Re: mod_ssl errors

2000-01-29 Thread Eckard Wille
jay wrote: > > [28/Jan/2000 15:54:06 12886] [error] OpenSSL: error:140890C7:SSL >routines:SSL3_GET_CLIENT_CERTIFICATE:peer did not return a certificate [Hint: No CAs >known to server for verification?] Your browser does not present a client cert (at least no cert issued by a CA your server know

RE: Crypto law question...

2000-01-29 Thread Daniel S. Reichenbach
> I though you're in Germany, Daniel? If yes, then why do you bother about > US export laws? For the Win32 problems I can only say that I've not > changed any Win32 stuff in mod_ssl recently, so I guess the problems > might be more related to changes in Apache. But if you have any patches > at han

RE: RPM installs (mod's)

2000-01-29 Thread GOMEZ Henri
To reply: 1) Install latest apache+mod_ssl. http://www.modssl.org/contrib/apache-mod_ssl-1.3.11.2.5.0-0.6.0.i386.rpm http://www.modssl.org/contrib/apache-mod_ssl-1.3.11.2.5.0-0.6.0.src.rpm mod_perl: take the latest SRPM for redhat, rebuild and install mod_php3: I'll provide a RPM this afternoo

RE: Diffie-Hellman Key Exchange again.

2000-01-29 Thread Jeffrey Altman
> That kinda sucks, doesn't it? > > > Once again, using anonymous DH is a really terrible idea. > > It leaves you completely open to active attack. > > That might be the case, but it's far better than no crypt at all. > I could imagine the effect of using ADH is similar to using SSH without RSA.

Re: Crypto law question...

2000-01-29 Thread Ralf S. Engelschall
On Fri, Jan 28, 2000, Daniel S. Reichenbach wrote: > just a little law thing: after the export laws now have changed to allow > 128bit exports, how about discussing code related things??? For OpenSA > we would have several mod_ssl related issues to be discussed. This would > help to fix the Win32

Re: Crypto law question...

2000-01-29 Thread Sibone Chen
Ralf, I am in China. This law question is relate to me. My problem is: If I need 128 bit SSL cryption, what should I do? Do I need to reinstall the mod-ssl? Do I need to reapply a cert for 128 bit SSL on my www site from Versign? If yes, can Versign give me that cert? Regards Sibone ---

Passphrase Dialog hangs

2000-01-29 Thread webmaster
All- I've just upgraded from Apache 1.3.9/mod_ssl 2.4.8 to 1.3.11/2.5.0. I've also got php 3.0.14 installed, all modules linked statically. I've got an section in my httpd.conf for my modssl configuration directives. Without mod_ssl loaded, apache starts up and runs fine. With mod_ssl enabl

mod_ssl errors

2000-01-29 Thread jay
Sorry I couldn't be more specific with my subject. :) Anyhow, I've never worked with ssl certs before, and the only knowledge I have is from reading documenation and reference manuals. I got a cert from Verisign, installed Apache+mod_ssl, and configured it to use the cert I got back from Verisi

Re: mod_ssl errors

2000-01-29 Thread jeffkoch
Hi - Does anyone on this list know what could be used to encrypt/decrypt streaming files on the fly? I understand that public key encryption could probably be used for encrypting a small key that would unlock the larger file. Regards, Jeff On Sat, 29 Jan 2000, Eckard Wille wrote: > jay wrote:

RE: I want to have my cake and eat it!

2000-01-29 Thread Airey, John
Thanks Graham. I'd investigated the cost of Cisco Secure ACS for NT. This supports TACACS+ authentication for NT but costs £3395 + vat. A bit steep methinks (especially when TACACS+ programs are available for free for Linux). I did notice that the Samba book I was reading mentioned LDAP, but I di

Modules

2000-01-29 Thread Airey, John
Do I have to recompile Apache-mod_ssl in order to use a module that is not part of the basic distribution (eg an authentication module), or is there a proper way to do this? I'm currently using RPM's with Redhat Linux 6.0 because I prefer the simplicity of installation. However, I'm prepared to b

Re: Modules

2000-01-29 Thread Ralf S. Engelschall
On Fri, Jan 28, 2000, Airey, John wrote: > Do I have to recompile Apache-mod_ssl in order to use a module that is not > part of the basic distribution (eg an authentication module), or is there a > proper way to do this? > > I'm currently using RPM's with Redhat Linux 6.0 because I prefer the >

Generating CSR for Netscape Certificate Server based CA

2000-01-29 Thread Merton Campbell Crockett
I need to create a Certificate Signing Request for the DoD Certificate Authority. DoD uses a Netscape Certificate Server to manage and sign its certificates. To date, I have not been able to generate a CSR that is acceptable to the Netscape Certificate Server. All requests are rejected with a "