Re: mod_ssl: Reading dhparams and ecparams not only from the first certificate file

2015-06-01 Thread Rainer Jung
Am 27.05.2015 um 09:33 schrieb Rainer Jung: Am 27.05.2015 um 08:40 schrieb Kaspar Brand: On 26.05.2015 10:33, Rainer Jung wrote: I find it questionable. I would find it more natural to embed the params in the cert files they apply to, so e.g. the DH params in the RSA cert file and the EC params

Re: mod_ssl: Reading dhparams and ecparams not only from the first certificate file

2015-05-27 Thread Rainer Jung
Am 27.05.2015 um 08:40 schrieb Kaspar Brand: On 26.05.2015 10:33, Rainer Jung wrote: I find it questionable. I would find it more natural to embed the params in the cert files they apply to, so e.g. the DH params in the RSA cert file and the EC params in the ECDH cert file and also to not requir

Re: mod_ssl: Reading dhparams and ecparams not only from the first certificate file

2015-05-26 Thread Kaspar Brand
On 26.05.2015 10:33, Rainer Jung wrote: > I find it questionable. I would find it more natural to embed the params > in the cert files they apply to, so e.g. the DH params in the RSA cert > file and the EC params in the ECDH cert file and also to not require a > special order for the files which

Re: mod_ssl: Reading dhparams and ecparams not only from the first certificate file

2015-05-26 Thread Rainer Jung
Am 26.05.2015 um 11:00 schrieb Tim Bannister: On 26 May 2015, at 09:37, Reindl Harald wrote: Am 26.05.2015 um 10:33 schrieb Rainer Jung: Current mod_ssl code tries to read embedded DH and ECC parameters only from the first certificate file. Although this is documented "DH and ECDH paramete

Re: mod_ssl: Reading dhparams and ecparams not only from the first certificate file

2015-05-26 Thread Tim Bannister
On 26 May 2015, at 09:37, Reindl Harald wrote: > > > Am 26.05.2015 um 10:33 schrieb Rainer Jung: >> Current mod_ssl code tries to read embedded DH and ECC parameters only from >> the first certificate file. Although this is documented >> >> "DH and ECDH parameters, however, are only read from

Re: mod_ssl: Reading dhparams and ecparams not only from the first certificate file

2015-05-26 Thread Reindl Harald
Am 26.05.2015 um 10:33 schrieb Rainer Jung: Current mod_ssl code tries to read embedded DH and ECC parameters only from the first certificate file. Although this is documented "DH and ECDH parameters, however, are only read from the first SSLCertificateFile directive, as they are applied indepe

mod_ssl: Reading dhparams and ecparams not only from the first certificate file

2015-05-26 Thread Rainer Jung
Current mod_ssl code tries to read embedded DH and ECC parameters only from the first certificate file. Although this is documented "DH and ECDH parameters, however, are only read from the first SSLCertificateFile directive, as they are applied independently of the authentication algorithm typ