Re: mod_ssl Client authentication question

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



It was thus said that the Great Brian Mearns once stated:
> 
> Thanks for the detailed response, Sean. I'm still not entirely clear
> on one thing, though: If I created my own certificate and gave the the
> organization name "Conman Laboratories" and an Organzational unit name
> of "Clients", would I be able to get onto your site? I'm 90% sure that
> the answer is NO, because I'm not signed by the CA specified by the
> SSLCACertificateFile directive, but the Apache documentation, as I
> interpreted it, is not explicit that this directive applies an
> implicit condition to the SSLRequire directive.

  I think it does.  The client certificate didn't work util I added the CA
Certificate to the file pointed to by SSLCACertificateFile.  If I were to
add your CA Certificate to that file, then yes, you should be able to sign
certificates with an organization name "Conman Laboratories" and a unit name
of "Clients" and have it accepted.  

  Of course, you could always try signing a certificate with said
information and see what happens.

  -spc 




---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx
   "   from the digest: users-digest-unsubscribe@xxxxxxxxxxxxxxxx
For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx


[Index of Archives]     [Open SSH Users]     [Linux ACPI]     [Linux Kernel]     [Linux Laptop]     [Kernel Newbies]     [Security]     [Netfilter]     [Bugtraq]     [Squid]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Samba]     [Video 4 Linux]     [Device Mapper]

  Powered by Linux