How clients certificates are choosen ?
am 12.06.2009 22:41:28 von Nicolas CrosHello !
I want to setup a proxy, allowing my internal hosts to connect on
external https servers (which forces client authentication by using a
certificate).
Excerpt of my .conf :
# TEST
#ProxyPass /proxy/TEST/ https://laposte.net
#ProxyPassReverse /proxy/TEST/ https://laposte.net
SSLEngine on
SSLProxyEngine on
SSLProxyMachineCertificateFile /etc/httpd/conf/ssl/SSLproxy.pem
SSLCertificateFile /etc/httpd/conf/ssl/my.cer
SSLCertificateKeyFile /etc/httpd/conf/ssl/my.key
SSLCACertificateFile /etc/httpd/conf/ssl/ca-bundle.crt
I try to connect on 2 servers with similar configuration (same CA
used, both requiring client auth, ... ):
One connection is successfull, as i can saw in my debug httpd log file :
[debug] ssl_engine_kernel.c(1499): Proxy client certificate callback:
(myproxy:443) found acceptable cert, sending /C=XX/ST=CITY/L=Port/
O=ORGANIZATION/OU=31/CN=myCN/emailAddress=myemail
The other one not :
[debug] ssl_engine_kernel.c(1571): Proxy client certificate callback:
(myproxy:443) no client certificate found!?
I wonder myself how clients certificates are choosen ?
Any thoughts ?
Thanks in advance
--
Nicolas Cros
Connaissez vous la maison du cordonnier ?
Elle se trouve ici : http://barsa.free.fr
____________________________________________________________ __________
Apache Interface to OpenSSL (mod_ssl) www.modssl.org
User Support Mailing List modssl-users@modssl.org
Automated List Manager majordomo@modssl.org