Welcome! Log In Create A New Profile

Advanced

Re: $ssl_client_escaped_cert does not contain intermediate client certificates

July 06, 2020 03:55PM
Thanks for your reply, Maxim! I'll work out an alternative then.

Re. session resumption, I read in the OpenSSL docs (https://www.openssl.org/docs/man1.1.0/man3/SSL_get0_verified_chain.html) that OpenSSL is willing to store the chain longer than a single request, but only if the implementing application (nginx) is managing freeing it at the proper time (eg. when the session times out):
> If applications wish to use any certificates in the returned chain indefinitely they must increase the reference counts using X509_up_ref() or obtain a copy of the whole chain with X509_chain_up_ref().

ps. I now see that HAProxy is also discussing it: https://www.mail-archive.com/haproxy@formilux.org/msg35607.html
Subject Author Posted

$ssl_client_escaped_cert does not contain intermediate client certificates

everhardt July 04, 2020 05:52AM

Re: $ssl_client_escaped_cert does not contain intermediate client certificates

Maxim Dounin July 06, 2020 11:12AM

Re: $ssl_client_escaped_cert does not contain intermediate client certificates

everhardt July 06, 2020 03:55PM

Re: $ssl_client_escaped_cert does not contain intermediate client certificates

Maxim Dounin July 06, 2020 08:48PM

Re: $ssl_client_escaped_cert does not contain intermediate client certificates

everhardt July 07, 2020 03:18AM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 258
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready