Hi,

Just clarifying on the previous comment.  From the release notes I've seen in 
the bionic package, I understand this fix does:
>     - debian/patches/tlsv1.3-support-3.patch: fail with 403 if
>      SSL_verify_client_post_handshake fails in
>      modules/ssl/ssl_engine_kernel.c.

However, when authentication is optional (SSLVerifyClient optional) and
no client authentication is provided, it MUST NOT count as a failure and
request processing should continue...

Cheers,
Vlad

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1865900

Title:
  apache 2.4.29-1ubuntu4.12 authentication with client certificate
  broken

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu-release-notes/+bug/1865900/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to