The problem is that the browser root verisign cert no longer matches the one that is root for the server. However the common name on the cert is the same as the name on the newer ca root that lasts beyound 2000. This means you can accept the cert, but you need to remove the other.
These are the instructions from Phil Tracy at Northwestern University.
The two possible remedies are (1) tell people to upgrade to a more modern
browser, or (2) publish a set of instructions which guides users through
the process of updating their older browsers to work with the newer digital
certificates. This will be a non-trivial process for most users. Which
support approach are you interested in? Both?
If you want to try out the certificate authority replacement approach, do
this (Windows):
Open Netscape 3.0x.
Under Options/Security, select Certificate Authorities.
Then select Verisign Secure Server.
Delete this certificate.
Go to URL http://www-gate.it-services.nwu.edu/it/new-verisign-ca.cacert
Follow the dialog boxes to accept the new certificate authority
Albert Steiner
At 12:04 PM 7/29/99 -0400, you wrote:
>
>Openssl .93a
>modssl 2.3.6
>apache 1.3.6
>Dec Unix 4.01
>
>B
>Hmm, ran into a dousy.
>
>We just upgraded our verisign cert on our development server, and suddenly
>Netscape 3 browsers get a database security error when trying to connect.
>Everything else seems fine. Any ideas?
>
>
>
>Jeff
>
>
>______________________________________________________________________
>Apache Interface to OpenSSL (mod_ssl) www.modssl.org
>User Support Mailing List [EMAIL PROTECTED]
>Automated List Manager [EMAIL PROTECTED]
>
--------------
Albert Steiner Coordinator Distributed Computing
Emerging Technologies Group of Academic Technologies
N O R T H W E S T E R N U N I V E R S I T Y
1603 Orrington Suite #1400, Evanston, IL 60201-5064
[EMAIL PROTECTED] Phone 847-491-4056 FAX 847-467-7732
