On Thu, Aug 7, 2014 at 4:57 PM, Kyle Hamilton <[email protected]> wrote:
> Usually you don't need to echo anything to get the "acceptable client CA
> names" list.
Thanks.

In this case, its IIS 7.5 and its *not* using SNI (SNI is available in
IIS 8). So I get a 400 "bad request" without the host header.

Jeff

> On 8/7/2014 1:55 PM, Jeffrey Walton wrote:
>> I'm trying to track down a client side issue with the use of HTTPS. I
>> suspect it has something to do with a server misconfiguration and
>> client side certificates.
>>
>> When running s_client:
>>
>> $ echo -e "GET / HTTP/1.1\nHost:example.com\n" | \
>>     openssl s_client -connect example.com:443 -ssl3 -ign_eof -CAfile 
>> ca-cert.pem
>>
>> Is there a message displayed that documents the server requesting a
>> client certificate?
>> ______________________________________________________________________
>> OpenSSL Project                                 http://www.openssl.org
>> User Support Mailing List                    [email protected]
>> Automated List Manager                           [email protected]
>
>
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [email protected]
Automated List Manager                           [email protected]

Reply via email to