i was too hasty posting the question - turns out my ca's certificate expired. my apologies for wasting time/bandwidth. -a "Leland V. Lammert" wrote: > At 12:01 PM 1/3/00 , you wrote: > >hi, > > > >i have an apache with mod ssl installed in november and i was using > >self-signed openssl generated client certificate issued in december > >expiring in december 2000. this morning i tried to connect over ssl to > >my server and faild due to "expired certificate" :-(. i just issued > >myself another client certificate and it failed too. i'm going to > >reissue the server certificate next. has anyone experienced this > >problem? > > > >-- > >Aaron Stromas > >Oracle Corp. > > I just tested ours (we also use self-certs), .. no problem, this one was recreated >ours on December 21.) > > I would expect: > > 1) You only generated a cert with 30 days expiration (created in November). > > 2) When you generated the second one, you might have accidentally changed the file >name or not restarted Apache, so the server did not see it. > > HTH, > > Lee > ============================================ > Leland V. Lammert [EMAIL PROTECTED] > Chief Scientist Omnitec Corporation > Network/Internet Consultants www.omnitec.net > ============================================ > ______________________________________________________________________ > OpenSSL Project http://www.openssl.org > User Support Mailing List [EMAIL PROTECTED] > Automated List Manager [EMAIL PROTECTED] -- Aaron Stromas Oracle Corp. "Tick-tick-tick!!!... ja, Pantani is weg...." (BRTN commentator, L'Alpe d'Huez, 1995 Tour de France)
begin:vcard n:Stromas;Aaron tel;fax:+1 703-708 7923 tel;work:+1 703 708 6821 x-mozilla-html:TRUE url:http://www.oracle.com org:Oracle;Advanced Technology Solutions adr:;;196 Van Buren Street;Herndon;Virginia;22070;USA version:2.1 email;internet:[EMAIL PROTECTED] title:Senior Principal consultant x-mozilla-cpt:;7952 fn:Stromas, Aaron end:vcard