[Bug 1833039] Re: 18.04/Apache2: rejecting client initiated renegotiation due to openssl 1.1.1

2019-06-28 Thread Andreas Hasenack
https://bz.apache.org/bugzilla/show_bug.cgi?id=62691#c5 "Moving "SSLVerifyClient require" outside of the block instantly returns the document. So it does appear to be ONLY the renegotiation case. " That works here too, in my simple test case. I had this location directive:

[Bug 1833039] Re: 18.04/Apache2: rejecting client initiated renegotiation due to openssl 1.1.1

2019-06-28 Thread Andreas Hasenack
I think this patch worked: https://github.com/apache/httpd/commit/bbedd8b80e50647e09f2937455cc57565d94a844 Could you please try the build from my ppa: https://launchpad.net/~ahasenack/+archive/ubuntu/apache2-client-cert-1833039 -- You received this bug notification because you are a member of Ub

[Bug 1803689] Re: Login with client cert times out

2019-06-28 Thread Andreas Hasenack
*** This bug is a duplicate of bug 1833039 *** https://bugs.launchpad.net/bugs/1833039 Discussion is happening in bug #1833039, so I'm marking this as a duplicate of that one. ** This bug has been marked a duplicate of bug 1833039 18.04/Apache2: rejecting client initiated renegotiation due

[Bug 1833039] Re: 18.04/Apache2: rejecting client initiated renegotiation due to openssl 1.1.1

2019-06-28 Thread Andreas Hasenack
** Also affects: apache2 (Ubuntu Cosmic) Importance: Undecided Status: New ** Also affects: openssl (Ubuntu Cosmic) Importance: Undecided Status: New ** Also affects: apache2 (Ubuntu Bionic) Importance: Undecided Status: New ** Also affects: openssl (Ubuntu Bionic)

[Bug 1834671] [NEW] TLSv1.3 client certificate authentication with renegotiation unsupported in browsers

2019-06-28 Thread Andreas Hasenack
Public bug reported: This is mostly a place holder bug, as more information becomes available. What is known so far is that a certain configuration of client certificate authentication using TLSv1.3 is not working with most (all at this point?) browsers, resulting in the server returning this err

[Bug 1833039] Re: 18.04/Apache2: rejecting client initiated renegotiation due to openssl 1.1.1

2019-06-28 Thread Andreas Hasenack
The PPA has cosmic and bionic packages. I tested with the prefork, worked and event MPMs, and also ran the apache DEP8 tests. All passed. I'll prepare MPs, update this bug with the SRU template and testing instructions, and get ready to release this early next week. -- You received this bug noti