Re: [ANN] Apache Tomcat Native 1.2.8 released

2016-07-04 Thread Florian Kleedorfer
Dear Mark, Thank you for fixing the OCSP bug I reported. I just tried the new release and I can confirm it works. Best regards, Florian Am 04.07.2016 um 16:57 schrieb Mark Thomas: The Apache Tomcat team announces the immediate availability of Apache Tomcat Native 1.2.8 stable. The key

Re: SSLVerifyClient="optionalNoCA" stops working in tomcat 8.0.32?

2016-06-17 Thread Florian Kleedorfer
Hi Christopher, Thanks for looking into this! Am 17.06.2016 um 00:01 schrieb Christopher Schultz: clientAuth="want"? Note that this is only documented for the JSSE-based connectors, not the APR connector. Yes, thanks - I think that's garbage left in there from my attempts to use BIO/NIO

Re: SSLVerifyClient="optionalNoCA" stops working in tomcat 8.0.32?

2016-06-16 Thread Florian Kleedorfer
with it for now, but we need a solution at some point. What is the recommended course of action in this case? Best regards, Florian Am 19.05.2016 um 18:49 schrieb Florian Kleedorfer: Hi! TL;DR: The TLS handshake with client authentication using self-signed client certificates (using APR/openssl

SSLVerifyClient="optionalNoCA" stops working in tomcat 8.0.32?

2016-05-19 Thread Florian Kleedorfer
Hi! TL;DR: The TLS handshake with client authentication using self-signed client certificates (using APR/openssl) stopped working from tomcat 8.0.30 to tomcat 8.0.32. Cause is suspected in a change of openssl or APR between versions. # Context: We're using tomcat 8 in a setting where the