By trial and error I have come to the conclusion that

SSLVerifyClient require

Only works with version 3 CA certificates... ok that fine.

As it stands now this option when included in an .htaccess file
will force a SSL renegotiation and that is fine too.

The problem is that it forces a  renegotiation for EVERY hit.

Lets say you have a page with three .gif files in it, than you will
renegotiate
four times.  Is there a technical reason for this?

I know that if I go per-server I wont have this problem but I want to
do is client verification for only a subsection of the site not the whole
site.

Thanks for any feedback
--------------------------------------------------------------------
I n t e r K n o w l e d g e
Gerald Villemure
I am a DO-er, not a TRY-er.                      email: [EMAIL PROTECTED]

______________________________________________________________________
Apache Interface to OpenSSL (mod_ssl)                   www.modssl.org
User Support Mailing List                      [EMAIL PROTECTED]
Automated List Manager                            [EMAIL PROTECTED]

Reply via email to