[openssl-users] No TLS Extended Master Secret Extension (RFC7627) support yet?

2015-11-11 Thread Igor Sverkos
Hi, today I read [1] that Microsoft finally added support for TLS Extended Master Secret Extension to their SSL implementation (SChannel). The author was so kind to provide a test script [2] to check if your own servers support TLS Extended Master Secret extension yet. Looks like my servers

Error in `openssl': munmap_chunk(): invalid pointer: 0x00007ffffc1065af

2014-04-09 Thread Igor Sverkos
Hi, when you set the -host parameter as last, you will get the following error: ~/cert-test/ $ openssl ocsp -CApath /etc/ssl/certs -no_nonce -issuer issuer.crt -cert cert.crt -url http://ocsp2.globalsign.com/gsalphag2 -host ocsp2.globalsign.com Error querying OCSP responsder

OpenSSL doesn't treat RFC 3280 validations as an error?

2013-11-13 Thread Igor Sverkos
Hi, please see the following certificate: -BEGIN CERTIFICATE- MIIEbTCCA1WgAwIBAgICLgAwDQYJKoZIhvcNAQEFBQAwQDELMAkGA1UEBhMCVVMx FzAVBgNVBAoTDkdlb1RydXN0LCBJbmMuMRgwFgYDVQQDEw9HZW9UcnVzdCBTU0wg Q0EwHhcNMTAxMDE5MDQyMDUwWhcNMTUxMDIwMjMzNTI0WjCBhDEpMCcGA1UEBRMg

Re: [openssl-users] OpenSSL doesn't treat RFC 3280 validations as an error?

2013-11-13 Thread Igor Sverkos
Hello, thank you for your response. There's one thing in your reply I don't understand: Erwann Abalea wrote: It seems to be a valid certificate for OpenSSL, right? OpenSSL can parse it, yes. [...] Reading X.520 shows that the DirectoryString type disallows 0-sized elements. So you're

Re: OCSP responder www.openca.org

2013-07-30 Thread Igor Sverkos
Hi, when I was looking for an OCSP responder in January I also found OpenCA.org and I also think it is dead. If you want to use it, read the mailing list. Someone posted important patches (against memory leaks and other things). Another thing is, that I am not sure if an OCSP responder, which

Re: Is it me or is ocsp.comodoca.com doing something wrong?

2013-06-13 Thread Igor Sverkos
Hi, Ryan Hurst wrote: They are doing a CA signed OCSP response, this is legitimate. We will do this in the not so distant future as well for many of our responses also. If this is called CA signed OCSP response, how is *your* current response, which you will change in future, called? You

Re: Is it me or is ocsp.comodoca.com doing something wrong?

2013-06-13 Thread Igor Sverkos
Hi, forget it - I got it :) -VAfile level1.crt is doing 'the trick'. But I still don't now how to compute/get the responseID on my own. Thanks. -- Regards, Igor __ OpenSSL Project

Is it me or is ocsp.comodoca.com doing something wrong?

2013-06-12 Thread Igor Sverkos
Hi, I tried to validate a certificate from Comodo using their OCSP, but I cannot verify the response: 3073455752:error:27069076:OCSP routines:OCSP_basic_verify:signer certificate not found:ocsp_vfy.c:85: The certificate I want to validate was issued by C=GB, ST=Greater Manchester,