We're trying to do client auth to an Apache web server, and we've discovered that if the end entity cert's issuing CA cert has an extendedKeyUsage extension, but the extension doesn't contain the clientAuth and serverAuth values, then the SSL handshake fails with an invalid CA error. Adding those values, or removing the extendedKeyUsage extension from the issuing CA cert allows it to work.
This seems like a bug to some of us around here. The end entity cert should definitely have clientAuth and serverAuth, but we don't believe the issuing CA cert needs to have them too. Has anyone heard of this? I will submit it as a bug, but I wanted to check with the list first. Thanks, -Rick Andrews -- Rick Andrews __o Phone: 650-426-3401 VeriSign, Inc. _ \>,_ Fax: 650-426-5195 487 E. Middlefield Rd. ...(_)/ (_) URL: www.verisign.com Mountain View, CA 94043 email: [EMAIL PROTECTED] ______________________________________________________________________ OpenSSL Project http://www.openssl.org Development Mailing List [email protected] Automated List Manager [EMAIL PROTECTED]
