Hi, I have a problem with openssl 0.9.5a incorporated in Oracle 9iAS 1.0.2.2 for win 2000server. My target is enable the ssl protocol with both authentication client and server, only server authentication is OK, client and server fail. I use a CA certificate for the client which is not included in the \ssl.crt\ca-bundle.crt. I link my certificate in the SSLCACertificateFile directive in the httpd.conf of apache The server requires the authentication client User seletc his certificate, but the following error occurred (from ssl_engine_log):
[04/giu/2002 17:25:05 01976] [error] Certificate Verification: Error (7): certificate signature failure [04/giu/2002 17:25:05 01976] [error] SSL handshake failed (server ...., client .... ) (OpenSSL library error follows) [04/giu/2002 17:25:05 01976] [error] OpenSSL: error:04077068:rsa routines:RSA_verify:bad signature [04/giu/2002 17:25:05 01976] [error] OpenSSL: error:0D079006:asn1 encoding routines:ASN1_verify:bad get asn1 object call [04/giu/2002 17:25:05 01976] [error] OpenSSL: error:140890B2:SSL routines:SSL3_GET_CLIENT_CERTIFICATE:no certificate returned The oracle support says me to upgrade the openssl 0.9.5a to the openssl 0.9.6a and incorporate it in 9iAS Where/How can find the openssl.exe in the 0.9.6a version? Thanks very much Daniela -- Daniela Prestipino [EMAIL PROTECTED] I.D.S., Informatica Distribuita e Software srl Via Consolare Pompea 19 98168 Messina ITALIA Tel.: +39 90 353638 Fax : +39 90 3500063 ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List [EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED]