Re: x509 cert parsing in web browsers

From: Fernando J. Pando (fpando@nyc.rr.com)
Date: 09/09/02


Date: Sun, 08 Sep 2002 22:08:38 -0400
From: "Fernando J. Pando" <fpando@nyc.rr.com>
To: admin@tek-art.com.pl


I am having the same issue with openssl.

i tried new openssl releases versions a-g but they all seem to fail on
netscape client for mac with
self-signed certs.

netscape 7.0 for mac was reported by my developers to be free of this ssl
mismatch issue.

does any one know of any server directives to fix this nescape issue?

-fjp

Administrator Serwera TEK-ART wrote:

> -----Original Message-----
> From: Administrator Serwera TEK-ART [mailto:admin@tek-art.com.pl]
> Sent: Monday, September 09, 2002 12:31 AM
> To: Michal Zalewski
> Subject: RE: x509 cert parsing in web browsers
>
> Well, it seems that I had the same problem.
>
> Bad certificate error was produced by OpenSSL, and connection failed by
> Netscape/Mozilla browser, while MSIE opened the secure pages correctly.
>
> I have noticed, that some commercial servers based on commercial (e.g.
> VeriSign) certificated are opened correctly by the browser. So it means,
> that OpenSSL produces certificates ONLY MSIE compatible. Well, as far as I
> think so :)
>
> If you know, how I can produce an all-browser-compatible certificate using
> my own CA and OpenSSL, I would be grateful for such an information.
>
> SeeYa



Relevant Pages

  • E2k7 Zertifikate (CSR mit openSSL signieren)
    ... Auf diesem habe ich eine RootCA und eine ServerCA etabliert. ... Mit New-ExchangeCertificate erzeuge ich jetzt ein Zertifikatsrequest (CSR) und stelle diesen der openSSL Server CA zum signieren bereit. ... certificate = $dir/ServerCA.cert.pem ...
    (microsoft.public.de.exchange)
  • Re: guidance on SSL certs and Apache2
    ... including the fact that the setup is neither automated nor documented ... > it has Kleopatra for certificate management. ... openssl req -new -key server.key -out newreq.pem ... /etc/init.d/apache2 restart ...
    (Debian-User)
  • Re: Pine and CA certificates
    ... Pine is installed in a shared file system; it would have been nice for the CA certificate that signed the IMAP server's certificate to have been there too. ... So, instead of reconfiguring OpenSSL once and being done with it, you instead want to reconfigure every application program that uses OpenSSL? ... You don't want the SSLKEYS directory to be the same as the CA certificate directory, since only a file protection stands between that key and a hacker who could do bad things with it. ... Most people just use the OpenSSL standard CA certificate directory, or they rebuild OpenSSL so that its standard CA certificate directory is what they want it to be. ...
    (comp.mail.pine)
  • Re: Help with issuing self signed certificates
    ... I generate a RSA key using openSSL. ... How do I make the clients trust my CA? ... OpenSSL comes with a simplistic script CA.sh (there's also a perl ... You also need a CA certificate, and a few files here and there for the ...
    (comp.security.misc)
  • 2K3 Cert Svcs gives invalid policy error on OpenSSL gend cert req
    ... OpenSSL-based UNIX SSL client and server and a Windows Server 2003 ... Standard Edition with Certificate Services for the CA. ... The OpenSSL generated ones look like, ... X509v3 Extended Key Usage: ...
    (microsoft.public.windows.server.security)