Holger Reif wrote:
> 
> Another variation of the "put images under http" proposal.
> Just puzt them into a separate directory that don't have
> client certs presentation as requirement. Thus you don't
> end up with possible "broken keys" (indicating no security)
> or with undisplayed images ('cause they are unsecured).

I have also seen this problem, and wasn't 100% sure of the cause.  I
would be happy to try and solve it if someone were willing to point me
in the right direction (no guarantees).
I have not seen any broken keys so far, only broken image icons which
disappear on reload.


> Regarding the actual problem, don't know. Perhaps something
> is wrong with the session cache.

Many things which were screwy in the SSL session cache went away when I
started using mm and the shared-memory cache.  Of course, I'm not 100%
certain that I'm using it (mm) right yet.


> Ralf, is there an easy way to display (or to dump) the actual
> content of the session cache for debugging purposes? (Perhaps
> even a feature to dump and reload like bind does with
> zone files...)

It seems like using the sdbm version and parsing the cache with Perl's
DBM module might work (?)


-- 
     "My new house has twenty Windows NT machines,
      and they can do sophisticated things like 
      turn the lights on and off."
      --Bill Gates, speaking at Cambridge University
______________________________________________________________________
Apache Interface to OpenSSL (mod_ssl)                   www.modssl.org
User Support Mailing List                      [EMAIL PROTECTED]
Automated List Manager                            [EMAIL PROTECTED]

Reply via email to