x509 cert parsing in web browsers

From: Administrator Serwera TEK-ART (admin@tek-art.com.pl)
Date: 09/09/02


From: "Administrator Serwera TEK-ART" <admin@tek-art.com.pl>
To: <vuln-dev@securityfocus.com>
Date: Mon, 9 Sep 2002 02:07:43 +0200


-----Original Message-----
From: Administrator Serwera TEK-ART [mailto:admin@tek-art.com.pl]
Sent: Monday, September 09, 2002 12:31 AM
To: Michal Zalewski
Subject: RE: x509 cert parsing in web browsers

Well, it seems that I had the same problem.

Bad certificate error was produced by OpenSSL, and connection failed by
Netscape/Mozilla browser, while MSIE opened the secure pages correctly.

I have noticed, that some commercial servers based on commercial (e.g.
VeriSign) certificated are opened correctly by the browser. So it means,
that OpenSSL produces certificates ONLY MSIE compatible. Well, as far as I
think so :)

If you know, how I can produce an all-browser-compatible certificate using
my own CA and OpenSSL, I would be grateful for such an information.

SeeYa



Relevant Pages

  • Re: How to starthandshake with client browser??
    ... >> And then what should i do to handshake with browser? ... > getting the browser to trust your certificate. ... 1-Open an SSL server Socket ... 2-Wait for a connection (from your client web browser). ...
    (comp.lang.java.programmer)
  • Re: username and Password sent as clear text strings
    ... I don't believe a certificate was every presented to the browser, I'll double check that when I get on the client site this morning. ... I completed a security review of a web server, ... Webscarab, like all intercepting web proxy programs I've used on ...
    (Pen-Test)
  • Re: Outlook Web Access / Remote Web Workplace
    ... I am unsure how the certificate process works, ... with what you type into the browser as that is the ... satisfied it is the one you expect to see, and if you install it, the ... generally the more dubious web sites which use only IP addresses, ...
    (microsoft.public.windows.server.sbs)
  • [Full-disclosure] Certificate spoofing issue with Mozilla, Konqueror, Safari 2
    ... This makes the user vulnerable to certificate spoofing by ... Assumed a phisher could redirect a user's browser to his prepared ... so the cert looks ok. ...
    (Full-Disclosure)
  • E2k7 Zertifikate (CSR mit openSSL signieren)
    ... Auf diesem habe ich eine RootCA und eine ServerCA etabliert. ... Mit New-ExchangeCertificate erzeuge ich jetzt ein Zertifikatsrequest (CSR) und stelle diesen der openSSL Server CA zum signieren bereit. ... certificate = $dir/ServerCA.cert.pem ...
    (microsoft.public.de.exchange)