It seems that we have the same problem. I just opened a thread here https://mta.openssl.org/pipermail/openssl-users/2016-May/003733.html It seems that a group of experts found a workaround here. https://github.com/elabftw/elabftw/issues/242 Maybe you're expert enough to understand how to use their javaclient to make the verification, while we wait openssl to correct the bug. I cannot understand how to do it. I would appreciate, if you succeed, to explain me how to do it.