<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:www.nabble.com,2006:forum-380</id>
	<title>Nabble - mod_ssl</title>
	<updated>2008-10-10T13:03:34Z</updated>
	<link rel="self" type="application/atom+xml" href="http://www.nabble.com/mod_ssl-f380.xml" />
	<link rel="alternate" type="text/html" href="http://www.nabble.com/mod_ssl-f380.html" />
	<subtitle type="html">mod_ssl provides strong cryptography for the Apache 1.3 webserver via the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) protocols. mod_ssl home is &lt;a href=&quot;http://www.modssl.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;here&lt;/a&gt;.</subtitle>
	
<entry>
	<id>tag:www.nabble.com,2006:post-19925184</id>
	<title>Jean-Pierre Guilloteau est absent.</title>
	<published>2008-10-10T13:03:34Z</published>
	<updated>2008-10-10T13:03:34Z</updated>
	<author>
		<name>jpguilloteau</name>
	</author>
	<content type="html">&lt;br&gt;I will be out of the office starting Fri 10/10/08 and will not return until
&lt;br&gt;Mon 27/10/08.
&lt;br&gt;&lt;br&gt;Je répondrai à votre message dès mon retour.
&lt;br&gt;Cordialement.
&lt;br&gt;&lt;br&gt;______________________________________________________________________
&lt;br&gt;Apache Interface to OpenSSL (mod_ssl) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; www.modssl.org
&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19925184&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19925184&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Jean-Pierre-Guilloteau-est-absent.-tp19925184p19925184.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19920735</id>
	<title>Re: X509 variables  ..UID</title>
	<published>2008-10-10T08:38:20Z</published>
	<updated>2008-10-10T08:38:20Z</updated>
	<author>
		<name>Michael Ströder</name>
	</author>
	<content type="html">Peter Sylvester wrote:
&lt;br&gt;&amp;gt; in ssl_engine_vars, there seems to be a problem to me concerning the UID
&lt;br&gt;&amp;gt; field.
&lt;br&gt;&amp;gt; The syntax for the field is a bitstring and not a &amp;quot;text&amp;quot;.
&lt;br&gt;&lt;br&gt;Nothing happened since I've filed this bug and raised the issue here:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &lt;a href=&quot;https://issues.apache.org/bugzilla/show_bug.cgi?id=45107&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://issues.apache.org/bugzilla/show_bug.cgi?id=45107&lt;/a&gt;&lt;br&gt;&lt;br&gt;It's broken =&amp;gt; it should be fixed. Unfortunately no-one cares. :-(
&lt;br&gt;&lt;br&gt;Ciao, Michael.
&lt;br&gt;______________________________________________________________________
&lt;br&gt;Apache Interface to OpenSSL (mod_ssl) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; www.modssl.org
&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19920735&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19920735&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/X509-variables--..UID-tp19919949p19920735.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19919949</id>
	<title>X509 variables  ..UID</title>
	<published>2008-10-10T07:49:54Z</published>
	<updated>2008-10-10T07:49:54Z</updated>
	<author>
		<name>Peter Sylvester-3</name>
	</author>
	<content type="html">in ssl_engine_vars, there seems to be a problem to me concerning the UID 
&lt;br&gt;field.
&lt;br&gt;The syntax for the field is a bitstring and not a &amp;quot;text&amp;quot;.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;static const struct {
&lt;br&gt;&amp;nbsp; &amp;nbsp; char *name;
&lt;br&gt;&amp;nbsp; &amp;nbsp; int &amp;nbsp; nid;
&lt;br&gt;} ssl_var_lookup_ssl_cert_dn_rec[] = {
&lt;br&gt;&amp;nbsp; &amp;nbsp; { &amp;quot;C&amp;quot;, &amp;nbsp; &amp;nbsp; NID_countryName &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;},
&lt;br&gt;&amp;nbsp; &amp;nbsp; { &amp;quot;ST&amp;quot;, &amp;nbsp; &amp;nbsp;NID_stateOrProvinceName &amp;nbsp; &amp;nbsp;}, /* officially &amp;nbsp; &amp;nbsp;(RFC2156) */
&lt;br&gt;&amp;nbsp; &amp;nbsp; { &amp;quot;SP&amp;quot;, &amp;nbsp; &amp;nbsp;NID_stateOrProvinceName &amp;nbsp; &amp;nbsp;}, /* compatibility (SSLeay) &amp;nbsp;*/
&lt;br&gt;&amp;nbsp; &amp;nbsp; { &amp;quot;L&amp;quot;, &amp;nbsp; &amp;nbsp; NID_localityName &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; },
&lt;br&gt;&amp;nbsp; &amp;nbsp; { &amp;quot;O&amp;quot;, &amp;nbsp; &amp;nbsp; NID_organizationName &amp;nbsp; &amp;nbsp; &amp;nbsp; },
&lt;br&gt;&amp;nbsp; &amp;nbsp; { &amp;quot;OU&amp;quot;, &amp;nbsp; &amp;nbsp;NID_organizationalUnitName },
&lt;br&gt;&amp;nbsp; &amp;nbsp; { &amp;quot;CN&amp;quot;, &amp;nbsp; &amp;nbsp;NID_commonName &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; },
&lt;br&gt;&amp;nbsp; &amp;nbsp; { &amp;quot;T&amp;quot;, &amp;nbsp; &amp;nbsp; NID_title &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;},
&lt;br&gt;&amp;nbsp; &amp;nbsp; { &amp;quot;I&amp;quot;, &amp;nbsp; &amp;nbsp; NID_initials &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; },
&lt;br&gt;&amp;nbsp; &amp;nbsp; { &amp;quot;G&amp;quot;, &amp;nbsp; &amp;nbsp; NID_givenName &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;},
&lt;br&gt;&amp;nbsp; &amp;nbsp; { &amp;quot;S&amp;quot;, &amp;nbsp; &amp;nbsp; NID_surname &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;},
&lt;br&gt;&amp;nbsp; &amp;nbsp; { &amp;quot;D&amp;quot;, &amp;nbsp; &amp;nbsp; NID_description &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;},
&lt;br&gt;#if SSL_LIBRARY_VERSION &amp;gt;= 0x00907000
&lt;br&gt;&amp;nbsp; &amp;nbsp; { &amp;quot;UID&amp;quot;, &amp;nbsp; NID_x500UniqueIdentifier &amp;nbsp; },
&lt;br&gt;#else
&lt;br&gt;&amp;nbsp; &amp;nbsp; { &amp;quot;UID&amp;quot;, &amp;nbsp; NID_uniqueIdentifier &amp;nbsp; &amp;nbsp; &amp;nbsp; },
&lt;br&gt;#endif
&lt;br&gt;&amp;nbsp; &amp;nbsp; { &amp;quot;Email&amp;quot;, NID_pkcs9_emailAddress &amp;nbsp; &amp;nbsp; },
&lt;br&gt;&amp;nbsp; &amp;nbsp; { NULL, &amp;nbsp; &amp;nbsp;0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;}
&lt;br&gt;};
&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;&lt;br&gt;&amp;lt;&lt;a href=&quot;http://www.edelweb.fr&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.edelweb.fr&lt;/a&gt;&amp;gt;
&lt;br&gt;*Edel/W/eb* 	Peter SYLVESTER
&lt;br&gt;Consultant Sécurité des Systèmes d'Information
&lt;br&gt;-----------------------------------------------------------
&lt;br&gt;EdelWeb - Groupe ON-X
&lt;br&gt;15, quai de Dion-Bouton
&lt;br&gt;F-92816 Puteaux Cedex
&lt;br&gt;Tel : +33.1.40.99.14.14 / Fax : +33.1.40.99.99.58
&lt;br&gt;www.edelweb.fr &amp;lt;&lt;a href=&quot;http://www.edelweb.fr&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.edelweb.fr&lt;/a&gt;&amp;gt; / www.on-x.com &amp;lt;&lt;a href=&quot;http://www.on-x.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.on-x.com&lt;/a&gt;&amp;gt;
&lt;br&gt;-----------------------------------------------------------
&lt;br&gt;To verify the message signature, see edelpki.edelweb.fr 
&lt;br&gt;&amp;lt;&lt;a href=&quot;http://edelpki.edelweb.fr/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://edelpki.edelweb.fr/&lt;/a&gt;&amp;gt;
&lt;br&gt;Cela vous permet de charger le certificat de l'autorité de racine 
&lt;br&gt;&amp;lt;&lt;a href=&quot;http://edelpki.edelweb.fr/cacerts/EdelPKI-ca.der&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://edelpki.edelweb.fr/cacerts/EdelPKI-ca.der&lt;/a&gt;&amp;gt;;
&lt;br&gt;die Liste mit zurückgerufenen Zertifikaten finden Sie da auch.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://www.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (5K) &lt;a href=&quot;http://www.nabble.com/attachment/19919949/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/X509-variables--..UID-tp19919949p19919949.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19843625</id>
	<title>Embedded purposes</title>
	<published>2008-10-06T11:32:45Z</published>
	<updated>2008-10-06T11:32:45Z</updated>
	<author>
		<name>Gunnar P. Vestergaard</name>
	</author>
	<content type="html">If a user is trying to authenticate himself with an SSL web server, he 
&lt;br&gt;needs to present a valid personal certificate, I understand. But what if 
&lt;br&gt;the purpose of the client certificate is not valid? I mean, for one 
&lt;br&gt;user's certificate, Mozilla SeaMonkey reports: &amp;quot;This certificate has 
&lt;br&gt;been verified for the following uses: Email Signer Certificate and Email 
&lt;br&gt;Recipient Certificate&amp;quot;. Will an SSL web server accept such a client 
&lt;br&gt;certificate for authenticating an SSL web connection?
&lt;br&gt;&lt;br&gt;Gunnar Vestergaard
&lt;br&gt;______________________________________________________________________
&lt;br&gt;Apache Interface to OpenSSL (mod_ssl) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; www.modssl.org
&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19843625&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19843625&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Can-i-use-CA-signed-cert-to-create-client-authentication-certificates---tp19614593p19843625.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19692550</id>
	<title>Re: Can i use CA signed cert to create client authentication certificates ?</title>
	<published>2008-09-26T10:02:15Z</published>
	<updated>2008-09-26T10:02:15Z</updated>
	<author>
		<name>Matt032</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;Asking every time does make it complicated. I can't remember if the firefox default is to ask or auto supply (and it has changed behavior between 1/2/3 AFAIK), I have it as ask every time.
&lt;br&gt;&lt;br&gt;Anyway the ask every time FF behavior isn't very nice for users (auto supply is probably fine for most users). FF will also ask for a cert every session ID change.
&lt;br&gt;&lt;br&gt;As you know there isn't an ask once option, which would be very nice. &amp;nbsp;I don't think there is much that can be done to &amp;quot;fix&amp;quot; it other than coding up an &amp;quot;ask once&amp;quot; option in FF (which I haven't got the time to do :( ).
&lt;br&gt;&lt;br&gt;Anyway you may also want to use/need the &amp;quot;SSLOptions +OptRenegotiate&amp;quot; if you have portions of the site that do and don't require client certs. It can help greatly with IE. Sometimes IE goes a little funny and renegotiates sessions all the time going from non-client cert to client cert areas.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Regards
&lt;br&gt;Matt
&lt;br&gt;&lt;br&gt;&lt;br&gt;----- Original Message ----
&lt;br&gt;From: Jan Stian Gabrielli &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19692550&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;stian@...&lt;/a&gt;&amp;gt;
&lt;br&gt;To: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19692550&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Sent: Thursday, September 25, 2008 9:37:00 AM
&lt;br&gt;Subject: Re: Can i use CA signed cert to create client authentication certificates ?
&lt;br&gt;&lt;br&gt;Thank you very much Matt .
&lt;br&gt;That solved it :).
&lt;br&gt;&lt;br&gt;I now have &amp;quot;Client Certificate Authentication&amp;quot; working with a CA signed certificate and a Self Signed CA which in turn signs client certs.
&lt;br&gt;&lt;br&gt;If i can only ask for a bit more advice regarding this setup ?.
&lt;br&gt;Although I think this problem might be Firefox specific I'm hoping for some advice here. 
&lt;br&gt;&lt;br&gt;Internet Explorer handles the client certificates fine, prompts me to select certificate on connection to the site and basically just works after that..
&lt;br&gt;&lt;br&gt;But when Firefox is set to &amp;quot;Ask me every time&amp;quot; instead of &amp;quot;auto select client certificate&amp;quot; I keep getting the select certificate pop up several(multiple) times per page request/load from the SSL secured Apache server.
&lt;br&gt;There is only one certificate in the select from dialog, but it keeps prompting me and I can see it loading &amp;quot;one&amp;quot; and &amp;quot;one&amp;quot; item(image) on the website.
&lt;br&gt;If i switch to &amp;quot;Auto select certificate&amp;quot; it works. But it would be nice not having the browser present the certificate without it being the users choice. And honestly, choosing it once per session per site should be sufficient
&lt;br&gt;&lt;br&gt;I should probably mention that the page served up is behind a mod_proxy module. But this content should not differ for Firefox, and certificate selection. Or does the mod_ssl module prompt for a client certificate for each item loaded ?
&lt;br&gt;&lt;br&gt;I have googled this but can't find any good answers.
&lt;br&gt;Some say it is because of image objects loading. but why. 
&lt;br&gt;&lt;br&gt;Best regards
&lt;br&gt;&lt;br&gt;Jan Stian Gabrielli
&lt;br&gt;&lt;br&gt;Original Message -----------------------
&lt;br&gt;Hi,
&lt;br&gt;&lt;br&gt;Basically...
&lt;br&gt;&lt;br&gt;SSLCACertificateFile SelfSignedCA Root Cert (public part)
&lt;br&gt;SSLVerifyClient require or optional
&lt;br&gt;SSLVerifyDepth 1 (default)
&lt;br&gt;&lt;br&gt;and have the setup from the Thwate cert as per normal for the server cert.
&lt;br&gt;&lt;br&gt;Regards
&lt;br&gt;Matt
&lt;br&gt;&lt;br&gt;----- Original Message ----
&lt;br&gt;From: Jan Stian Gabrielli &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19692550&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;stian@...&lt;/a&gt;&amp;gt;
&lt;br&gt;To: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19692550&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Sent: Tuesday, September 23, 2008 1:39:16 PM
&lt;br&gt;Subject: Re: Can i use CA signed cert to create client authentication certificates ?
&lt;br&gt;&lt;br&gt;Ok. This seems like a viable solution.
&lt;br&gt;Ie.
&lt;br&gt;I use an approved CA signed cert to verify the site auhtentisity, and i use a selfsigned CA root for client certificates.
&lt;br&gt;&lt;br&gt;Can you point me in a direction of how i make this work in apache ?.
&lt;br&gt;I already have a setup with a Selfsigned CA working for client certificates.
&lt;br&gt;&lt;br&gt;Createed SelfSignedCA
&lt;br&gt;|--&amp;gt;Create and Sign Apache Cert from SelfSigned CA
&lt;br&gt;|--&amp;gt;Create and Sign Client Cert from SelfSigned CA
&lt;br&gt;&lt;br&gt;How do I incorporate this with a CA (thawte) signed webserver certificate ?.
&lt;br&gt;&lt;br&gt;Best regards
&lt;br&gt;&lt;br&gt;Wizkidnono
&lt;br&gt;&lt;br&gt;Original Message -----------------------
&lt;br&gt;Sounds like your trying to use the thawte apache cert to sign your client certs? The thawte cert won't have the right attributes to sign a client cert and then try to use it.
&lt;br&gt;&lt;br&gt;You could use your CA for client certs and Thawte for the server cert.
&lt;br&gt;&lt;br&gt;Regards
&lt;br&gt;Matt
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;----- Original Message ----
&lt;br&gt;From: Jan Stian Gabrielli &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19692550&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;stian@...&lt;/a&gt;&amp;gt;
&lt;br&gt;To: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19692550&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Sent: Monday, September 22, 2008 7:54:37 PM
&lt;br&gt;Subject: Can i use CA signed cert to create client authentication certificates ?
&lt;br&gt;&lt;br&gt;I am trying to set up apache with mod_ssl , and I have it working with a
&lt;br&gt;Self Signed CA.
&lt;br&gt;But i can not get it to work with a cert created by thawte.com.
&lt;br&gt;&lt;br&gt;Does anyone know if it is possible to do this with a crt signed by a &amp;quot;third&amp;quot;
&lt;br&gt;party where one does not have access to their root ca key ?..
&lt;br&gt;&lt;br&gt;Ie.
&lt;br&gt;&lt;br&gt;I have generated a : apache_server.key made a apache_server..csr and sent
&lt;br&gt;this for signing by thawte.com
&lt;br&gt;Recived a apache_server.crt
&lt;br&gt;&lt;br&gt;Created a client.key and a client.csr
&lt;br&gt;Signed it with my apache_server.key and apache_server.crt
&lt;br&gt;&lt;br&gt;Converted the client.key,crt to a pkcs12 file and imported this into my
&lt;br&gt;browser but i can not make things work.
&lt;br&gt;&lt;br&gt;SSL works fine on the server on pages that does not require SSL client auth.
&lt;br&gt;&lt;br&gt;A I stated earlier, IT works when I create and self sign a CA, but I cant
&lt;br&gt;make it work when I use a 3rd party CA and only have apache_server.key,
&lt;br&gt;apache_server.crt , thawte root cert.
&lt;br&gt;&lt;br&gt;Best regards
&lt;br&gt;&lt;br&gt;Wizkidnono
&lt;br&gt;Ã¢â‚¬â€œÃ…â€œÃ¢â‚¬Â¦ÃƒÂ¢'Ã‚ÂµÃƒÂªÃƒÅ¸iÃƒâ€¡Ã‚Â­ ÃƒÂª^Ã¯Â¿Â½$Ã¢â‚¬Â¹Ã…Â¡Ã¢â‚¬Â¡lÃ‚Â²\0Ãƒâ€šjÃ‚Â²Ãƒâ€°hÃ‚Â®,zÃ‚Â´Ã‚Â®Ã‚Â¦Ã…Â¡+Ã‚Â´Ãƒâ€ Ã‚Â¢Ã¢â‚¬â€œ)Ãƒ .+-Ã…Â¡Ã¢â‚¬Â¡lÃ‚Â²[Ã‚Â¬zÃ‚Â»&amp;Ã‚Â¡Ãƒâ€º,Ã¢â‚¬â€œÃ… Ãƒ ÃƒÂ«hÃ¢â€žÂ¢Ã‚Â«^tÃ‚Â¸Ã‚Â¬Ã‚Â´Ãƒâ€ Ã‚Â§jÃ‚Â«Ã¢â€žÂ¢Ã‚Â¨ÃƒÂ¨Ã‚Â­ÃƒÅ¡&amp;Ã‚Â¢jÃ‚Â²Ãƒâ€°hÃ‚Â®
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;______________________________________________________________________
&lt;br&gt;Apache Interface to OpenSSL (mod_ssl) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;www.modssl.org
&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19692550&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19692550&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;â€“Å“â€¦Ã¢'ÂµÃªÃŸiÃ‡Â­ Ãª^ï¿½$â€¹Å¡â€¡lÂ²\0Ã‚jÂ²Ã‰hÂ®,zÂ´Â®Â¦Å¡+Â´Ã†Â¢â€“)Ã .+-Å¡â€¡lÂ²[Â¬zÂ»&amp;Â¡Ã›,â€“Å Ã Ã«hâ„¢Â«^tÂ¸Â¬Â´Ã†Â§jÂ«â„¢Â¨Ã¨Â­Ãš&amp;Â¢jÂ²Ã‰hÂ®
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;______________________________________________________________________
&lt;br&gt;Apache Interface to OpenSSL (mod_ssl) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; www.modssl.org
&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19692550&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19692550&amp;i=9&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;–œ…â'µêßiÇ­ ê^�$‹š‡l²\0Âj²Éh®,z´®¦š+´Æ¢–)à.+-š‡l²[¬z»&amp;¡Û,–Šàëh™«^t¸¬´Æ§j«™¨è­Ú&amp;¢j²Éh®
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;______________________________________________________________________
&lt;br&gt;Apache Interface to OpenSSL (mod_ssl) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; www.modssl.org
&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19692550&amp;i=10&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19692550&amp;i=11&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Can-i-use-CA-signed-cert-to-create-client-authentication-certificates---tp19614593p19692550.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19634162</id>
	<title>Re: Can i use CA signed cert to create client authentication certificates ?</title>
	<published>2008-09-23T11:36:51Z</published>
	<updated>2008-09-23T11:36:51Z</updated>
	<author>
		<name>Matt032</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;Basically...
&lt;br&gt;&lt;br&gt;SSLCACertificateFile SelfSignedCA Root Cert (public part)
&lt;br&gt;SSLVerifyClient require or optional
&lt;br&gt;SSLVerifyDepth 1 (default)
&lt;br&gt;&lt;br&gt;and have the setup from the Thwate cert as per normal for the server cert.
&lt;br&gt;&lt;br&gt;Regards
&lt;br&gt;Matt
&lt;br&gt;&lt;br&gt;----- Original Message ----
&lt;br&gt;From: Jan Stian Gabrielli &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19634162&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;stian@...&lt;/a&gt;&amp;gt;
&lt;br&gt;To: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19634162&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Sent: Tuesday, September 23, 2008 1:39:16 PM
&lt;br&gt;Subject: Re: Can i use CA signed cert to create client authentication certificates ?
&lt;br&gt;&lt;br&gt;Ok. This seems like a viable solution.
&lt;br&gt;Ie.
&lt;br&gt;I use an approved CA signed cert to verify the site auhtentisity, and i use a selfsigned CA root for client certificates.
&lt;br&gt;&lt;br&gt;Can you point me in a direction of how i make this work in apache ?.
&lt;br&gt;I already have a setup with a Selfsigned CA working for client certificates.
&lt;br&gt;&lt;br&gt;Createed SelfSignedCA
&lt;br&gt;|--&amp;gt;Create and Sign Apache Cert from SelfSigned CA
&lt;br&gt;|--&amp;gt;Create and Sign Client Cert from SelfSigned CA
&lt;br&gt;&lt;br&gt;How do I incorporate this with a CA (thawte) signed webserver certificate ?.
&lt;br&gt;&lt;br&gt;Best regards
&lt;br&gt;&lt;br&gt;Wizkidnono
&lt;br&gt;&lt;br&gt;Original Message -----------------------
&lt;br&gt;Sounds like your trying to use the thawte apache cert to sign your client certs? The thawte cert won't have the right attributes to sign a client cert and then try to use it.
&lt;br&gt;&lt;br&gt;You could use your CA for client certs and Thawte for the server cert.
&lt;br&gt;&lt;br&gt;Regards
&lt;br&gt;Matt
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;----- Original Message ----
&lt;br&gt;From: Jan Stian Gabrielli &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19634162&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;stian@...&lt;/a&gt;&amp;gt;
&lt;br&gt;To: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19634162&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Sent: Monday, September 22, 2008 7:54:37 PM
&lt;br&gt;Subject: Can i use CA signed cert to create client authentication certificates ?
&lt;br&gt;&lt;br&gt;I am trying to set up apache with mod_ssl , and I have it working with a
&lt;br&gt;Self Signed CA.
&lt;br&gt;But i can not get it to work with a cert created by thawte.com.
&lt;br&gt;&lt;br&gt;Does anyone know if it is possible to do this with a crt signed by a &amp;quot;third&amp;quot;
&lt;br&gt;party where one does not have access to their root ca key ?..
&lt;br&gt;&lt;br&gt;Ie.
&lt;br&gt;&lt;br&gt;I have generated a : apache_server.key made a apache_server..csr and sent
&lt;br&gt;this for signing by thawte.com
&lt;br&gt;Recived a apache_server.crt
&lt;br&gt;&lt;br&gt;Created a client.key and a client.csr
&lt;br&gt;Signed it with my apache_server.key and apache_server.crt
&lt;br&gt;&lt;br&gt;Converted the client.key,crt to a pkcs12 file and imported this into my
&lt;br&gt;browser but i can not make things work.
&lt;br&gt;&lt;br&gt;SSL works fine on the server on pages that does not require SSL client auth.
&lt;br&gt;&lt;br&gt;A I stated earlier, IT works when I create and self sign a CA, but I cant
&lt;br&gt;make it work when I use a 3rd party CA and only have apache_server.key,
&lt;br&gt;apache_server.crt , thawte root cert.
&lt;br&gt;&lt;br&gt;Best regards
&lt;br&gt;&lt;br&gt;Wizkidnono
&lt;br&gt;â€“Å“â€¦Ã¢'ÂµÃªÃŸiÃ‡Â­ Ãª^ï¿½$â€¹Å¡â€¡lÂ²\0Ã‚jÂ²Ã‰hÂ®,zÂ´Â®Â¦Å¡+Â´Ã†Â¢â€“)Ã .+-Å¡â€¡lÂ²[Â¬zÂ»&amp;Â¡Ã›,â€“Å Ã Ã«hâ„¢Â«^tÂ¸Â¬Â´Ã†Â§jÂ«â„¢Â¨Ã¨Â­Ãš&amp;Â¢jÂ²Ã‰hÂ®
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;______________________________________________________________________
&lt;br&gt;Apache Interface to OpenSSL (mod_ssl) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;www.modssl.org
&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19634162&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19634162&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;–œ…â'µêßiÇ­ ê^�$‹š‡l²\0Âj²Éh®,z´®¦š+´Æ¢–)à.+-š‡l²[¬z»&amp;¡Û,–Šàëh™«^t¸¬´Æ§j«™¨è­Ú&amp;¢j²Éh®
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;______________________________________________________________________
&lt;br&gt;Apache Interface to OpenSSL (mod_ssl) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; www.modssl.org
&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19634162&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19634162&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Can-i-use-CA-signed-cert-to-create-client-authentication-certificates---tp19614593p19634162.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19615744</id>
	<title>Re: Can i use CA signed cert to create client authentication certificates ?</title>
	<published>2008-09-22T13:19:05Z</published>
	<updated>2008-09-22T13:19:05Z</updated>
	<author>
		<name>Matt032</name>
	</author>
	<content type="html">Sounds like your trying to use the thawte apache cert to sign your client certs? The thawte cert won't have the right attributes to sign a client cert and then try to use it.
&lt;br&gt;&lt;br&gt;You could use your CA for client certs and Thawte for the server cert.
&lt;br&gt;&lt;br&gt;Regards
&lt;br&gt;Matt
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;----- Original Message ----
&lt;br&gt;From: Jan Stian Gabrielli &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19615744&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;stian@...&lt;/a&gt;&amp;gt;
&lt;br&gt;To: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19615744&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Sent: Monday, September 22, 2008 7:54:37 PM
&lt;br&gt;Subject: Can i use CA signed cert to create client authentication certificates ?
&lt;br&gt;&lt;br&gt;I am trying to set up apache with mod_ssl , and I have it working with a
&lt;br&gt;Self Signed CA.
&lt;br&gt;But i can not get it to work with a cert created by thawte.com.
&lt;br&gt;&lt;br&gt;Does anyone know if it is possible to do this with a crt signed by a &amp;quot;third&amp;quot;
&lt;br&gt;party where one does not have access to their root ca key ?.
&lt;br&gt;&lt;br&gt;Ie.
&lt;br&gt;&lt;br&gt;I have generated a : apache_server.key made a apache_server.csr and sent
&lt;br&gt;this for signing by thawte.com
&lt;br&gt;Recived a apache_server.crt
&lt;br&gt;&lt;br&gt;Created a client.key and a client.csr
&lt;br&gt;Signed it with my apache_server.key and apache_server.crt
&lt;br&gt;&lt;br&gt;Converted the client.key,crt to a pkcs12 file and imported this into my
&lt;br&gt;browser but i can not make things work.
&lt;br&gt;&lt;br&gt;SSL works fine on the server on pages that does not require SSL client auth.
&lt;br&gt;&lt;br&gt;A I stated earlier, IT works when I create and self sign a CA, but I cant
&lt;br&gt;make it work when I use a 3rd party CA and only have apache_server.key,
&lt;br&gt;apache_server.crt , thawte root cert.
&lt;br&gt;&lt;br&gt;Best regards
&lt;br&gt;&lt;br&gt;Wizkidnono
&lt;br&gt;–œ…â'µêßiÇ­ ê^�$‹š‡l²\0Âj²Éh®,z´®¦š+´Æ¢–)à.+-š‡l²[¬z»&amp;¡Û,–Šàëh™«^t¸¬´Æ§j«™¨è­Ú&amp;¢j²Éh®
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;______________________________________________________________________
&lt;br&gt;Apache Interface to OpenSSL (mod_ssl) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; www.modssl.org
&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19615744&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19615744&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Can-i-use-CA-signed-cert-to-create-client-authentication-certificates---tp19614593p19615744.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19613946</id>
	<title>Re: Authenticating users based on S/MIME certificate</title>
	<published>2008-09-22T11:36:53Z</published>
	<updated>2008-09-22T11:36:53Z</updated>
	<author>
		<name>Matt032</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;Have a look at mod_authz_ldap (ldap baseed white listing,
&lt;br&gt;&lt;a href=&quot;http://authzldap.othello.ch/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://authzldap.othello.ch/&lt;/a&gt;). Probably far more than you need but it
&lt;br&gt;does things along the same lines and has some nice notes how to do
&lt;br&gt;various bits and pieces.
&lt;br&gt;&lt;br&gt;You can add env vars that you can use php have a look at &amp;nbsp;SSLOptions +StdEnvVars &amp;nbsp;and +ExportCertData.
&lt;br&gt;&lt;br&gt;Regards
&lt;br&gt;Matt
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;----- Original Message ----
&lt;br&gt;From: Gunnar Vestergaard &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19613946&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;post@...&lt;/a&gt;&amp;gt;
&lt;br&gt;To: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19613946&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Sent: Sunday, September 21, 2008 12:10:16 AM
&lt;br&gt;Subject: Authenticating users based on S/MIME certificate
&lt;br&gt;&lt;br&gt;Hi. I am an administrator of a user account at an Apache web server. 
&lt;br&gt;Currently the server is running Apache 1.3.37. My hosting provider plans 
&lt;br&gt;on switching to new hardware with possibly new software. So I don't know 
&lt;br&gt;if my web server will be run on Apache 1.3.37 or Apache 2.0.
&lt;br&gt;&lt;br&gt;My goal is to let visitors of my web site authenticate themselves to my 
&lt;br&gt;web server using some certificate, possibly S/MIME certificates.
&lt;br&gt;&lt;br&gt;Now, my current S/MIME certificate for personal e-mail is approved for 
&lt;br&gt;the following purposes:
&lt;br&gt;Email Signer Certificate
&lt;br&gt;Email Recipient Certificate
&lt;br&gt;&lt;br&gt;Is it possible to have such a certificate authenticate its user towards 
&lt;br&gt;an SSL web server? In any case I want to have a limited crowd of users 
&lt;br&gt;seeing a subdirectory of pages without bothering the user with a user 
&lt;br&gt;name/password dialog. Just their personal certificate lets them see 
&lt;br&gt;pages in a certain subdirectory.
&lt;br&gt;&lt;br&gt;As I understand the documentation for PHP, there is no means whereby PHP 
&lt;br&gt;can read and interpret an SSL client certificate. Is that correct?
&lt;br&gt;&lt;br&gt;Gunnar
&lt;br&gt;______________________________________________________________________
&lt;br&gt;Apache Interface to OpenSSL (mod_ssl) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;www.modssl.org
&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19613946&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19613946&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;______________________________________________________________________
&lt;br&gt;Apache Interface to OpenSSL (mod_ssl) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; www.modssl.org
&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19613946&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19613946&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Authenticating-users-based-on-S-MIME-certificate-tp19589935p19613946.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19605391</id>
	<title>Re: Authenticating users based on S/MIME certificate</title>
	<published>2008-09-22T03:38:49Z</published>
	<updated>2008-09-22T03:38:49Z</updated>
	<author>
		<name>Dave Sparks-2</name>
	</author>
	<content type="html">Gunnar Vestergaard wrote:
&lt;br&gt;&lt;br&gt;&amp;nbsp;&amp;gt; My goal is to let visitors of my web site authenticate themselves to
&lt;br&gt;&amp;nbsp;&amp;gt; my web server using some certificate, possibly S/MIME certificates.
&lt;br&gt;&lt;br&gt;&amp;nbsp;&amp;gt; As I understand the documentation for PHP, there is no means whereby
&lt;br&gt;&amp;nbsp;&amp;gt; PHP can read and interpret an SSL client certificate. Is that correct?
&lt;br&gt;&lt;br&gt;It's possible to configure Apache 2 to add the client certificate to a 
&lt;br&gt;request header. &amp;nbsp;From one of my configuration files:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;RewriteCond ${ESC:%{SSL:SSL_CLIENT_CERT}} \
&lt;br&gt;^.*(-----BEGIN%20(X509%20|TRUSTED%20|)CERTIFICATE-----(%0[Dd])?%0[Aa].*%0[Aa]-----END%20\2CERTIFICATE-----(%0[Dd])?%0[Aa]).*$
&lt;br&gt;&amp;nbsp; &amp;nbsp;RewriteRule ^.*$ - [E=CLIENT_CERT:%1]
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;RequestHeader unset L-ClientCert
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;RequestHeader set L-ClientCert %{CLIENT_CERT}e env=CLIENT_CERT
&lt;br&gt;&lt;br&gt;The certificate is %-encoded to avoid problems with newline characters. 
&lt;br&gt;&amp;nbsp; Presumably PHP can use the string in the header to match the 
&lt;br&gt;certificate against a list of known certificates.
&lt;br&gt;&lt;br&gt;The certificate digest would be less unwieldy than the entire 
&lt;br&gt;certificate, but mod_ssl would need some simple changes to make the 
&lt;br&gt;digest available and I would be reluctant to use a hosting provider who 
&lt;br&gt;allowed customers to use a modified mod_ssl.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Dave Sparks
&lt;br&gt;&lt;br&gt;______________________________________________________________________
&lt;br&gt;Apache Interface to OpenSSL (mod_ssl) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; www.modssl.org
&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19605391&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19605391&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Authenticating-users-based-on-S-MIME-certificate-tp19589935p19605391.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19589935</id>
	<title>Authenticating users based on S/MIME certificate</title>
	<published>2008-09-20T16:10:16Z</published>
	<updated>2008-09-20T16:10:16Z</updated>
	<author>
		<name>Gunnar P. Vestergaard</name>
	</author>
	<content type="html">Hi. I am an administrator of a user account at an Apache web server. 
&lt;br&gt;Currently the server is running Apache 1.3.37. My hosting provider plans 
&lt;br&gt;on switching to new hardware with possibly new software. So I don't know 
&lt;br&gt;if my web server will be run on Apache 1.3.37 or Apache 2.0.
&lt;br&gt;&lt;br&gt;My goal is to let visitors of my web site authenticate themselves to my 
&lt;br&gt;web server using some certificate, possibly S/MIME certificates.
&lt;br&gt;&lt;br&gt;Now, my current S/MIME certificate for personal e-mail is approved for 
&lt;br&gt;the following purposes:
&lt;br&gt;Email Signer Certificate
&lt;br&gt;Email Recipient Certificate
&lt;br&gt;&lt;br&gt;Is it possible to have such a certificate authenticate its user towards 
&lt;br&gt;an SSL web server? In any case I want to have a limited crowd of users 
&lt;br&gt;seeing a subdirectory of pages without bothering the user with a user 
&lt;br&gt;name/password dialog. Just their personal certificate lets them see 
&lt;br&gt;pages in a certain subdirectory.
&lt;br&gt;&lt;br&gt;As I understand the documentation for PHP, there is no means whereby PHP 
&lt;br&gt;can read and interpret an SSL client certificate. Is that correct?
&lt;br&gt;&lt;br&gt;Gunnar
&lt;br&gt;______________________________________________________________________
&lt;br&gt;Apache Interface to OpenSSL (mod_ssl) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; www.modssl.org
&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19589935&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19589935&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Authenticating-users-based-on-S-MIME-certificate-tp19589935p19589935.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19536924</id>
	<title>Truncated response via mod_proxy</title>
	<published>2008-09-17T10:10:45Z</published>
	<updated>2008-09-17T10:10:45Z</updated>
	<author>
		<name>Kogelheide, Ryan LCS:EX</name>
	</author>
	<content type="html">&lt;html xmlns:o=&quot;urn:schemas-microsoft-com:office:office&quot; xmlns:w=&quot;urn:schemas-microsoft-com:office:word&quot; xmlns=&quot;http://www.w3.org/TR/REC-html40&quot;&gt;

&lt;head&gt;
&lt;meta http-equiv=Content-Type content=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;meta name=Generator content=&quot;Microsoft Word 11 (filtered medium)&quot;&gt;


&lt;/head&gt;

&lt;body lang=EN-CA link=blue vlink=purple&gt;

&lt;div class=Section1&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;I&amp;#8217;m trying to debug an issue with a client getting a
truncated response via mod_proxy and mod_ssl on apache 2.0.63. The client
software is SQLAnywhere, and they are trying to get a response from a backend
web service running under IIS6. If they make the request directly against the
origin server via SSL or port 80, it works. If they query via the reverse-proxy
on port 80, it works. On SSL via the reverse-proxy the results are truncated
(only part of the XML is returned).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;This reverse-proxy serves hundreds of vhosts and thousands
of clients a day. This is the only vhost + client with a problem.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Using wireshark, we can see that the rproxy is sending an
encrypted alert 21 and then client is sending an SSL alert 21 and closing the
connection. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;I&amp;#8217;ve set Apache&amp;#8217;s LogLevel to debug, and I can
see the incoming SSL handshake and the request, and I can see the mod_proxy
working, but I don&amp;#8217;t see a detailed trace of the response going back
(even though a partial response is sent). The access log says that the whole
response is returned. Is there some special command to trace the response?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Regards,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Ryan&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=3 face=&quot;Times New Roman&quot;&gt;&lt;span style='font-size:
12.0pt'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/body&gt;

&lt;/html&gt;
&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Truncated-response-via-mod_proxy-tp19536924p19536924.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19498912</id>
	<title>SSL works from server command line, but not from outside server. Weird!</title>
	<published>2008-09-15T11:53:46Z</published>
	<updated>2008-09-15T11:53:46Z</updated>
	<author>
		<name>John Fox-7</name>
	</author>
	<content type="html">Hi, folks.
&lt;br&gt;&lt;br&gt;I've run across a wierd problem -- https/SSL works fine when accessed
&lt;br&gt;from the machine running httpd, but is unavailable from all others.
&lt;br&gt;&lt;br&gt;Software versions: Apache 1.3.37/mod_ssl-2.8.28-1.3.37/OpenSSL 0.9.8b
&lt;br&gt;&lt;br&gt;Running 'http' on port 8118, 'https' on port 8119
&lt;br&gt;&lt;br&gt;I get positive results from openssl's &amp;quot;s_client&amp;quot; when I connect to
&lt;br&gt;8119 from the server's command line:
&lt;br&gt;&lt;br&gt;&amp;nbsp; $ openssl s_client -connect webdev-gold:8119
&lt;br&gt;&amp;nbsp; CONNECTED(00000003)
&lt;br&gt;&amp;nbsp; depth=0 /C=US/ST=Oregon/L=Medford/O=Musey's
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19498912&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Pal/OU=WebDev/CN=webdev-gold.musiciansfriend.com/emailAddress=foo@...&lt;/a&gt;
&lt;br&gt;&amp;nbsp; verify error:num=18:self signed certificate
&lt;br&gt;&amp;nbsp; verify return:1
&lt;br&gt;&amp;nbsp; depth=0 /C=US/ST=Oregon/L=Medford/O=Musey's
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19498912&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Pal/OU=WebDev/CN=webdev-gold.musiciansfriend.com/emailAddress=foo@...&lt;/a&gt;
&lt;br&gt;&amp;nbsp; &amp;lt; SNIP &amp;gt;
&lt;br&gt;&amp;nbsp; New, TLSv1/SSLv3, Cipher is DHE-RSA-AES256-SHA
&lt;br&gt;&amp;nbsp; Server public key is 1024 bit
&lt;br&gt;&amp;nbsp; Compression: NONE
&lt;br&gt;&amp;nbsp; Expansion: NONE
&lt;br&gt;&amp;nbsp; SSL-Session:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Protocol &amp;nbsp;: TLSv1
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Cipher &amp;nbsp; &amp;nbsp;: DHE-RSA-AES256-SHA
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Session-ID:
&lt;br&gt;9D8989B47E6EE3546426AFC100348052D900956A40E0C33AAB41019D71CF515E
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Session-ID-ctx:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Master-Key:
&lt;br&gt;EF1AC496532EE1B8EF0F63988AB7CED1F05F9EAB8675DD76DC54A6DC6E91410C12B9808C8567B803838137B79089591C
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Key-Arg &amp;nbsp; : None
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Krb5 Principal: None
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Start Time: 1221497972
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Timeout &amp;nbsp; : 300 (sec)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Verify return code: 18 (self signed certificate)
&lt;br&gt;&amp;nbsp; ---
&lt;br&gt;&lt;br&gt;To verify this a bit further, I (again, from the server's command
&lt;br&gt;line) made use of the 'lynx' browswer to attempt accessing https on
&lt;br&gt;port 8119 -- this worked, as well.
&lt;br&gt;&lt;br&gt;Next thing I tried was running the same &amp;quot;s_client&amp;quot; command from my
&lt;br&gt;workstation's command line:
&lt;br&gt;(openssl version 0.9.8g))
&lt;br&gt;&lt;br&gt;&amp;nbsp; $ openssl s_client -connect webdev-gold:8119 -state -debug
&lt;br&gt;&amp;nbsp; CONNECTED(00000003)
&lt;br&gt;&amp;nbsp; SSL_connect:before/connect initialization
&lt;br&gt;&amp;nbsp; write to 0x80c1340 [0x80c22f8] (124 bytes =&amp;gt; 124 (0x7C))
&lt;br&gt;&amp;nbsp; 0000 - 80 7a 01 03 01 00 51 00-00 00 20 00 00 39 00 00 &amp;nbsp; .z....Q... ..9..
&lt;br&gt;&amp;nbsp; 0010 - 38 00 00 35 00 00 16 00-00 13 00 00 0a 07 00 c0 &amp;nbsp; 8..5............
&lt;br&gt;&amp;nbsp; 0020 - 00 00 33 00 00 32 00 00-2f 00 00 07 05 00 80 03 &amp;nbsp; ..3..2../.......
&lt;br&gt;&amp;nbsp; 0030 - 00 80 00 00 05 00 00 04-01 00 80 00 00 15 00 00 &amp;nbsp; ................
&lt;br&gt;&amp;nbsp; 0040 - 12 00 00 09 06 00 40 00-00 14 00 00 11 00 00 08 &amp;nbsp; ......@.........
&lt;br&gt;&amp;nbsp; 0050 - 00 00 06 04 00 80 00 00-03 02 00 80 78 79 d0 f1 &amp;nbsp; ............xy..
&lt;br&gt;&amp;nbsp; 0060 - 49 80 86 36 2c 4a 72 b0-9a 3d 73 a6 d7 2e e9 78 &amp;nbsp; I..6,Jr..=s....x
&lt;br&gt;&amp;nbsp; 0070 - 05 4e 73 b7 84 12 ea 38-18 b1 41 c2 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; .Ns....8..A.
&lt;br&gt;&amp;nbsp; SSL_connect:SSLv2/v3 write client hello A
&lt;br&gt;&amp;nbsp; read from 0x80c1340 [0x80c7858] (7 bytes =&amp;gt; 7 (0x7))
&lt;br&gt;&amp;nbsp; 0000 - 3c 21 44 4f 43 54 59 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;lt;!DOCTY
&lt;br&gt;&amp;nbsp; SSL_connect:error in SSLv2/v3 read server hello A
&lt;br&gt;&amp;nbsp; 16389:error:140770FC:SSL routines:SSL23_GET_SERVER_HELLO:unknown
&lt;br&gt;protocol:s23_clnt.c:583:
&lt;br&gt;&lt;br&gt;&lt;br&gt;And the corresponding entry from the server's error log:
&lt;br&gt;&amp;nbsp; [Mon Sep 15 10:04:30 2008] [error] [client 172.16.70.182] Invalid
&lt;br&gt;method in request \\x80t\\x01\\x03\\x01
&lt;br&gt;&lt;br&gt;&lt;br&gt;Seems to be working from the server, but not from outside it. &amp;nbsp;So I
&lt;br&gt;thought I'd best be sure that I wasn't doing
&lt;br&gt;something silly like listening only on the loopback address or something:
&lt;br&gt;&lt;br&gt;&amp;nbsp; tcp &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0 &amp;nbsp; &amp;nbsp; &amp;nbsp;0 0.0.0.0:8118 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0.0.0.0:*
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;LISTEN
&lt;br&gt;&amp;nbsp; tcp &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0 &amp;nbsp; &amp;nbsp; &amp;nbsp;0 0.0.0.0:8119 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0.0.0.0:*
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;LISTEN
&lt;br&gt;&lt;br&gt;Which I think proves that httpd isn't confining itself to a single
&lt;br&gt;network interface.
&lt;br&gt;&lt;br&gt;I've spent a couple of hours googling on this, and discovered that
&lt;br&gt;while the the error shown in the Apache log excerpt is quite common,
&lt;br&gt;the situation I'm describing is not. &amp;nbsp;Any insights, thoughts, and
&lt;br&gt;suggestions would be appreciated, as I feel I've taken this as far as
&lt;br&gt;I can on my own.
&lt;br&gt;&lt;br&gt;I am attaching the relevant httpd.conf file -- in gzipped format -- on
&lt;br&gt;the chance it may prove helpful.
&lt;br&gt;&lt;br&gt;Thank you.
&lt;br&gt;&lt;br&gt;-John
&lt;br&gt;&lt;br /&gt; &lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://www.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;sample_httpd.conf.gz&lt;/strong&gt; (2K) &lt;a href=&quot;http://www.nabble.com/attachment/19498912/0/sample_httpd.conf.gz&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/SSL-works-from-server-command-line%2C-but-not-from-outside-server.-Weird%21-tp19498912p19498912.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19423495</id>
	<title>RE: SSL_CLIENT_S_DN &amp; SSL_CLIENT_I_DN Formats</title>
	<published>2008-09-10T14:28:11Z</published>
	<updated>2008-09-10T14:28:11Z</updated>
	<author>
		<name>Bolger, Ken</name>
	</author>
	<content type="html">&lt;!DOCTYPE HTML PUBLIC &quot;-//W3C//DTD HTML 4.0 Transitional//EN&quot;&gt;
&lt;HTML&gt;&lt;HEAD&gt;
&lt;META http-equiv=Content-Type content=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;META content=&quot;MSHTML 6.00.6000.16705&quot; name=GENERATOR&gt;&lt;/HEAD&gt;
&lt;BODY&gt;
&lt;DIV&gt;&lt;SPAN style=&quot;FONT-SIZE: 8pt; COLOR: navy; FONT-FAMILY: Arial; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-AU; mso-bidi-language: AR-SA&quot;&gt;&lt;STRONG&gt;&lt;SPAN class=151591821-10092008&gt;Hi,&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style=&quot;FONT-SIZE: 8pt; COLOR: navy; FONT-FAMILY: Arial; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-AU; mso-bidi-language: AR-SA&quot;&gt;&lt;STRONG&gt;&lt;SPAN class=151591821-10092008&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style=&quot;FONT-SIZE: 8pt; COLOR: navy; FONT-FAMILY: Arial; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-AU; mso-bidi-language: AR-SA&quot;&gt;&lt;STRONG&gt;&lt;SPAN class=151591821-10092008&gt;I have noticed that the DN components of the 
SSL_CLIENT_S_DN and SSL_CLIENT_I_DN&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style=&quot;FONT-SIZE: 8pt; COLOR: navy; FONT-FAMILY: Arial; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-AU; mso-bidi-language: AR-SA&quot;&gt;&lt;STRONG&gt;&lt;SPAN class=151591821-10092008&gt;environment variables are separated by the '/' (forward 
slash) character rather than&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style=&quot;FONT-SIZE: 8pt; COLOR: navy; FONT-FAMILY: Arial; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-AU; mso-bidi-language: AR-SA&quot;&gt;&lt;STRONG&gt;&lt;SPAN class=151591821-10092008&gt;the ',' (comma) separator as required by &amp;nbsp;RFC2253. 
&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style=&quot;FONT-SIZE: 8pt; COLOR: navy; FONT-FAMILY: Arial; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-AU; mso-bidi-language: AR-SA&quot;&gt;&lt;STRONG&gt;&lt;SPAN class=151591821-10092008&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style=&quot;FONT-SIZE: 8pt; COLOR: navy; FONT-FAMILY: Arial; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-AU; mso-bidi-language: AR-SA&quot;&gt;&lt;STRONG&gt;&lt;SPAN class=151591821-10092008&gt;Is the use of the forward slash part of an older 
standard or is there another reason for its use?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style=&quot;FONT-SIZE: 8pt; COLOR: navy; FONT-FAMILY: Arial; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-AU; mso-bidi-language: AR-SA&quot;&gt;&lt;STRONG&gt;&lt;SPAN class=151591821-10092008&gt;Is there a setting to change the 
format?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style=&quot;FONT-SIZE: 8pt; COLOR: navy; FONT-FAMILY: Arial; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-AU; mso-bidi-language: AR-SA&quot;&gt;&lt;STRONG&gt;&lt;SPAN class=151591821-10092008&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style=&quot;FONT-SIZE: 8pt; COLOR: navy; FONT-FAMILY: Arial; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-AU; mso-bidi-language: AR-SA&quot;&gt;&lt;STRONG&gt;&lt;SPAN class=151591821-10092008&gt;Thanks,&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style=&quot;FONT-SIZE: 8pt; COLOR: navy; FONT-FAMILY: Arial; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-AU; mso-bidi-language: AR-SA&quot;&gt;&lt;STRONG&gt;&lt;SPAN class=151591821-10092008&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style=&quot;FONT-SIZE: 8pt; COLOR: navy; FONT-FAMILY: Arial; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-AU; mso-bidi-language: AR-SA&quot;&gt;&lt;STRONG&gt;&lt;SPAN class=151591821-10092008&gt;Ken Bolger&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;
&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/RE%3A-SSL_CLIENT_S_DN---SSL_CLIENT_I_DN-Formats-tp19423495p19423495.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19313097</id>
	<title>Some help with ssl</title>
	<published>2008-09-04T08:27:26Z</published>
	<updated>2008-09-04T08:27:26Z</updated>
	<author>
		<name>V H-2</name>
	</author>
	<content type="html">&lt;html&gt;
&lt;head&gt;

&lt;/head&gt;
&lt;body class='hmmessage'&gt;I've been trying to secure an apache sever with ssl but I keep the following error after I enter my attributes - can anyone help. Thanks:&lt;BR&gt;
&amp;nbsp;&lt;BR&gt;
&lt;FONT color=#800000&gt;Error adding attribute&lt;BR&gt;3556:error:0D0BF041:asn1 encoding routines:ASN1_item_dup:malloc failure:.\crypto&lt;BR&gt;\asn1\a_dup.c:104: problems making Certificate Request&lt;/FONT&gt;&lt;BR&gt;
&amp;nbsp;&lt;BR&gt;
See the full print out of the command I issued below:&lt;BR&gt;
&amp;nbsp;&lt;BR&gt;
C:\Program Files\Apache Software Foundation\Apache2.2\bin&amp;gt;openssl req -config .\&lt;BR&gt;&lt;FONT face=&quot;&quot;&gt;openssl.cnf&lt;/FONT&gt; -new -out myserver.csr&lt;BR&gt;
&lt;BR&gt;Loading 'screen' into random state - done&lt;BR&gt;Generating a 1024 bit RSA private key&lt;BR&gt;...........................................++++++&lt;BR&gt;.......++++++&lt;BR&gt;writing new private key to 'privkey.pem'&lt;BR&gt;Enter PEM pass phrase:&lt;BR&gt;Verifying - Enter PEM pass phrase:&lt;BR&gt;-----&lt;BR&gt;You are about to be asked to enter information that will be incorporated&lt;BR&gt;into your certificate request.&lt;BR&gt;What you are about to enter is what is called a Distinguished Name or a DN.&lt;BR&gt;There are quite a few fields but you can leave some blank&lt;BR&gt;For some fields there will be a default value,&lt;BR&gt;If you enter '.', the field will be left blank.&lt;BR&gt;-----&lt;BR&gt;.&lt;BR&gt;
.&lt;BR&gt;
.&lt;BR&gt;
.&lt;BR&gt;
A challenge password []:vj150&lt;BR&gt;Error adding attribute&lt;BR&gt;3556:error:0D0BF041:asn1 encoding routines:ASN1_item_dup:malloc failure:.\crypto&lt;BR&gt;\asn1\a_dup.c:104: problems making Certificate Request&lt;BR&gt;
C:\Program Files\Apache Software Foundation\Apache2.2\bin&amp;gt;&lt;BR&gt;&lt;br /&gt;&lt;hr /&gt;Want to do more with Windows Live? Learn “10 hidden secrets” from Jamie. &lt;a href='http://windowslive.com/connect/post/jamiethomson.spaces.live.com-Blog-cns!550F681DAD532637!5295.entry?ocid=TXT_TAGLM_WL_domore_092008' target='_new' rel=&quot;nofollow&quot;&gt;Learn Now&lt;/a&gt;&lt;/body&gt;
&lt;/html&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Some-help-with-ssl-tp19313097p19313097.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19264163</id>
	<title>RE: Error when trying shmcb SSLSessionCache on 64-bit Windows</title>
	<published>2008-09-01T22:03:10Z</published>
	<updated>2008-09-01T22:03:10Z</updated>
	<author>
		<name>Johan Hoogenboezem</name>
	</author>
	<content type="html">Hi Martin
&lt;br&gt;I tried the short (8.3) version of the directory with no luck. Ah well...
&lt;br&gt;Thanks
&lt;br&gt;Johan 
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19264163&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;owner-modssl-users@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19264163&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;owner-modssl-users@...&lt;/a&gt;]
&lt;br&gt;On Behalf Of Johan Hoogenboezem
&lt;br&gt;Sent: 01 September 2008 01:10 PM
&lt;br&gt;To: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19264163&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Cc: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19264163&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mdickau@...&lt;/a&gt;
&lt;br&gt;Subject: RE: Error when trying shmcb SSLSessionCache on 64-bit Windows
&lt;br&gt;&lt;br&gt;Hi Martin
&lt;br&gt;1) I'm still reluctant to use an unofficial build, but its good to know
&lt;br&gt;others are using it.
&lt;br&gt;2) Wow, well spotted with your &amp;quot;(x86)&amp;quot; theory! It also failed with a
&lt;br&gt;relative path: logs/ssl_scache(512000), but depending on how the relative
&lt;br&gt;path is being translated to an absolute path behind the scenes, you might
&lt;br&gt;still be right... I'll try it out as soon as I can and let you know.
&lt;br&gt;Thanks a lot
&lt;br&gt;Johan
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: Martin Dickau [mailto:&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19264163&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mdickau@...&lt;/a&gt;] 
&lt;br&gt;Sent: 01 September 2008 12:18 PM
&lt;br&gt;To: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19264163&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;hoogenbj@...&lt;/a&gt;
&lt;br&gt;Subject: Re: Error when trying shmcb SSLSessionCache on 64-bit Windows
&lt;br&gt;&lt;br&gt;I am using an unofficial 2.2.9 native on Windows Server 2003 64-bit 
&lt;br&gt;(AMD64/EM64T) from &lt;a href=&quot;http://www.blackdot.be/?inc=apache/binaries&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.blackdot.be/?inc=apache/binaries&lt;/a&gt;&amp;nbsp;and am using 
&lt;br&gt;shmcb without any trouble. &amp;nbsp;You do need to install the VC++ 2005 64-bit 
&lt;br&gt;redistributable runtime. &amp;nbsp;I am also using the mod_jk build from that site, 
&lt;br&gt;but I could not get the mod_log_rotate to run without crashing and had to 
&lt;br&gt;build that one myself.
&lt;br&gt;&lt;br&gt;That said, the &amp;quot;invalid size&amp;quot; error and the fact that size is passed in 
&lt;br&gt;parentheses as &amp;quot;(512000)&amp;quot; makes me wonder if it is reading the &amp;quot;(x86)&amp;quot; from 
&lt;br&gt;the path as the size. &amp;nbsp;Have you tried using C:/PROGRA~1/ (or PROGRA~2 -- &amp;nbsp;
&lt;br&gt;whichever it is on your system) instead?
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;&lt;br&gt;Martin
&lt;br&gt;&lt;br&gt;______________________________________________________________________
&lt;br&gt;Apache Interface to OpenSSL (mod_ssl) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; www.modssl.org
&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19264163&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19264163&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;No virus found in this incoming message.
&lt;br&gt;Checked by AVG - &lt;a href=&quot;http://www.avg.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.avg.com&lt;/a&gt;&amp;nbsp;
&lt;br&gt;Version: 8.0.169 / Virus Database: 270.6.14/1644 - Release Date: 8/31/2008
&lt;br&gt;4:59 PM
&lt;br&gt;&lt;br&gt;______________________________________________________________________
&lt;br&gt;Apache Interface to OpenSSL (mod_ssl) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; www.modssl.org
&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19264163&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19264163&amp;i=9&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Error-when-trying-shmcb-SSLSessionCache-on-64-bit-Windows-tp19251739p19264163.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19252890</id>
	<title>RE: Error when trying shmcb SSLSessionCache on 64-bit Windows</title>
	<published>2008-09-01T04:09:58Z</published>
	<updated>2008-09-01T04:09:58Z</updated>
	<author>
		<name>Johan Hoogenboezem</name>
	</author>
	<content type="html">Hi Martin
&lt;br&gt;1) I'm still reluctant to use an unofficial build, but its good to know
&lt;br&gt;others are using it.
&lt;br&gt;2) Wow, well spotted with your &amp;quot;(x86)&amp;quot; theory! It also failed with a
&lt;br&gt;relative path: logs/ssl_scache(512000), but depending on how the relative
&lt;br&gt;path is being translated to an absolute path behind the scenes, you might
&lt;br&gt;still be right... I'll try it out as soon as I can and let you know.
&lt;br&gt;Thanks a lot
&lt;br&gt;Johan
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: Martin Dickau [mailto:&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19252890&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mdickau@...&lt;/a&gt;] 
&lt;br&gt;Sent: 01 September 2008 12:18 PM
&lt;br&gt;To: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19252890&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;hoogenbj@...&lt;/a&gt;
&lt;br&gt;Subject: Re: Error when trying shmcb SSLSessionCache on 64-bit Windows
&lt;br&gt;&lt;br&gt;I am using an unofficial 2.2.9 native on Windows Server 2003 64-bit 
&lt;br&gt;(AMD64/EM64T) from &lt;a href=&quot;http://www.blackdot.be/?inc=apache/binaries&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.blackdot.be/?inc=apache/binaries&lt;/a&gt;&amp;nbsp;and am using 
&lt;br&gt;shmcb without any trouble. &amp;nbsp;You do need to install the VC++ 2005 64-bit 
&lt;br&gt;redistributable runtime. &amp;nbsp;I am also using the mod_jk build from that site, 
&lt;br&gt;but I could not get the mod_log_rotate to run without crashing and had to 
&lt;br&gt;build that one myself.
&lt;br&gt;&lt;br&gt;That said, the &amp;quot;invalid size&amp;quot; error and the fact that size is passed in 
&lt;br&gt;parentheses as &amp;quot;(512000)&amp;quot; makes me wonder if it is reading the &amp;quot;(x86)&amp;quot; from 
&lt;br&gt;the path as the size. &amp;nbsp;Have you tried using C:/PROGRA~1/ (or PROGRA~2 -- &amp;nbsp;
&lt;br&gt;whichever it is on your system) instead?
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;&lt;br&gt;Martin
&lt;br&gt;&lt;br&gt;______________________________________________________________________
&lt;br&gt;Apache Interface to OpenSSL (mod_ssl) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; www.modssl.org
&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19252890&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19252890&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Error-when-trying-shmcb-SSLSessionCache-on-64-bit-Windows-tp19251739p19252890.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19251739</id>
	<title>Error when trying shmcb SSLSessionCache on 64-bit Windows</title>
	<published>2008-09-01T02:41:48Z</published>
	<updated>2008-09-01T02:41:48Z</updated>
	<author>
		<name>Johan Hoogenboezem</name>
	</author>
	<content type="html">Hi All
&lt;br&gt;I'm running Apache 2.2.9 on Windows Server 2003 (64-bit version) in a
&lt;br&gt;production environment with mod_ssl configured. The only type of
&lt;br&gt;SSLSessionCache I am able to use is dbm. If I try the memory-based cache
&lt;br&gt;(shmcb, shmht or just shm), I get this error:
&lt;br&gt;&lt;br&gt;Syntax error on line 62 of C:/Program Files (x86)/Apache Software
&lt;br&gt;Foundation/Apache2.2/conf/extra/httpd-ssl.conf:
&lt;br&gt;SSLSessionCache: Invalid argument: size has to be &amp;gt;= 8192 bytes
&lt;br&gt;&lt;br&gt;Their is nothing wrong with the way the argument is set. This is what the
&lt;br&gt;line looks like:
&lt;br&gt;&lt;br&gt;SSLSessionCache &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;quot;shmcb:C:/Program Files (x86)/Apache Software
&lt;br&gt;Foundation/Apache2.2/logs/ssl_scache(512000)&amp;quot;
&lt;br&gt;&lt;br&gt;I tried different argument values to no avail.
&lt;br&gt;&lt;br&gt;I realize their is no official version of httpd for 64-bit Windows. I found
&lt;br&gt;an unofficial one, but that one doesn't work at all. It appears to have
&lt;br&gt;other issues. Besides, I'd rather use a production-ready, offical version
&lt;br&gt;even if it is 32-bit. 
&lt;br&gt;&lt;br&gt;Any comments will be greatly appreciated
&lt;br&gt;&lt;br&gt;Regards
&lt;br&gt;&lt;br&gt;Johan Hoogenboezem
&lt;br&gt;&lt;br&gt;&lt;br&gt;______________________________________________________________________
&lt;br&gt;Apache Interface to OpenSSL (mod_ssl) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; www.modssl.org
&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19251739&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19251739&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Error-when-trying-shmcb-SSLSessionCache-on-64-bit-Windows-tp19251739p19251739.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19091462</id>
	<title>Re: Cannot load libssl.so into server: ld.so.1: httpd: fatal: relocation error:</title>
	<published>2008-08-21T06:29:45Z</published>
	<updated>2008-08-21T06:29:45Z</updated>
	<author>
		<name>Xian Xian</name>
	</author>
	<content type="html">&lt;div dir=&quot;ltr&quot;&gt;You did not configure your Apache with mod_ssl when you set it up. You need to rebuild your Apache.&lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Thu, Aug 21, 2008 at 1:02 AM, Linda Lee &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19091462&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;n2kcn29@...&lt;/a&gt;&amp;gt;&lt;/span&gt; wrote:&lt;br&gt;
&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;&lt;div&gt;&lt;div style=&quot;font-family: times new roman,new york,times,serif; font-size: 12pt;&quot;&gt;&lt;div&gt;
&lt;div&gt;Hi all&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;*I am using apache &lt;span style=&quot;border-bottom: 1px dashed rgb(0, 102, 204);&quot;&gt;1.3.41&lt;/span&gt; with mod_ssl &lt;span style=&quot;border-bottom: 1px dashed rgb(0, 102, 204);&quot;&gt;2.8.31&lt;/span&gt;.&amp;nbsp; I kept getting the below error:&lt;/div&gt;

&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;Starting httpd: httpd &lt;span style=&quot;border-bottom: 1px dashed rgb(0, 102, 204);&quot;&gt;Syntax error&lt;/span&gt; on line 249 of /export/home/httpd/conf/httpd.conf:&lt;br&gt;Cannot load /export/home/httpd/libexec/libssl.so into server: &lt;a href=&quot;http://ld.so/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;&lt;span&gt;&lt;font color=&quot;#0000ff&quot;&gt;ld.so&lt;/font&gt;&lt;/span&gt;&lt;/a&gt;.1: httpd: fatal: relocation error: file /export/home/httpd/libexec/libssl.so: symbol inflateEnd: referenced symbol not found&lt;br&gt;
FAILED&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;*In my httpd.conf, line 249 is:&amp;nbsp; &lt;/div&gt;
&lt;div&gt;LoadModule ssl_module&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; libexec/libssl.so&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;*libssl.so&amp;#39;s loation is correct.&amp;nbsp; It is&amp;nbsp;in /export/home/httpd/libexec/.&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;Thanks for your help&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;br&gt;

      &lt;/div&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;/div&gt;
&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Cannot-load-libssl.so-into-server%3A-ld.so.1%3A-httpd%3A-fatal%3A-relocation-error%3A-tp19082488p19091462.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19082488</id>
	<title>Cannot load libssl.so into server: ld.so.1: httpd: fatal: relocation error:</title>
	<published>2008-08-20T22:02:52Z</published>
	<updated>2008-08-20T22:02:52Z</updated>
	<author>
		<name>Linda Lee-3</name>
	</author>
	<content type="html">&lt;html&gt;&lt;head&gt;&lt;/head&gt;&lt;body&gt;&lt;div style=&quot;font-family:times new roman, new york, times, serif;font-size:12pt&quot;&gt;&lt;DIV&gt;
&lt;DIV&gt;Hi all&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;*I am using apache &lt;SPAN class=yshortcuts id=lw_1219294819_0 style=&quot;CURSOR: hand; BORDER-BOTTOM: #0066cc 1px dashed&quot;&gt;1.3.41&lt;/SPAN&gt; with mod_ssl &lt;SPAN class=yshortcuts id=lw_1219294819_1 style=&quot;CURSOR: hand; BORDER-BOTTOM: #0066cc 1px dashed&quot;&gt;2.8.31&lt;/SPAN&gt;.&amp;nbsp; I kept getting the below error:&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Starting httpd: httpd &lt;SPAN class=yshortcuts id=lw_1219294819_2 style=&quot;CURSOR: hand; BORDER-BOTTOM: #0066cc 1px dashed&quot;&gt;Syntax error&lt;/SPAN&gt; on line 249 of /export/home/httpd/conf/httpd.conf:&lt;BR&gt;Cannot load /export/home/httpd/libexec/libssl.so into server: &lt;A href=&quot;http://ld.so/&quot; target=_blank rel=&quot;nofollow&quot;&gt;&lt;SPAN class=yshortcuts id=lw_1219294819_3&gt;&lt;FONT color=#0000ff&gt;ld.so&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;.1: httpd: fatal: relocation error: file /export/home/httpd/libexec/libssl.so: symbol inflateEnd: referenced symbol not found&lt;BR&gt;FAILED&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;*In my httpd.conf, line 249 is:&amp;nbsp; &lt;/DIV&gt;
&lt;DIV&gt;LoadModule ssl_module&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; libexec/libssl.so&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;*libssl.so's loation is correct.&amp;nbsp; It is&amp;nbsp;in /export/home/httpd/libexec/.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Thanks for your help&lt;/DIV&gt;&lt;/DIV&gt;&lt;/div&gt;&lt;br&gt;

      &lt;/body&gt;&lt;/html&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Cannot-load-libssl.so-into-server%3A-ld.so.1%3A-httpd%3A-fatal%3A-relocation-error%3A-tp19082488p19082488.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-19082458</id>
	<title>Cannot load /export/home/httpd/libexec/libssl.so into server: ld.so.1:</title>
	<published>2008-08-20T21:57:31Z</published>
	<updated>2008-08-20T21:57:31Z</updated>
	<author>
		<name>Linda Lee-3</name>
	</author>
	<content type="html">MIME-Version: 1.0
&lt;br&gt;Content-Type: multipart/alternative; boundary=&amp;quot;0-1715676727-1219294651=:94206&amp;quot;
&lt;br&gt;&lt;br&gt;--0-1715676727-1219294651=:94206
&lt;br&gt;Content-Type: text/plain; charset=iso-8859-1
&lt;br&gt;Content-Transfer-Encoding: quoted-printable
&lt;br&gt;&lt;br&gt;=0A=0A=0A=0AHi all=0A=A0=0A*I am using apache 1.3.41 with mod_ssl 2.8.31.=
&lt;br&gt;=A0 I kept getting the below error:=0A=A0=0AStarting httpd: httpd Syntax er=
&lt;br&gt;ror on line 249 of /export/home/httpd/conf/httpd.conf:=0ACannot load /expor=
&lt;br&gt;t/home/httpd/libexec/libssl.so into server: ld.so.1: httpd: fatal: relocati=
&lt;br&gt;on error: file /export/home/httpd/libexec/libssl.so: symbol inflateEnd: ref=
&lt;br&gt;erenced symbol not found=0AFAILED=0A=A0=0A*In my httpd.conf, line 249 is:=
&lt;br&gt;=A0 =0ALoadModule ssl_module=A0=A0=A0=A0=A0=A0=A0=A0 libexec/libssl.so=0A=
&lt;br&gt;=A0=0A*libssl.so's loation is correct.=A0 It is=A0in /export/home/httpd/lib=
&lt;br&gt;exec/.=0A=A0=0AThanks for your help=0A=0A=0A &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;--0-1715676727-1219294651=:94206
&lt;br&gt;Content-Type: text/html; charset=us-ascii
&lt;br&gt;&lt;br&gt;&amp;lt;html&amp;gt;&amp;lt;head&amp;gt;&amp;lt;style type=&amp;quot;text/css&amp;quot;&amp;gt;&amp;lt;!-- DIV {margin:0px;} --&amp;gt;&amp;lt;/style&amp;gt;&amp;lt;/head&amp;gt;&amp;lt;body&amp;gt;&amp;lt;div style=&amp;quot;font-family:times new roman, new york, times, serif;font-size:12pt&amp;quot;&amp;gt;&amp;lt;DIV&amp;gt;&amp;lt;BR&amp;gt;&amp;lt;/DIV&amp;gt;
&lt;br&gt;&amp;lt;DIV style=&amp;quot;FONT-SIZE: 12pt; FONT-FAMILY: times new roman, new york, times, serif&amp;quot;&amp;gt;&amp;lt;BR&amp;gt;
&lt;br&gt;&amp;lt;DIV style=&amp;quot;FONT-SIZE: 12pt; FONT-FAMILY: times new roman, new york, times, serif&amp;quot;&amp;gt;
&lt;br&gt;&amp;lt;DIV style=&amp;quot;FONT-SIZE: 12pt; FONT-FAMILY: times new roman, new york, times, serif&amp;quot;&amp;gt;
&lt;br&gt;&amp;lt;DIV&amp;gt;Hi all&amp;lt;/DIV&amp;gt;
&lt;br&gt;&amp;lt;DIV&amp;gt;&amp;nbsp;&amp;lt;/DIV&amp;gt;
&lt;br&gt;&amp;lt;DIV&amp;gt;*I am using apache 1.3.41 with mod_ssl 2.8.31.&amp;nbsp; I kept getting the below error:&amp;lt;/DIV&amp;gt;
&lt;br&gt;&amp;lt;DIV&amp;gt;&amp;nbsp;&amp;lt;/DIV&amp;gt;
&lt;br&gt;&amp;lt;DIV&amp;gt;Starting httpd: httpd Syntax error on line 249 of /export/home/httpd/conf/httpd.conf:&amp;lt;BR&amp;gt;Cannot load /export/home/httpd/libexec/libssl.so into server: &amp;lt;A href=&amp;quot;&lt;a href=&quot;http://ld.so/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://ld.so/&lt;/a&gt;&amp;quot; target=_blank&amp;gt;ld.so&amp;lt;/A&amp;gt;.1: httpd: fatal: relocation error: file /export/home/httpd/libexec/libssl.so: symbol inflateEnd: referenced symbol not found&amp;lt;BR&amp;gt;FAILED&amp;lt;/DIV&amp;gt;
&lt;br&gt;&amp;lt;DIV&amp;gt;&amp;nbsp;&amp;lt;/DIV&amp;gt;
&lt;br&gt;&amp;lt;DIV&amp;gt;*In my httpd.conf, line 249 is:&amp;nbsp; &amp;lt;/DIV&amp;gt;
&lt;br&gt;&amp;lt;DIV&amp;gt;LoadModule ssl_module&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; libexec/libssl.so&amp;lt;/DIV&amp;gt;
&lt;br&gt;&amp;lt;DIV&amp;gt;&amp;nbsp;&amp;lt;/DIV&amp;gt;
&lt;br&gt;&amp;lt;DIV&amp;gt;*libssl.so's loation is correct.&amp;nbsp; It is&amp;nbsp;in /export/home/httpd/libexec/.&amp;lt;/DIV&amp;gt;
&lt;br&gt;&amp;lt;DIV&amp;gt;&amp;nbsp;&amp;lt;/DIV&amp;gt;
&lt;br&gt;&amp;lt;DIV&amp;gt;Thanks for your help&amp;lt;/DIV&amp;gt;
&lt;br&gt;&amp;lt;DIV&amp;gt;&amp;nbsp;&amp;lt;/DIV&amp;gt;
&lt;br&gt;&amp;lt;DIV&amp;gt;&amp;lt;BR&amp;gt;&amp;lt;BR&amp;gt;&amp;nbsp;&amp;lt;/DIV&amp;gt;&amp;lt;/DIV&amp;gt;&amp;lt;BR&amp;gt;&amp;lt;/DIV&amp;gt;&amp;lt;/DIV&amp;gt;&amp;lt;/div&amp;gt;&amp;lt;br&amp;gt;
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;/body&amp;gt;&amp;lt;/html&amp;gt;
&lt;br&gt;--0-1715676727-1219294651=:94206--
&lt;br&gt;&lt;br&gt;______________________________________________________________________
&lt;br&gt;Apache Interface to OpenSSL (mod_ssl) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; www.modssl.org
&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19082458&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=19082458&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Cannot-load--export-home-httpd-libexec-libssl.so-into-server%3A-ld.so.1%3A-tp19082458p19082458.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18550285</id>
	<title>Fips compliant mod_ssl module availability</title>
	<published>2008-07-19T17:40:41Z</published>
	<updated>2008-07-19T17:40:41Z</updated>
	<author>
		<name>Sean Coleman</name>
	</author>
	<content type="html">I need to implement a FIPS 140 compliant version of mod_ssl. Is there a 
&lt;br&gt;patch file or a distribution of mod_ssl
&lt;br&gt;currently available for download which can be used in conjunction with 
&lt;br&gt;the fips compliant libopenssl?
&lt;br&gt;&lt;br&gt;I found a link to a patch file for modssl in a message sent earlier in 
&lt;br&gt;2008 but the link doesn't work. The link was
&lt;br&gt;found in this thread: 
&lt;br&gt;&lt;a href=&quot;http://www.mail-archive.com/openssl-users@openssl.org/msg52290.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.mail-archive.com/openssl-users@.../msg52290.html&lt;/a&gt;&amp;nbsp;The 
&lt;br&gt;actual link
&lt;br&gt;posted was 
&lt;br&gt;&lt;a href=&quot;http://mail-archives.apache.org/mod_mbox/httpd-bugs/200711.mbox/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://mail-archives.apache.org/mod_mbox/httpd-bugs/200711.mbox/&lt;/a&gt;[EMAIL 
&lt;br&gt;PROTECTED]/bugzilla/%3e
&lt;br&gt;&lt;br&gt;Has this patch been obsoleted?
&lt;br&gt;&lt;br&gt;I also found an entire distribution tree for a FIPS compliant httpd 
&lt;br&gt;server at
&lt;br&gt;&lt;a href=&quot;http://svn.apache.org/repos/asf/httpd/sandbox/gaithersburg&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://svn.apache.org/repos/asf/httpd/sandbox/gaithersburg&lt;/a&gt;. What is the 
&lt;br&gt;status of this code? Is this code
&lt;br&gt;available somewhere for download to be used to provide a FIPS compliant 
&lt;br&gt;mod_ssl module?
&lt;br&gt;&lt;br&gt;Thank you,
&lt;br&gt;&lt;br&gt;Sean Coleman
&lt;br&gt;&lt;br&gt;&lt;br&gt;______________________________________________________________________
&lt;br&gt;Apache Interface to OpenSSL (mod_ssl) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; www.modssl.org
&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18550285&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18550285&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Fips-compliant-mod_ssl-module-availability-tp18550285p18550285.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18540214</id>
	<title>stop sending me this stuff please !!!!!!!!!!!</title>
	<published>2008-07-18T18:17:06Z</published>
	<updated>2008-07-18T18:17:06Z</updated>
	<author>
		<name>erika20</name>
	</author>
	<content type="html">&lt;html&gt;
&lt;!-- BEGIN WEBMAIL STATIONERY --&gt;
&lt;head&gt;&lt;/head&gt;
&lt;body&gt;
&lt;!-- WEBMAIL STATIONERY noneset --&gt;
&lt;DIV&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT color=#ff0000 size=7&gt;stop sendig me this &lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT color=#ff0000 size=7&gt;stuff please !!!!&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT color=#ff0000 size=7&gt;take me out of your mailing list !!! thanks &lt;/FONT&gt;&lt;/DIV&gt;
&lt;BLOCKQUOTE style=&quot;PADDING-LEFT: 5px; MARGIN-LEFT: 5px; BORDER-LEFT: #1010ff 2px solid&quot;&gt;-------------- Original message from Frederic Heem &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18540214&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;frederic.heem@...&lt;/a&gt;&amp;gt;: -------------- &lt;BR&gt;&lt;BR&gt;&lt;div class='shrinkable-quote'&gt;&lt;BR&gt;&amp;gt; Hi, &lt;BR&gt;&amp;gt; Valgrind has found a problem related to an overlapping memcpy in mod_ssl &lt;BR&gt;&amp;gt; (Apache/2.2.9 (Unix)), here is the output: &lt;BR&gt;&amp;gt; &lt;BR&gt;&amp;gt; ==18546== Thread 5: &lt;BR&gt;&amp;gt; ==18546== Source and destination overlap in memcpy(0x425E0E8, 0x425E10E, &lt;BR&gt;&amp;gt; 141) &lt;BR&gt;&amp;gt; ==18546== at 0x4007A42: memcpy (mc_replace_strmem.c:402) &lt;BR&gt;&amp;gt; ==18546== by 0x446C464: ssl_io_input_read (in &lt;BR&gt;&amp;gt; /usr/local/apache2/modules/mod_ssl.so) &lt;BR&gt;&amp;gt; ==18546== by 0x446C781: ssl_io_filter_input (in &lt;BR&gt;&amp;gt; /usr/local/apache2/modules/mod_ssl.so) &lt;BR&gt;&amp;gt; ==18546== by 0x8068DB5: ap_rgetline_core (in &lt;BR&gt;&amp;gt; /usr/local/apache2/bin/httpd) &lt;BR&gt;&amp;gt; ==18546== by 0x80690CE: ap_get_mime_headers_core (in &lt;BR&gt;&amp;gt; /usr/local/apache2/bin/httpd) &lt;BR&gt;&amp;gt; ==18546== by 0x80696FC: ap_read_request (in /usr/local/apache2/bin/httpd) &lt;BR&gt;&amp;gt; ==18546== by 0x80799DA: ap_process_http_connection (in &lt;BR&gt;&amp;gt; /usr/local/apache2/bin/httpd) &lt;BR&gt;&amp;gt; ==18546== by 0x8076CEC: ap_run_process_connection (in &lt;BR&gt;&amp;gt; /usr/local/apache2/bin/httpd) &lt;BR&gt;&amp;gt; ==18546== by 0x807FFD3: worker_thread (in /usr/local/apache2/bin/httpd) &lt;BR&gt;&amp;gt; ==18546== by 0x4057603: dummy_worker (in &lt;BR&gt;&amp;gt; /usr/local/apache2/lib/libapr-1.so.0.3.0) &lt;BR&gt;&amp;gt; ==18546== by 0x8E145A: start_thread (in /lib/libpthread-2.5.so) &lt;BR&gt;&amp;gt; ==18546== by 0x71323D: clone (in /lib/libc-2.5.so) &lt;BR&gt;&amp;gt; &lt;BR&gt;&amp;gt; This happens when an axis2 client sends a https request. &lt;BR&gt;&amp;gt; Let me know if you need more information. &lt;BR&gt;&amp;gt; Frederic Heem &lt;BR&gt;&amp;gt; &lt;BR&gt;&amp;gt; &lt;BR&gt;&amp;gt; &lt;BR&gt;&amp;gt; ______________________________________________________________________________ &lt;BR&gt;&amp;gt; &lt;BR&gt;&amp;gt; --- NOTICE --- &lt;BR&gt;&amp;gt; &lt;BR&gt;&amp;gt; This email and any attachments are confidential and are intended for the &lt;BR&gt;&amp;gt; addressee only. If you have received this message by mistake, please contact &lt;BR&gt;&amp;gt; us immediately and then delete the message from your system. You must not &lt;BR&gt;&amp;gt; copy, distribute, disclose or act upon the contents of this email. Personal &lt;BR&gt;&amp;gt; and corporate data submitted will be used in a correct, transparent and lawful &lt;BR&gt;&amp;gt; manner. The data collected will be processed in paper or computerized form for &lt;BR&gt;&amp;gt; the performance of contractual and lawful obligations as well as for the &lt;BR&gt;&amp;gt; effective management of business relationship. The data processor is Telsey &lt;BR&gt;&amp;gt; S.p.A. The data subject may exercise all the rights set forth in art. 7 of &lt;BR&gt;&amp;gt; Law by Decree 30.06.2003 n. 196 as reported in the following url &lt;BR&gt;&amp;gt; http://www.telsey.com/privacy.asp. &lt;BR&gt;&amp;gt; &lt;BR&gt;&amp;gt; ______________________________________________________________________________ &lt;BR&gt;&amp;gt; 798t8RfNa6Dl8Ilf &lt;BR&gt;&amp;gt; ______________________________________________________________________ &lt;BR&gt;&amp;gt; Apache Interface to OpenSSL (mod_ssl) www.modssl.org &lt;BR&gt;&amp;gt; User Support Mailing List &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18540214&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt; &lt;BR&gt;&amp;gt; Automated List Manager &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18540214&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt; &lt;/BLOCKQUOTE&gt;
&lt;!-- END WEBMAIL STATIONERY --&gt;

&lt;/body&gt;
&lt;/html&gt;
&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/overlapping-memcpy-tp18533749p18540214.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18533749</id>
	<title>overlapping memcpy</title>
	<published>2008-07-18T10:05:04Z</published>
	<updated>2008-07-18T10:05:04Z</updated>
	<author>
		<name>frederic heem</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;Valgrind has found a problem related to an overlapping memcpy in mod_ssl 
&lt;br&gt;(Apache/2.2.9 (Unix)), here is the output:
&lt;br&gt;&lt;br&gt;==18546== Thread 5:
&lt;br&gt;==18546== Source and destination overlap in memcpy(0x425E0E8, 0x425E10E, 
&lt;br&gt;141)
&lt;br&gt;==18546== &amp;nbsp; &amp;nbsp;at 0x4007A42: memcpy (mc_replace_strmem.c:402)
&lt;br&gt;==18546== &amp;nbsp; &amp;nbsp;by 0x446C464: ssl_io_input_read (in 
&lt;br&gt;/usr/local/apache2/modules/mod_ssl.so)
&lt;br&gt;==18546== &amp;nbsp; &amp;nbsp;by 0x446C781: ssl_io_filter_input (in 
&lt;br&gt;/usr/local/apache2/modules/mod_ssl.so)
&lt;br&gt;==18546== &amp;nbsp; &amp;nbsp;by 0x8068DB5: ap_rgetline_core (in 
&lt;br&gt;/usr/local/apache2/bin/httpd)
&lt;br&gt;==18546== &amp;nbsp; &amp;nbsp;by 0x80690CE: ap_get_mime_headers_core (in 
&lt;br&gt;/usr/local/apache2/bin/httpd)
&lt;br&gt;==18546== &amp;nbsp; &amp;nbsp;by 0x80696FC: ap_read_request (in /usr/local/apache2/bin/httpd)
&lt;br&gt;==18546== &amp;nbsp; &amp;nbsp;by 0x80799DA: ap_process_http_connection (in 
&lt;br&gt;/usr/local/apache2/bin/httpd)
&lt;br&gt;==18546== &amp;nbsp; &amp;nbsp;by 0x8076CEC: ap_run_process_connection (in 
&lt;br&gt;/usr/local/apache2/bin/httpd)
&lt;br&gt;==18546== &amp;nbsp; &amp;nbsp;by 0x807FFD3: worker_thread (in /usr/local/apache2/bin/httpd)
&lt;br&gt;==18546== &amp;nbsp; &amp;nbsp;by 0x4057603: dummy_worker (in 
&lt;br&gt;/usr/local/apache2/lib/libapr-1.so.0.3.0)
&lt;br&gt;==18546== &amp;nbsp; &amp;nbsp;by 0x8E145A: start_thread (in /lib/libpthread-2.5.so)
&lt;br&gt;==18546== &amp;nbsp; &amp;nbsp;by 0x71323D: clone (in /lib/libc-2.5.so)
&lt;br&gt;&lt;br&gt;This happens when an axis2 client sends a https request.
&lt;br&gt;Let me know if you need more information.
&lt;br&gt;Frederic Heem
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;______________________________________________________________________________
&lt;br&gt;&lt;br&gt;--- NOTICE ---
&lt;br&gt;&lt;br&gt;This &amp;nbsp;email &amp;nbsp;and &amp;nbsp;any &amp;nbsp;attachments &amp;nbsp;are &amp;nbsp;confidential and are intended for the
&lt;br&gt;addressee &amp;nbsp;only. &amp;nbsp;If you have received this message by mistake, please contact
&lt;br&gt;us &amp;nbsp;immediately and &amp;nbsp;then &amp;nbsp;delete the message from your system. &amp;nbsp; You must not
&lt;br&gt;copy, distribute, disclose &amp;nbsp;or &amp;nbsp;act upon the contents of this email. &amp;nbsp;Personal
&lt;br&gt;and corporate data submitted will be used in a correct, transparent and lawful
&lt;br&gt;manner. The data collected will be processed in paper or computerized form for
&lt;br&gt;the &amp;nbsp;performance &amp;nbsp;of &amp;nbsp;contractual &amp;nbsp;and &amp;nbsp;lawful &amp;nbsp;obligations as well as for the
&lt;br&gt;effective &amp;nbsp;management of business relationship. &amp;nbsp; The data processor is Telsey
&lt;br&gt;S.p.A. &amp;nbsp; The &amp;nbsp;data &amp;nbsp;subject may exercise all the rights set forth in art. 7 of
&lt;br&gt;Law &amp;nbsp;by &amp;nbsp;Decree &amp;nbsp;30.06.2003 &amp;nbsp;n. &amp;nbsp;196 &amp;nbsp; as &amp;nbsp; reported &amp;nbsp; in &amp;nbsp;the &amp;nbsp;following &amp;nbsp;url
&lt;br&gt;&lt;a href=&quot;http://www.telsey.com/privacy.asp&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.telsey.com/privacy.asp&lt;/a&gt;.
&lt;br&gt;&lt;br&gt;______________________________________________________________________________
&lt;br&gt;798t8RfNa6Dl8Ilf
&lt;br&gt;______________________________________________________________________
&lt;br&gt;Apache Interface to OpenSSL (mod_ssl) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; www.modssl.org
&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18533749&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18533749&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/overlapping-memcpy-tp18533749p18533749.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18517881</id>
	<title>Re: redirect port</title>
	<published>2008-07-17T14:03:25Z</published>
	<updated>2008-07-17T14:03:25Z</updated>
	<author>
		<name>Tim Hester</name>
	</author>
	<content type="html">A few more hours of investigation revealed the solution;
&lt;br&gt;&lt;br&gt;&amp;nbsp;RewriteCond %{HTTP_HOST} &amp;nbsp; ^www.mydomain.com:8080 [NC]
&lt;br&gt;&amp;nbsp;RewriteRule ^/(.*) &lt;a href=&quot;https://www.mydomain.com/$1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.mydomain.com/$1&lt;/a&gt;&amp;nbsp;[L,R=301]
&lt;br&gt;&lt;br&gt;Sorry bout the html mail earlier.
&lt;br&gt;&lt;br&gt;Tim
&lt;br&gt;&lt;br&gt;----- Original Message ----- 
&lt;br&gt;From: Tim Hester
&lt;br&gt;To: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18517881&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Sent: Thursday, July 17, 2008 10:38 AM
&lt;br&gt;Subject: redirect port
&lt;br&gt;&lt;br&gt;&lt;br&gt;I have been using Apache/2.2.3 and Tomcat 5.5 as standalone servers. I'm
&lt;br&gt;adding ssl with mod_jk and mod_proxy_ajp to access tomcat via ssl.
&lt;br&gt;&lt;br&gt;I access my static content and cgi via &lt;a href=&quot;http://www.mydomain.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.mydomain.com/&lt;/a&gt;&amp;nbsp;and use
&lt;br&gt;mod_rewrite in .htaccess to redirect to https. This works fine as desired.
&lt;br&gt;&lt;br&gt;I can access my webapp via &lt;a href=&quot;http://www.mydomain.com:8080/MyWebApp&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.mydomain.com:8080/MyWebApp&lt;/a&gt;, and this
&lt;br&gt;is the url users have book marked. This continues to work. I can also access
&lt;br&gt;&lt;a href=&quot;https://www.mydomain.com/MyWebApp&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.mydomain.com/MyWebApp&lt;/a&gt;.
&lt;br&gt;&lt;br&gt;What I'd like to do is force a redirect from
&lt;br&gt;&lt;a href=&quot;http://www.mydomain.com:8080/MyWebApp&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.mydomain.com:8080/MyWebApp&lt;/a&gt;&amp;nbsp;to &lt;a href=&quot;https://www.mydomain.com/MyWebApp&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.mydomain.com/MyWebApp&lt;/a&gt;&lt;br&gt;&lt;br&gt;Note; tomcat is not under the apache webroot
&lt;br&gt;&lt;br&gt;Any assistance appreciated.
&lt;br&gt;&lt;br&gt;Thanks
&lt;br&gt;&lt;br&gt;Tim 
&lt;br&gt;&lt;br&gt;______________________________________________________________________
&lt;br&gt;Apache Interface to OpenSSL (mod_ssl) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; www.modssl.org
&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18517881&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18517881&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/redirect-port-tp18511440p18517881.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18511440</id>
	<title>redirect port</title>
	<published>2008-07-17T08:38:11Z</published>
	<updated>2008-07-17T08:38:11Z</updated>
	<author>
		<name>Tim Hester</name>
	</author>
	<content type="html">&lt;!DOCTYPE HTML PUBLIC &quot;-//W3C//DTD HTML 4.0 Transitional//EN&quot;&gt;
&lt;HTML&gt;&lt;HEAD&gt;
&lt;META http-equiv=Content-Type content=&quot;text/html; charset=windows-1252&quot;&gt;
&lt;META content=&quot;MSHTML 6.00.2900.3354&quot; name=GENERATOR&gt;

&lt;/HEAD&gt;
&lt;BODY bgColor=#ffffff&gt;
&lt;DIV&gt;I have been using Apache/2.2.3 and Tomcat 5.5 as standalone servers. I'm 
&lt;BR&gt;adding ssl with mod_jk and mod_proxy_ajp to access tomcat via ssl.&lt;BR&gt;&lt;BR&gt;I 
access my static content and cgi via &lt;A href=&quot;&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.mydomain.com/&lt;/A&gt; and 
use &lt;BR&gt;mod_rewrite in .htaccess to redirect to https. This works fine as 
desired.&lt;BR&gt;&lt;BR&gt;I can access my webapp via &lt;A href=&quot;&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.mydomain.com:8080/MyWebApp&lt;/A&gt;, and this &lt;BR&gt;is the url users 
have book marked. This continues to work. I can also access &lt;BR&gt;&lt;A href=&quot;&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.mydomain.com/MyWebApp&lt;/A&gt;.&lt;BR&gt;&lt;BR&gt;What I'd like to do is 
force a redirect from &lt;BR&gt;&lt;A href=&quot;&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.mydomain.com:8080/MyWebApp&lt;/A&gt; 
to &lt;A href=&quot;&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.mydomain.com/MyWebApp&lt;/A&gt;&lt;BR&gt;&lt;BR&gt;Note; tomcat is not 
under the apache webroot&lt;BR&gt;&lt;BR&gt;Any assistance 
appreciated.&lt;BR&gt;&lt;BR&gt;Thanks&lt;BR&gt;&lt;BR&gt;Tim&lt;BR&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;
&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/redirect-port-tp18511440p18511440.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18452185</id>
	<title>Re: wrong e-mail !!!!!!!!!!!!!!!!!!!!!!!</title>
	<published>2008-07-14T13:13:22Z</published>
	<updated>2008-07-14T13:13:22Z</updated>
	<author>
		<name>Robert Uzgalis</name>
	</author>
	<content type="html">&lt;!DOCTYPE html PUBLIC &quot;-//W3C//DTD HTML 4.01 Transitional//EN&quot;&gt;
&lt;html&gt;
&lt;head&gt;
  &lt;meta content=&quot;text/html;charset=UTF-8&quot; http-equiv=&quot;Content-Type&quot;&gt;
  &lt;title&gt;&lt;/title&gt;
&lt;/head&gt;
&lt;body bgcolor=&quot;#ffffff&quot; text=&quot;#000000&quot;&gt;
One small comment.  I have tried for years to get off this mailing list.&lt;br&gt;
I have sent my request and it has always been effective, for say a
month or so,&lt;br&gt;
then I get put back on the mailing list.  And it keeps coming.  My
solution was&lt;br&gt;
to add it to my spam filter.  It doesn't bother me that way and
occasionally I drop in&lt;br&gt;
to see what the latest complaint is.&lt;br&gt;
&lt;br&gt;
In this case I couldn't agree with the message more.  Perhaps the tone
is not quite right.&lt;br&gt;
Somebody ought to fix mailing-list software so that once you are off
you are really gone.&lt;br&gt;
It is true that &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18452185&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;erika20@...&lt;/a&gt; ought to ask to be taken off the
list; but it won't help much I'm afraid.&lt;br&gt;
&lt;br&gt;
BUZ&lt;br&gt;
&lt;br&gt;
&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18452185&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;erika20@...&lt;/a&gt; wrote:
&lt;blockquote cite=&quot;mid:071420081810.22034.487B9684000ACF8F0000561222218675169B0A02D2089B9A019C04040A0DBFCFCD0E05079D0A@att.net&quot; type=&quot;cite&quot;&gt;&lt;!-- BEGIN WEBMAIL STATIONERY --&gt;
&lt;!-- WEBMAIL STATIONERY noneset --&gt;
  &lt;div&gt;&lt;font size=&quot;7&quot;&gt;stop &lt;/font&gt;&lt;font color=&quot;#cc0000&quot;&gt;&lt;font size=&quot;7&quot;&gt;stop&lt;/font&gt; 
  &lt;font size=&quot;7&quot;&gt;sending me &lt;/font&gt;&lt;/font&gt;&lt;/div&gt;
  &lt;div&gt;&lt;font color=&quot;#cc0000&quot; size=&quot;7&quot;&gt;this bs , i have no idea  who are
you !!!!&lt;/font&gt;&lt;/div&gt;
  &lt;div&gt;&lt;font color=&quot;#cc0000&quot; size=&quot;7&quot;&gt;stop !!!!!!!!!!!!!!!&lt;/font&gt;&lt;/div&gt;
  &lt;blockquote style=&quot;border-left: 2px solid rgb(16, 16, 255); padding-left: 5px; margin-left: 5px;&quot;&gt;--------------
Original message from Dave Paris &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18452185&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;dparis@...&lt;/a&gt;:
-------------- &lt;br&gt;
    &lt;br&gt;
    &lt;br&gt;
&amp;gt; It seem like you might be confusing &quot;shared infrastructure&quot; with &lt;br&gt;
&amp;gt; &quot;single ip&quot;. As others have said, you need a distinct address for
each &lt;br&gt;
&amp;gt; SSL-enabled httpd or proxy, although they can reside on the same
hardware. &lt;br&gt;
&amp;gt; &lt;br&gt;
&amp;gt; A good example of this is the typical configuration for larger
server &lt;br&gt;
&amp;gt; farms. You find multiple High Availability load balancers in the
DMZ for &lt;br&gt;
&amp;gt; both http and https using something like ha/keepalived for linux.
These &lt;br&gt;
&amp;gt; proxy the incoming request back into private address space. The
SSL &lt;br&gt;
&amp;gt; proxies terminate the SSL connection and broker the request on
behalf of &lt;br&gt;
&amp;gt; the user and everything goes to the private address space in plain
http. &lt;br&gt;
&amp;gt; This allows each of the _real_ webservers to achieve better &lt;br&gt;
&amp;gt; performance since the SSL overhead is not present. &lt;br&gt;
&amp;gt; &lt;br&gt;
&amp;gt; While you can use Apache as an SSL-terminating proxy, I find I get
    &lt;br&gt;
&amp;gt; better performance, lower memory utilization and easier
configuration &lt;br&gt;
&amp;gt; using Pound ( &lt;a class=&quot;moz-txt-link-freetext&quot; href=&quot;http://www.apsis.ch/pound/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.apsis.ch/pound/&lt;/a&gt; ). Using keepalived, I
have &lt;br&gt;
&amp;gt; multiple public IP addresses floating between several hosts and
pound &lt;br&gt;
&amp;gt; binds https to those addresses. &lt;br&gt;
&amp;gt; &lt;br&gt;
&amp;gt; Hope that adds a bit of additional clarity, &lt;br&gt;
&amp;gt; Dave &lt;br&gt;
&amp;gt; &lt;br&gt;
&amp;gt; Cuesta Gilles sent forth: &lt;br&gt;
&amp;gt; &amp;gt; So what about this ? &lt;br&gt;
&amp;gt; &amp;gt; &quot;*MULTIPLE CN (SAN) SERVER CERTIFICATES* &lt;br&gt;
&amp;gt; &amp;gt; &lt;br&gt;
&amp;gt; &amp;gt; This type of certificate (also called /Subject Alternative
Name/ (SAN) ) &lt;br&gt;
&amp;gt; &amp;gt; enables to secure not only one website but a large number of
sites (a &lt;br&gt;
&amp;gt; &amp;gt; list of sites) hosted on a shared infrastructure (server with
multiple &lt;br&gt;
&amp;gt; &amp;gt; names, reverse proxy). Ideal to secure multiple brands of a
corporation. &lt;br&gt;
&amp;gt; &amp;gt; One certificate per hardware is required.&quot; &lt;br&gt;
&amp;gt; &amp;gt; &lt;br&gt;
&amp;gt; &amp;gt; &lt;a class=&quot;moz-txt-link-freetext&quot; href=&quot;http://www.tbs-certificats.com/index.html.en&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.tbs-certificats.com/index.html.en&lt;/a&gt; &lt;br&gt;
&amp;gt; &amp;gt; &lt;br&gt;
&amp;gt;
______________________________________________________________________ &lt;br&gt;
&amp;gt; Apache Interface to OpenSSL (mod_ssl) &lt;a class=&quot;moz-txt-link-abbreviated&quot; href=&quot;http://www.modssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;www.modssl.org&lt;/a&gt; &lt;br&gt;
&amp;gt; User Support Mailing List &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18452185&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt; &lt;br&gt;
&amp;gt; Automated List Manager &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18452185&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt; &lt;/blockquote&gt;
&lt;!-- END WEBMAIL STATIONERY --&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;/body&gt;
&lt;/html&gt;
&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/SSL-proxy-tp18391124p18452185.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18451226</id>
	<title>Re: wrong e-mail !!!!!!!!!!!!!!!!!!!!!!!</title>
	<published>2008-07-14T12:24:46Z</published>
	<updated>2008-07-14T12:24:46Z</updated>
	<author>
		<name>erika20</name>
	</author>
	<content type="html">&lt;html&gt;
&lt;!-- BEGIN WEBMAIL STATIONERY --&gt;
&lt;head&gt;&lt;/head&gt;
&lt;body&gt;
&lt;!-- WEBMAIL STATIONERY noneset --&gt;
&lt;DIV&gt;&lt;/DIV&gt;
&lt;DIV&gt;THANK'S &lt;/DIV&gt;
&lt;BLOCKQUOTE style=&quot;PADDING-LEFT: 5px; MARGIN-LEFT: 5px; BORDER-LEFT: #1010ff 2px solid&quot;&gt;-------------- Original message from &quot;Shahadat Hossain&quot; &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18451226&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;shahadat9612@...&lt;/a&gt;&amp;gt;: -------------- &lt;BR&gt;&lt;BR&gt;
&lt;DIV&gt;you know what, You are a f***en idiot.&lt;/DIV&gt;
&lt;DIV&gt;if you do not want to receive these emails, just get your name taken off from the list instead of b-shitting. &lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;send an email to &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18451226&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt; address (you can also find it at the bottom of this message) with subject as 'Remove me'.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;ok?&lt;BR&gt;&lt;BR&gt;&lt;/DIV&gt;
&lt;DIV class=gmail_quote&gt;On Mon, Jul 14, 2008 at 7:10 PM, &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18451226&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;erika20@...&lt;/a&gt;&amp;gt; wrote:&lt;BR&gt;
&lt;BLOCKQUOTE class=gmail_quote style=&quot;PADDING-LEFT: 1ex; MARGIN: 0px 0px 0px 0.8ex; BORDER-LEFT: #ccc 1px solid&quot;&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT size=7&gt;stop &lt;/FONT&gt;&lt;FONT color=#cc0000&gt;&lt;FONT size=7&gt;stop&lt;/FONT&gt;&amp;nbsp; &lt;FONT size=7&gt;sending me &lt;/FONT&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT color=#cc0000 size=7&gt;this bs , i have no idea&amp;nbsp; who are you !!!!&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT color=#cc0000 size=7&gt;stop !!!!!!!!!!!!!!!&lt;/FONT&gt;&lt;/DIV&gt;
&lt;BLOCKQUOTE style=&quot;PADDING-LEFT: 5px; MARGIN-LEFT: 5px; BORDER-LEFT: #1010ff 2px solid&quot;&gt;-------------- Original message from Dave Paris &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18451226&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;dparis@...&lt;/a&gt;&amp;gt;: -------------- &lt;BR&gt;&lt;BR&gt;&lt;div class='shrinkable-quote'&gt;&lt;BR&gt;&amp;gt; It seem like you might be confusing &quot;shared infrastructure&quot; with &lt;BR&gt;&amp;gt; &quot;single ip&quot;. As others have said, you need a distinct address for each &lt;BR&gt;&amp;gt; SSL-enabled httpd or proxy, although they can reside on the same hardware. &lt;BR&gt;&amp;gt; &lt;BR&gt;&amp;gt; A good example of this is the typical configuration for larger server &lt;BR&gt;&amp;gt; farms. You find multiple High Availability load balancers in the DMZ for &lt;BR&gt;&amp;gt; both http and https using something like ha/keepalived for linux. These &lt;BR&gt;&amp;gt; proxy the incoming request back into private address space. The SSL &lt;BR&gt;&amp;gt; proxies terminate the SSL connection and broker the request on behalf of &lt;BR&gt;&amp;gt; the user and everything goes to the private address space in plain http. &lt;BR&gt;&amp;gt; This allows each of the _real_ webservers to achieve better &lt;BR&gt;&amp;gt; performance since the SSL overhead is not present. &lt;BR&gt;&amp;gt; &lt;BR&gt;&amp;gt; While you can use Apache as an SSL-terminating proxy, I find I get &lt;BR&gt;&amp;gt; better performance, lower memory utilization and easier configuration &lt;BR&gt;&amp;gt; using Pound ( &lt;A href=&quot;http://www.apsis.ch/pound/&quot; target=_blank rel=&quot;nofollow&quot;&gt;http://www.apsis.ch/pound/&lt;/A&gt; ). Using keepalived, I have &lt;BR&gt;&amp;gt; multiple public IP addresses floating between several hosts and pound &lt;BR&gt;&amp;gt; binds https to those addresses. &lt;BR&gt;&amp;gt; &lt;BR&gt;&amp;gt; Hope that adds a bit of additional clarity, &lt;BR&gt;&amp;gt; Dave &lt;BR&gt;&amp;gt; &lt;BR&gt;&amp;gt; Cuesta Gilles sent forth: &lt;BR&gt;&amp;gt; &amp;gt; So what about this ? &lt;BR&gt;&amp;gt; &amp;gt; &quot;*MULTIPLE CN (SAN) SERVER CERTIFICATES* &lt;BR&gt;&amp;gt; &amp;gt; &lt;BR&gt;&amp;gt; &amp;gt; This type of certificate (also called /Subject Alternative Name/ (SAN) ) &lt;BR&gt;&amp;gt; &amp;gt; enables to secure not only one website but a large number of sites (a &lt;BR&gt;&amp;gt; &amp;gt; list of sites) hosted on a shared infrastructure (server with multiple &lt;BR&gt;&amp;gt; &amp;gt; names, reverse proxy). Ideal to secure multiple brands of a corporation. &lt;BR&gt;&amp;gt; &amp;gt; One certificate per hardware is required.&quot; &lt;BR&gt;&amp;gt; &amp;gt; &lt;BR&gt;&amp;gt; &amp;gt; &lt;A href=&quot;http://www.tbs-certificats.com/index.html.en&quot; target=_blank rel=&quot;nofollow&quot;&gt;http://www.tbs-certificats.com/index.html.en&lt;/A&gt; &lt;BR&gt;&amp;gt; &amp;gt; &lt;BR&gt;&amp;gt; ______________________________________________________________________ &lt;BR&gt;&amp;gt; Apache Interface to OpenSSL (mod_ssl) &lt;A href=&quot;http://www.modssl.org/&quot; target=_blank rel=&quot;nofollow&quot;&gt;www.modssl.org&lt;/A&gt; &lt;BR&gt;&amp;gt; User Support Mailing List &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18451226&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt; &lt;BR&gt;&amp;gt; Automated List Manager &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18451226&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt; &lt;/BLOCKQUOTE&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;&lt;/DIV&gt;&lt;/div&gt;&lt;/BLOCKQUOTE&gt;
&lt;!-- END WEBMAIL STATIONERY --&gt;

&lt;/body&gt;
&lt;/html&gt;
&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/SSL-proxy-tp18391124p18451226.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18450988</id>
	<title>Re: wrong e-mail !!!!!!!!!!!!!!!!!!!!!!!</title>
	<published>2008-07-14T12:13:05Z</published>
	<updated>2008-07-14T12:13:05Z</updated>
	<author>
		<name>Shahadat Hossain</name>
	</author>
	<content type="html">&lt;div&gt;you know what, You are a f***en idiot.&lt;/div&gt;
&lt;div&gt;if you do not want to receive these emails, just get your name taken off from the list instead of b-shitting. &lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;send an email to &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18450988&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt; address (you can also find it at the bottom of this message) with subject as &amp;#39;Remove me&amp;#39;.&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;ok?&lt;br&gt;&lt;br&gt;&lt;/div&gt;
&lt;div class=&quot;gmail_quote&quot;&gt;On Mon, Jul 14, 2008 at 7:10 PM, &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18450988&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;erika20@...&lt;/a&gt;&amp;gt; wrote:&lt;br&gt;
&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;PADDING-LEFT: 1ex; MARGIN: 0px 0px 0px 0.8ex; BORDER-LEFT: #ccc 1px solid&quot;&gt;
&lt;div&gt;
&lt;div&gt;&lt;/div&gt;
&lt;div&gt;&lt;font size=&quot;7&quot;&gt;stop &lt;/font&gt;&lt;font color=&quot;#cc0000&quot;&gt;&lt;font size=&quot;7&quot;&gt;stop&lt;/font&gt;&amp;nbsp; &lt;font size=&quot;7&quot;&gt;sending me &lt;/font&gt;&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font color=&quot;#cc0000&quot; size=&quot;7&quot;&gt;this bs , i have no idea&amp;nbsp; who are you !!!!&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font color=&quot;#cc0000&quot; size=&quot;7&quot;&gt;stop !!!!!!!!!!!!!!!&lt;/font&gt;&lt;/div&gt;
&lt;blockquote style=&quot;PADDING-LEFT: 5px; MARGIN-LEFT: 5px; BORDER-LEFT: #1010ff 2px solid&quot;&gt;-------------- Original message from Dave Paris &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18450988&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;dparis@...&lt;/a&gt;&amp;gt;: -------------- &lt;br&gt;
&lt;br&gt;&lt;br&gt;&amp;gt; It seem like you might be confusing &amp;quot;shared infrastructure&amp;quot; with &lt;br&gt;&amp;gt; &amp;quot;single ip&amp;quot;. As others have said, you need a distinct address for each &lt;br&gt;&amp;gt; SSL-enabled httpd or proxy, although they can reside on the same hardware. &lt;br&gt;
&amp;gt; &lt;br&gt;&amp;gt; A good example of this is the typical configuration for larger server &lt;br&gt;&amp;gt; farms. You find multiple High Availability load balancers in the DMZ for &lt;br&gt;&amp;gt; both http and https using something like ha/keepalived for linux. These &lt;br&gt;
&amp;gt; proxy the incoming request back into private address space. The SSL &lt;br&gt;&amp;gt; proxies terminate the SSL connection and broker the request on behalf of &lt;br&gt;&amp;gt; the user and everything goes to the private address space in plain http. &lt;br&gt;
&amp;gt; This allows each of the _real_ webservers to achieve better &lt;br&gt;&amp;gt; performance since the SSL overhead is not present. &lt;br&gt;&amp;gt; &lt;br&gt;&amp;gt; While you can use Apache as an SSL-terminating proxy, I find I get &lt;br&gt;&amp;gt; better performance, lower memory utilization and easier configuration &lt;br&gt;
&amp;gt; using Pound ( &lt;a href=&quot;http://www.apsis.ch/pound/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.apsis.ch/pound/&lt;/a&gt; ). Using keepalived, I have &lt;br&gt;&amp;gt; multiple public IP addresses floating between several hosts and pound &lt;br&gt;&amp;gt; binds https to those addresses. &lt;br&gt;
&amp;gt; &lt;br&gt;&amp;gt; Hope that adds a bit of additional clarity, &lt;br&gt;&amp;gt; Dave &lt;br&gt;&amp;gt; &lt;br&gt;&amp;gt; Cuesta Gilles sent forth: &lt;br&gt;&amp;gt; &amp;gt; So what about this ? &lt;br&gt;&amp;gt; &amp;gt; &amp;quot;*MULTIPLE CN (SAN) SERVER CERTIFICATES* &lt;br&gt;&amp;gt; &amp;gt; &lt;br&gt;
&amp;gt; &amp;gt; This type of certificate (also called /Subject Alternative Name/ (SAN) ) &lt;br&gt;&amp;gt; &amp;gt; enables to secure not only one website but a large number of sites (a &lt;br&gt;&amp;gt; &amp;gt; list of sites) hosted on a shared infrastructure (server with multiple &lt;br&gt;
&amp;gt; &amp;gt; names, reverse proxy). Ideal to secure multiple brands of a corporation. &lt;br&gt;&amp;gt; &amp;gt; One certificate per hardware is required.&amp;quot; &lt;br&gt;&amp;gt; &amp;gt; &lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;http://www.tbs-certificats.com/index.html.en&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.tbs-certificats.com/index.html.en&lt;/a&gt; &lt;br&gt;
&amp;gt; &amp;gt; &lt;br&gt;&amp;gt; ______________________________________________________________________ &lt;br&gt;&amp;gt; Apache Interface to OpenSSL (mod_ssl) &lt;a href=&quot;http://www.modssl.org/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;www.modssl.org&lt;/a&gt; &lt;br&gt;&amp;gt; User Support Mailing List &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18450988&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;modssl-users@...&lt;/a&gt; &lt;br&gt;
&amp;gt; Automated List Manager &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18450988&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt; &lt;/blockquote&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;
&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/mod_ssl---Users-f381.html&quot; embed=&quot;fixTarget[381]&quot; target=&quot;_top&quot; &gt;mod_ssl - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/SSL-proxy-tp18391124p18450988.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18449708</id>
	<title>wrong e-mail !!!!!!!!!!!!!!!!!!!!!!!</title>
	<published>2008-07-14T11:10:12Z</published>
	<updated>2008-07-14T11:10:12Z</updated>
	<author>
		<name>erika20</name>
	</author>
	<content type="html">&lt;html&gt;
&lt;!-- BEGIN WEBMAIL STATIONERY --&gt;
&lt;head&gt;&lt;/head&gt;
&lt;body&gt;
&lt;!-- WEBMAIL STATIONERY noneset --&gt;
&lt;DIV&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT size=7&gt;stop &lt;/FONT&gt;&lt;FONT color=#cc0000&gt;&lt;FONT size=7&gt;stop&lt;/FONT&gt;&amp;nbsp; &lt;FONT size=7&gt;sending me &lt;/FONT&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT color=#cc0000 size=7&gt;this bs , i have no idea&amp;nbsp; who are you !!!!&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT color=#cc0000 size=7&gt;stop !!!!!!!!!!!!!!!&lt;/FONT&gt;&lt;/DIV&gt;
&lt;BLOCKQUOTE style=&quo