Re: feature ? authorizing only given certificates ?

Christopher Schultz <[email protected]> Thu, 11 Jul 2019 10:43:56 -0400
Newsgroups gmane.network.stunnel.user
Message-ID <[email protected]>
Fred,

(Apologies for the previous empty email.)

On 7/10/19 12:01, [email protected] wrote:
> Hello
> 
> My european organization is using a certificate chain which signs tens
> of thousands of user certificates.
> 
> My local organization counts 300 users ...  and i only want these 300 to
> get in the IT system.
> 
> I'd like to know if there is a way to restrict the connection to a
> subset of certificates ( for example based on a list of authorized
> emails which are written in the certificate ) 

Why not simply create a new CA certificate, sign those 300 you trust,
and then trust the new CA?

-chris

_______________________________________________
stunnel-users mailing list
[email protected]
https://www.stunnel.org/cgi-bin/mailman/listinfo/stunnel-users
signature.asc (application/pgp-signature, 899 B)
-----BEGIN PGP SIGNATURE-----
Comment: Using GnuPG with Thunderbird - https://www.enigmail.net/

iQIzBAEBCAAdFiEEMmKgYcQvxMe7tcJcHPApP6U8pFgFAl0nSywACgkQHPApP6U8
pFiLLg/7BlPTvaLf4NxTVEHoaloN3gKy/FwrkkGua6zB2WRVM+BLe8XhAQZ/nK4B
o5AGf59BVLEp2ZHP/tAUMNuFTprMgEo8f+dwvLrVgcqm2wS5hrSUBZhCAUX4xH4q
0tUgbIqTRdR629luu9N0qB8RTJuPykYSx3VZ4Pu78sEMbh/cJbHzZY7ncado2AOL
wGgtHJyROPKrFyxPcpYSZV59R1A0q5tiaVbwxUzGRCNkpNE6GN/baApy1T2Kechx
gO2YmMUBezRaq6k+PhxS/PyytZEwWXIMYiE3tHoiMr9EhkmCOxRux24jv6zw87RB
8R1zOEzR5h8fMhXyAYy+fIls/7HGp5mnz2KBEi883/xtTmTZe6OA2DIMiJZ6eNoF
JUWXHcan1VYCuUvYzdorJtWGnglMcpm/RbhpqI8cqWSWOc5BZPna3R9OCqjFhbrJ
FeXzP/n1LSo2/VqO24h7TsIGhVKIPc0U8KFeEJpCNYvUOszxpFLrKlciBTkCugK0
WUU73foGHBWmL/hFhEyPiqsdx/sjCgjcRWQp0/t2wa75mGiPW+khnaU/emE5Xy3K
7uq2QIhyvzp8ugKHAqFOgngiSN5S8mInAolooPSE2Np4sjgxkQGtgC/cCWm94TVG
aSPExkqZbXst1ZaH+Pb2ERDAoecews9m4JJseWnqAQVuHJgnJjg=
=5CTp
-----END PGP SIGNATURE-----