On Mon, Nov 18, 2002, Richard Levitte - VMS Whacker wrote:
> In message <[EMAIL PROTECTED]> on Mon, 18 Nov 2002 
>10:43:54 -0800, Ed Kasky <[EMAIL PROTECTED]> said:
> 

> ed> 27781:error:140890E9:SSL routines:SSL3_GET_CLIENT_CERTIFICATE:tls peer did
> ed> not respond with certificate list:s3_srvr.c:1638:
> 
> The last two lines should say it all.  You need a client certificate
> in Eudora, or if possible, turn off the need for client certificates
> in sendmail.  I don't know how to do either.

Why do you need a client cert?

AFAIK the client can respond with an empty list (RFC 2246, section
7.4.6).  This is what sendmail (using OpenSSL) does when it acts
as client and no client cert is available.

The question is whether Eudora is broken and should respond with
an empty list too.

PS: yes, you can turn off the certificate request, but that defeats
the possibility to allow relaying based on certs.
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to