Re: Client Authentication and Access Control

Øyvin Sømme <[email protected]>
Newsgroups gmane.comp.apache.mod-ssl.user
Organization Schlumberger, OFS IT
Message-ID <[email protected]>
Øyvin Sømme wrote:
> Joe Orton wrote:
> 
>> On Fri, Jun 03, 2005 at 08:56:56AM +0200, Øyvin Sømme wrote:
>>
>>> Method 2 (SSLRequire):
>>>
>>>  The user-id field is just '-'.
>>>
>>> Can I somehow configure apache/mod_ssl to only store certain elements of
>>> the DN (e.g. the CN in the DN) as the user-id in the access-log?
>>
>>
>>
>> mod_ssl in httpd 2.0 supports the "SSLUsername" directive which allows
>> this:
>>
>> http://httpd.apache.org/docs-2.0/mod/mod_ssl.html#sslusername
>>
>> Regards,
>>
>> joe
> 
> 
> Thanks for a very good suggestion. Seems to be just what I need.
> So I tried to use the directive 'SSLUserName SSL_CLIENT_S_DN_CN'
> inside the <IfDefine SSL> </IfDefine> context. This resulted in *no*
> change in my log files, the user-id field was still '-'.
> 
> Any idea why it didn't work?
> 
> 
> Regards
> Øyvin


I found out the issue: I cannot use 'SSLOptions +FakeBasicAuth' together with 'SSLUserName xxx'
(not documented anywhere).

Regards.
______________________________________________________________________
Apache Interface to OpenSSL (mod_ssl)                   www.modssl.org
User Support Mailing List                      [email protected]
Automated List Manager                            [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.