Re: [openssl.org #3102] s_server does not reject invalid client certificates in "OpenSSL 1.0.1 14 Mar 2012" with -verify or -Verify options

2013-08-06 Thread Jim Keener via RT
Steve, Thank you! That worked. That option doesn't exist in the man page for s_server (1.0.1 2013-06-04) for me, so this may be a documentation bug then? Thanks again! Jim On 08/06/2013 10:46 AM, Stephen Henson via RT wrote: > On Fri Aug 02 10:23:23 2013, j...@jimkeener.com wrote: >> With -ver

[openssl.org #3102] s_server does not reject invalid client certificates in "OpenSSL 1.0.1 14 Mar 2012" with -verify or -Verify options

2013-08-02 Thread Jim Keener via RT
Steps to reproduce: mkdir client_cert_test mkdir CA cd CA openssl req -out CA.pem -new -x509 openssl pkcs12 -export -out CA.pfx -inkey privkey.pem -in CA.pem echo "00" > serial cd .. mkdir server cd server openssl genrsa -out server.key 1024 openssl req -key server.key -new -out server.req openssl