Hi, Just clarifying on the previous comment. From the release notes I've seen in the bionic package, I understand this fix does: > - debian/patches/tlsv1.3-support-3.patch: fail with 403 if > SSL_verify_client_post_handshake fails in > modules/ssl/ssl_engine_kernel.c.
However, when authentication is optional (SSLVerifyClient optional) and no client authentication is provided, it MUST NOT count as a failure and request processing should continue... Cheers, Vlad -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1865900 Title: apache 2.4.29-1ubuntu4.12 authentication with client certificate broken To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu-release-notes/+bug/1865900/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
