免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
查看: 1138 | 回复: 0
打印 上一主题 下一主题

CA authentication [复制链接]

论坛徽章:
0
跳转到指定楼层
1 [收藏(0)] [报告]
发表于 2005-05-24 20:10 |只看该作者 |倒序浏览
CA验证的,当初找到的文章
Mario Truyens wrote:
>
> Hi,
>
> I have a problem using SSLCACertificatePath.
>
> I have a PEM encoded CA certificate in directory /certs, called class1.pem.
> When I use 'SSLCACertificateFile /certs/class1.pem' everything works fine
> and client authentication is possible.
>
> However, when I do the following:
> $ cd /certs
> $ ssleay x509 -noout -hash  12345678
> $ ln -s class1.pem 12345678.0
> and remove 'SSLCACertificateFile ...' and add
> 'SSLCACertificatePath /certs', client authentication fails?
>
> I get this message in the error_log:
> [Tue Nov 10 16:28:31 1998] [error] verify error:num=19:self signed certificate in certificate chain
> [Tue Nov 10 16:28:31 1998] [error] SSL_accept failed
> [Tue Nov 10 16:28:31 1998] [error] error:140890B1:SSL routines:SSL3_GET_CLIENT_CERTIFICATE:no certificate returned
>
> I use both Server and Client authentication. Note that the server certificate is self signed
> which may explain the first message. The CA certificate though is a valid one.
> The same for the client certificate.
> Versions are apache_1.3.3+ssl_1.28 and SSLeay-0.9.0b. Platform is Solaris 2.5.1.
>
> Has anyone a clue what's going on?
Yes - we've looked into this and it appears to be related to the way the
newer browsers handle client certificate passing - Ben is currently
working on a fix which should take care of it.
Apologies for not replying to all the postings on this subject direct,
as I know there have been a couple - this is just the one that came to
hand...
> P.S.: I know I can concatenate multiple CA certificates into one file,
>       but I prefer the hash method.
This is the workaround for now.
Cheers,
Adam
--
Adam Laurie                   Tel: +44 (181) 742 0755
A.L. Digital Ltd.             Fax: +44 (181) 742 5995
Voysey House                  
Barley Mow Passage            
http://www.aldigital.co.uk
London W4 4GB                 
mailto:adam@algroup.co.uk
UNITED KINGDOM                PGP key on keyservers

本文来自ChinaUnix博客,如果查看原文请点:http://blog.chinaunix.net/u/2389/showart_27566.html
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP