We're trying to do client auth to an Apache web server, and we've
discovered that if the end entity cert's issuing CA cert has an
extendedKeyUsage extension, but the extension doesn't contain the
clientAuth and serverAuth values, then the SSL handshake fails with an
invalid CA error. Adding those values, or removing the extendedKeyUsage
extension from the issuing CA cert allows it to work.

This seems like a bug to some of us around here. The end entity cert
should definitely have clientAuth and serverAuth, but we don't believe
the issuing CA cert needs to have them too.

Has anyone heard of this? I will submit it as a bug, but I wanted to
check with the list first. Thanks,

-Rick Andrews

-- 
Rick Andrews                 __o    Phone: 650-426-3401
VeriSign, Inc.             _ \>,_   Fax:   650-426-5195
487 E. Middlefield Rd. ...(_)/ (_)  URL:   www.verisign.com
Mountain View, CA  94043            email: [EMAIL PROTECTED]
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       [email protected]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to