All, Background: https://lists.apache.org/thread/5x9y41t4c39nocswbv4p389554dhbzls
When a client authenticates using CLIENT-CERT the client presents a client certificate and any intermediate certificates but not the root cert.
If OCSP is enabled there is a difference between how JSSE and OpenSSL[-FFM] behaves.
JSSE stops (and does not perform an OCSP check) once it reaches a certificate that is in the trust store.
OpenSSL[-FFM] stops (and does not perform an OCSP check) once it reaches a root certificate.
So there is a difference in behaviour if an intermediate cert is in the trust store. JSSE does not perform an OCSP check on the intermediate cert whereas OpenSSL-[FFM] does. Neither perform an OCSP check on the root cert.
The proposal is to align the OpenSSL-[FFM] implementations with JSSE on the grounds that any cert in the trusted store is - by definition - trusted.
I have patches ready to implement this if we want to proceed. Thoughts? Mark --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
