'sign-req COMMON client1 nopass' would generate an invalid certificate. Do not allow COMMON as a $cert_type. Also, improve comment and user output for existing certificate check. Closese: #634 Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>