RE: SSLCACertificatePath directive (UNCLASSIFIED)

"Victor, Dwight P CTR DISA PAC" <[email protected]>
Newsgroups gmane.comp.apache.mod-ssl.user
Message-ID <87FC85CC4AE9C94D9EF34083790C610F57019A@bangladesh.disanet.disa-u.mil>
Classification:  UNCLASSIFIED 
Caveats: NONE


Hello Arsen,

If you're using mod_ssl/OpenSSL on Linux, I know you can use the c_rehash
command to automatically create the required symoblic links.  On my install,
c_rehash is in the /usr/local/bin directory.

Hope that helps,

Dwight...

---
Dwight Victor, CISSP (Contractor)
DISA-PAC EMSS Gateway Hawaii
EMAIL: [email protected]
TEL:   (808) 653-3677 ext 229

-----Original Message-----
From: [email protected] [mailto:[email protected]]
On Behalf Of Arsen Hayrapetyan
Sent: Wednesday, August 08, 2007 2:26 AM
To: [email protected]
Subject: SSLCACertificatePath directive

Hello,

I have a bunch of certificates of CAs which I want to put in directory
pointed by SSLCACertificatePath directive. All of them have the filenames in
the form hash-value.0 The mod_ssl official documentation says:
"The files in this directory have to be ... accessible through hash names.
So usually you can't just place the certificate files there: you also have
to create symbolic links named hash-value.N".

1) What should be N in the CA certificate file name? Should certificate file
names have sequential N's, reflecting the prefered order of checking against
them during client authentication? 

2) Are symbolic links mandatory? Can I put the hash-value.N files there
without creating the links?

Thanks in advance,
Arsen.
______________________________________________________________________
Apache Interface to OpenSSL (mod_ssl)                   www.modssl.org
User Support Mailing List                      [email protected]
Automated List Manager                            [email protected]
Classification:  UNCLASSIFIED 
Caveats: NONE
smime.p7s (application/x-pkcs7-signature, 5.5 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.