RE: OCSP-validation fails - Wrong cert passed to OCSP by Apache

2010-08-17 Thread Ulf Wahlqvist
t out any errors I have made. /ulfW -Original Message- From: Joe Orton [mailto:jor...@redhat.com] Sent: den 17 augusti 2010 16:01 To: Ulf Wahlqvist Cc: modssl-users@modssl.org Subject: Re: OCSP-validation fails - Wrong cert passed to OCSP by Apache On Tue, Aug 17, 2010 at 12:47:26PM

Re: OCSP-validation fails - Wrong cert passed to OCSP by Apache

2010-08-17 Thread Joe Orton
On Tue, Aug 17, 2010 at 12:47:26PM +0200, Ulf Wahlqvist wrote: > I still don't get it. I used Wireshark and found out that the > certificate sent to the OCSP-responder is the CA-cert, not the > client-cert to be validated! I am clueless. The code tries to verify each cert in the client cert chai

RE: OCSP-validation fails - Wrong cert passed to OCSP by Apache

2010-08-17 Thread Ulf Wahlqvist
I still don't get it. I used Wireshark and found out that the certificate sent to the OCSP-responder is the CA-cert, not the client-cert to be validated! I am clueless. Online Certificate Status Protocol tbsRequest requestList: 1 item Request reqCert

RE: OCSP-validation fails - UPDATE

2010-07-29 Thread Ulf Wahlqvist
l.org] On Behalf Of Ulf Wahlqvist Sent: den 27 juli 2010 16:43 To: modssl-users@modssl.org Subject: OCSP-validation fails Hi I'm trying to get Apache to do Client certificate verification with OCSP-validation. It works without OCSP, but OCSP-validation fails when I turn it on.

OCSP-validation fails

2010-07-27 Thread Ulf Wahlqvist
Hi I'm trying to get Apache to do Client certificate verification with OCSP-validation. It works without OCSP, but OCSP-validation fails when I turn it on. The error is "OCSP_check_validity:status too old", but that doesn't make sense because the clocks are within 2