Re: [Pound Mailing List] Pound SNI and SAN matching
Filidor Wiese <[email protected]>
| Newsgroups | gmane.comp.web.pound.general |
|---|---|
| Message-ID | <[email protected]> |
For anyone looking for the same answer, it seems that Richard Green is right in that "Certificate alternate names support" is introduced in version 2.7a (according to the changelogs). Regards, Filidor Filidor Wiese schreef op 22.08.2014 12:53: > Thanks for you reply. Yes I have installed the ca chain just like > you've described. The thing is, https://www.domaina.com works (correct > certificate) https://domaina.com doesn't (certificate of domainb). So > the certificate is fine, somehow Pound doesn't match a request to the > naked domain to the second SAN in the certificate... > > Regards, > Filidor > > > Richard Green schreef op 22.08.2014 12:12: >> Did you add the CA chain cert to domaina.pem? Also the order may be >> important. I make them >> >> 1. key >> 2. cert >> 3. chain-auth-cert >> >> order seems to work. >> >> My organization use commodo certs. >> >> This worked on 2.6, although I went to 2.7 because it handles multiple >> UCC certs. 2.6 did not, I found. >> >> -R >> > > -- > To unsubscribe send an email with subject unsubscribe to > [email protected] > Please contact [email protected] for questions. -- To unsubscribe send an email with subject unsubscribe to [email protected] Please contact [email protected] for questions.