"Ralf S. Engelschall" wrote:

> This cipher works only with a DSA server cert, and that's
> what you're using:

Ok.

> So it's clear that you cannot connect with Netscape.  But... errrr.... why to
> the hell are people using the DSA certs?  You _HAVE_ to pressed "D" or used
> ALGO=DSA on the "make certificate" procedure. Because else the RSA snakeoil
> cert is used, of course.
> 
> Can someone explain me why people with the "no shared cipher" problem are
> using DSA certs? Is there an error in one of our scripts or why do they all
> select the DSA certs?

The "make certifacate" procedure produces both dsa and rsa certs at the
same time. I pointed my installation at the dsa certs as nothing told me
that I shouldn't have done so. Perhaps by default the installation
should not produce the dsa certs, if there was a warning it is possible
that I missed it.

Regards,
Graham
-- 
-----------------------------------------
[EMAIL PROTECTED]                "There's a moon
                                        over Bourbon Street
                                                tonight...
______________________________________________________________________
Apache Interface to OpenSSL (mod_ssl)                   www.modssl.org
User Support Mailing List                      [EMAIL PROTECTED]
Automated List Manager                            [EMAIL PROTECTED]

Reply via email to