Welcome! Log In Create A New Profile

Advanced

Re: failure to limit access to a secure area with self-signed client SSL cert fingerprint match

Francis Daly
March 21, 2023 08:54PM
On Tue, Mar 21, 2023 at 07:02:23PM -0400, PGNet Dev wrote:
> > What does the error_log say about this request and response?

> 2023/03/21 18:52:14 [info] 4955#4955: *7 client SSL certificate verify error: certificate status request failed while reading client request headers, client: 2401::...::1, server: example.com, request: "GET / HTTP/2.0", host: "example.com"

That'll be why nginx blocks the access, at least -- the client cert is
not verified as good.

You have indicated that the client cert has:

Issuer: C = US, ST = NY, O = example.com, OU = example.com_CA, CN = example.com_CA_INT, emailAddress = ssl@example.com

Do you have the certificate that has that value as the Subject? What
is that certificate's Issuer? And repeat until you get to the root
certificate.

And which of the ssl*certificate files named in your config holds those certificates?

f
--
Francis Daly francis@daoine.org
_______________________________________________
nginx mailing list
nginx@nginx.org
https://mailman.nginx.org/mailman/listinfo/nginx
Subject Author Posted

failure to limit access to a secure area with self-signed client SSL cert fingerprint match

pgn March 20, 2023 01:52PM

Re: failure to limit access to a secure area with self-signed client SSL cert fingerprint match

Francis Daly March 21, 2023 05:50PM

Re: failure to limit access to a secure area with self-signed client SSL cert fingerprint match

pgn March 21, 2023 07:04PM

Re: failure to limit access to a secure area with self-signed client SSL cert fingerprint match

Francis Daly March 21, 2023 08:54PM

Re: failure to limit access to a secure area with self-signed client SSL cert fingerprint match

pgn March 22, 2023 08:50AM

Re: failure to limit access to a secure area with self-signed client SSL cert fingerprint match

Francis Daly March 23, 2023 06:00PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 162
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready