https://issues.apache.org/bugzilla/show_bug.cgi?id=46531

           Summary: Erroneously repots Server Certificate as Revoked if same
                    serial No. in CRL
           Product: Apache httpd-2
           Version: 2.2.9
          Platform: PC
        OS/Version: Windows XP
            Status: NEW
          Severity: normal
          Priority: P2
         Component: mod_ssl
        AssignedTo: [email protected]
        ReportedBy: [email protected]


Server Certificate is self-signed and has a Serial No. 00

If the same Serial No. (00) is present in the CRL (Certificate Revocation
List),
upon log-in Internet Explorer issues a message, similar to the following:

"This Site's Security Certificate is revoked. Do not trust this site!"

and prohibits log-in.

Installed on Windows Server 2003 and Windows XP Pro SP1 (both installations
display the same behaviour).

Installed from:
apache_2.2.9-win32-x86-openssl-0.9.8h-r2 ( 
https://svn.apache.org/viewcvs.cgi?view=rev&rev=2 )msi

The Server Certificate is self-signed.
The CA Certificate is self-signed, too.

All certificates and CRLs are created using command-line OpenSSL 0.9.8b.

No errors are reported in the course of Certificate Generation or the Normal
Apache run.


-- 
Configure bugmail: https://issues.apache.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to