Using openssl we have designed a system with our own self generated
Certificate Authority ("CA"), and our own generated and self-signed
client.crt and client.key.

The IE9 process of following the Certificate Authority path breaks when it
encounters our self generated CA which has no signer recognized in the web
client's certificate trust. 

I do not know how to overcome this issue. If you know of a way around the
web-browser negotiation process for accepting CA's, please help!

Our goal is to give the web client what it needs so that it will accept our
CA, and use the client cert we automatically generate for client web
authentication (using nginx in front of 4D).

The answer is probably "We must get our CA signed by a CA known to and
trusted by the web clients CA trust path."

If you know the answer to this a "yes I agree" or "no that is not right...",
or you can do it this way... is greatly appreciated.

Thanks!
David Ringsmuth

_______________________________________________
Active4D-dev mailing list
[email protected]
http://list.aparajitaworld.com/listinfo/active4d-dev
Archives: http://vasudev.aparajitaworld.com/archive/active4d-dev/

Reply via email to