Hello,
I am trying to write a server that will accept an incoming SSL connection.
In psuedo, I have the following chain of function calls
SSL_CTX_load_verify_locations(ctx, root_cert_file, root_cert_dir)
SSL_CTX_use_certificate_chain_file(chain file)
SSK_CTX_use_PrivateKey_file(chain file)
SSL_CTX_set_verify (sets SSL_VERIFY_PEER)
SSL_CTS_set_verify_depth(to a depth of 4)
The chain file has 3 things in it -
private key of the server CA
a signed certificate request signed by my server CA
the public key of the server CA
When I create a new SSL structure everything goes fine, but when I call
SSL_accept() on it, I get a return of zero, which when I read the error
queue says "sslv3 alert bad certificate"
What does this error mean exactly? Is it a problem with my server
certificate itself, the client certificate returned on the verify, or what?