How can I configure an SSL server to redirect (eg to
an enrollment web page) if a client fails to
provide a valid certificate.

Trying to access the server (with netscape46) results
in a "No user certificate" message from the browser
followed by an "IO error occured during security
authorisation"

The server takes the failure as an error in the
SSL handshaking with the following in the error_log
(and a funny hint from openssl!):

mod_ssl: SSL handshake failed (client xxx.xx.xxx, server
xxxx.xxx.xx:8443) (OpenSSL library error follows)
OpenSSL: error:140890C7:SSL routines:SSL3_GET_CLIENT_CERTIFICATE:peer
did not return a certificate [Hint: No CAs known to server for
verification?]

Apache/1.3.6 mod_ssl/2.3.10

Cheers,

Andy
______________________________________________________________________
Apache Interface to OpenSSL (mod_ssl)                   www.modssl.org
User Support Mailing List                      [EMAIL PROTECTED]
Automated List Manager                            [EMAIL PROTECTED]

Reply via email to