RE: CA hierarchy / pathlen:0

2013-08-23 Thread Patrick Tronnier
The RFC 5280 is for path building and validation when certificates are being used. It is not meant for validation during certificate creation. As Rich indicated OpenSSL will sign anything you present. With kind regards, Patrick Tronnier Principal Security Architect & Sr. Director of Qua

RE: apache with client certificates

2002-09-18 Thread Patrick Tronnier
CA it has in SSLCACertificateFile? Yes. And if "who" signed the client certificate is NOT in the SSLCACertificateFile the server will attempt to download the signing certificate. Hope this helps. Sincerely, Patrick Tronnier Principal Security Architect Open Access Technology Internat

RE: problems with openssl 0.9.6d and up

2002-09-18 Thread Patrick Tronnier
Have you tried this with a non "self signed certificate". ie. The subject and issuer of the cert should be different for client/end user certs. Sincerely, Patrick Tronnier Principal Security Architect www.oaticerts.com CONFIDENTIAL INFORMATION: This email and any attachment(