[Pound Mailing List] Confuring Pound to work with seperate Keys/Certificate pairs
warren perdue <kronos2185-/[email protected]> Fri, 17 Mar 2017 21:35:54 +0000 (UTC)
| Newsgroups | gmane.comp.web.pound.general |
|---|---|
| Message-ID | <[email protected]> |
Hey everyone, I need your help with trying to setup my Pound on an Linux embedded system. What I want to do is have pound only accept a certificate that I give the user. I will place the key as a private key on my machine and will give the user the certificate. They will then have to add that certificate to their browser so that they can access Pound. I understand Pound needs an initial PEM to send out. But I do not want to accept that PEM. I want to send them the Certificate to place in their browser or what ever program they will use to access the system and access the system. Basically. My plan is to create an different key and certificate with SHA512 and 4096 Bytes long. Place the key in the private section of Pound. Give the certificate to the key to the user and they can use that to access Pound and my system. I am having problems setting Pound up to function in that manner. I Am aware of the CAList, Verifylist commands, but what else do i need to add to my Pound/conf file to make it work?There are many options and not alot of documentation online supporting pound. If any of you all can help. Please reply. I will also have it working in conjunction with SSL and running BOA as my web-server if that will help you. I have already compiled the system kernel and system to use BOA with SSL and also include Pound as a part of its kernel. I can run pound and have it control access through the listener but I want to make it super hard to crack or hack my system. Warren -- To unsubscribe send an email with subject unsubscribe to [email protected] Please contact [email protected] for questions.