Re: ssl verification problem

Matthias Hunstock <[email protected]> Thu, 20 Dec 2012 10:59:23 +0100
Newsgroups gmane.mail.perdition.user
Message-ID <[email protected]>
Am 19.12.2012 17:14, schrieb Pablo Davicino:

> This is the output that we get when we tried to connect to prediction
> (port 995) via openssl:
> 
> verify error:num=20:unable to get local issuer certificate
> verify return:1


Try using openssl with -show_certs, and check that the first certificate
is the correct one from your pem file.


> We have setup a cert_file with the three certificates:
> 
> ---Begin Certificate---
>     our certificate
> ---End Certificate---
> ---Begin Certificate---
>     intermediate certificate
> ---End Certificate---
> ---Begin Certificate---
>     root certificate
> ---End Certificate---

Correct, works here. Which version of perdition and libssl do you have?

> Also we test using ssl_ca_chain file, and ssl_ca_path and nothing works.
> Every test produces the same errors.

ca_path should only be neccessary if perdition must check certificates
of other entities, either the real servers or client certificates.


Regards,
Matthias

-- 
Dipl.-Inf. Matthias Hunstock
UniRZ der TU Ilmenau, Raum 07
Tel.: +49 3677 69-1289
______________________________________________
Perdition-users mailing list
[email protected]
http://lists.vergenet.net/listinfo/perdition-users