Hi!!! I've been trying to test the SSL client-server executables given in the bin folder of the NSS package binary: I'm using selfserv.exe & strsclnt.exe. The server side is getting initialized alright.
But I have problems with server authentication: I tried many hit-&- trial approaches to obtain a successful connection but for one reason or the other, the client is not recognising the issuer CA(self-signed and added to the client DB with certutil -t "CTU, CTU, CTU") as trusted. I created three DB directories: one for each, the client, the server & the CA. The DBs, keys, and the certificates requests as well as the finished certificates of each one was put into its respective directory. Also, when I created the Self-signed CA certificate using the -S argument with certutil.exe, it got added to the DB fine but was not visible in its directory due to which I could not add it to the client & the server databases. I fixed this problem by creating a secondary CA cert from the Self signed "root" cert and adding it to both the other databases...But again it could not recognize the CA cert... :-(( Then I generated all the certs in a common directory. Again, no success... It was throwing the error : "Peer's Certificate issuer is not recognized." on the client side. I tried fixing it with -oo argument(which skips the server authetication altogether) but this time the error thrown was : "Cannot communicate securely with peer. The requested domain name does not match the server certificate." Somebody please help or atleast give me some clue as to what could probably be the mistake... Also please tell the importance of the -1234567 arguments in the certutil tool. Can I somehow add the root CA cert in the client-server DBs without having to create the secondary CA cert?? Warm Regards, D3|\||\|!$ _______________________________________________ dev-tech-crypto mailing list [email protected] https://lists.mozilla.org/listinfo/dev-tech-crypto

