I have already posted the following on the lists under "Proxy'ing client
certs" thread.
Could not see the posting, hence re-posting.
-----------------------------------------------------------------
My understanding had been the following :

Client       ----       Proxy Server   --  Proxy Client         ----
Server
produces a          consumes           presents a                        Can
only recv
CA signed           the                      ProxyClient Cert
ProxyClient Cert
Client Cert           Client Cert

"ProxyClient Cert" is not the same as "Client Cert".

Though the Proxy Server is in receipt of the "Client Cert", it
cannot represent the same in the SSL connection between
"ProxyClient - Server".  The requirement is to make the Proxy
faithfully forward the "Client Cert" to the "Server".


Vadim, suggested that "CONNECT method of HTTP can be
used to setup TCP connections first and run SSL next.  Proxy
could forward SSL traffic".

It had been difficult to understand the solution.  It seems to me that
we need to set up a TCP connection via the proxy server first and add
SSL to it later.  I am not aware of how to do this.

Could one help me further.

Namaste,
R S Chandrasekhar
[EMAIL PROTECTED]
ISD     : 091-080-2051166
Telnet : 847-1166
Phone : 2052427

______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to