Nicolas Cros
Fri, 12 Jun 2009 13:42:15 -0700
Hello !I want to setup a proxy, allowing my internal hosts to connect on external https servers (which forces client authentication by using a certificate).
Excerpt of my .conf : # TEST #ProxyPass /proxy/TEST/ https://laposte.net #ProxyPassReverse /proxy/TEST/ https://laposte.net SSLEngine on SSLProxyEngine on SSLProxyMachineCertificateFile /etc/httpd/conf/ssl/SSLproxy.pem SSLCertificateFile /etc/httpd/conf/ssl/my.cer SSLCertificateKeyFile /etc/httpd/conf/ssl/my.key SSLCACertificateFile /etc/httpd/conf/ssl/ca-bundle.crt </VirtualHost>I try to connect on 2 servers with similar configuration (same CA used, both requiring client auth, ... ):
One connection is successfull, as i can saw in my debug httpd log file :[debug] ssl_engine_kernel.c(1499): Proxy client certificate callback: (myproxy:443) found acceptable cert, sending /C=XX/ST=CITY/L=Port/ O=ORGANIZATION/OU=31/CN=myCN/emailAddress=myemail
The other one not :[debug] ssl_engine_kernel.c(1571): Proxy client certificate callback: (myproxy:443) no client certificate found!?
I wonder myself how clients certificates are choosen ? Any thoughts ? Thanks in advance -- Nicolas Cros Connaissez vous la maison du cordonnier ? Elle se trouve ici : http://barsa.free.fr ______________________________________________________________________ Apache Interface to OpenSSL (mod_ssl) www.modssl.org User Support Mailing List modssl-users@modssl.org Automated List Manager majord...@modssl.org