"Venkatesha, Ashalatha" wrote:
>
> Hi All,
>
> I am using the latest openssl library openssl.0.9.5a with stunnel-3.8p2.
>
> when i used to connect to the server i am getting the following error.
> Could anyone look into this and give me some solution please.
> LOG7[878:1] Jun 28 10:23:13: before/accept initialization
> LOG7[878:1] Jun 28 10:23:13: before/accept initialization
> LOG7[878:1] Jun 28 10:23:13: SSLv3 read client hello A
> LOG7[878:1] Jun 28 10:23:13: SSLv3 write server hello A
> LOG7[878:1] Jun 28 10:23:13: SSLv3 write certificate A
> LOG7[878:1] Jun 28 10:23:13: SSLv3 write certificate request A
> LOG7[878:1] Jun 28 10:23:13: SSLv3 flush data
> LOG4[878:1] Jun 28 10:23:13: VERIFY ERROR: depth=0 error=unsupported
> certificate purpose:
> /C=AU/O=CSFB/OU=Equities/0.9.2342.19200300.100.1.1=TradeView-Asia/CN=TradeVi
> [EMAIL PROTECTED]
> LOG7[878:1] Jun 28 10:23:13: SSLv3 read client certificate B
> LOG7[878:1] Jun 28 10:23:13: SSLv3 read client certificate B
> LOG7[878:1] Jun 28 10:23:13: SSLv3 read client certificate B
> LOG3[878:1] Jun 28 10:23:13: SSL_accept fire: error:140890B2:SSL
> routines:SSL3_GET_CLIENT_CERTIFICATE:no certificate returned
>
> The same was working with stunnel-3.8 and openssl-0.9.4
>
There are two possibilities. One is that the certificate chain is really
invalid (OpenSSL 0.9.4 didn't check this) the other is that its the
server certificate checking bug.
Try a later snapshot or just replace the file crypto\x509v3\v3_purp.c
with one from the latest snapshot.
Steve.
--
Dr Stephen N. Henson. http://www.drh-consultancy.demon.co.uk/
Personal Email: [EMAIL PROTECTED]
Senior crypto engineer, Celo Communications: http://www.celocom.com/
Core developer of the OpenSSL project: http://www.openssl.org/
Business Email: [EMAIL PROTECTED] PGP key: via homepage.
______________________________________________________________________
OpenSSL Project http://www.openssl.org
Development Mailing List [EMAIL PROTECTED]
Automated List Manager [EMAIL PROTECTED]