SSL_SESSION_ID on RHEL 5.5

2010-05-10 Thread Michael Ströder
HI! For security reasons I'm using env var SSL_SESSION_ID to cross-check the application's session ID with the SSL session ID in my web application. This works without any issues on my openSUSE boxes. Browser is Seamonkey 2.0.4. But I have problems with Apache 2.2.3 shipped with Red Hat

Jean-Pierre Guilloteau est absent.

2010-05-10 Thread jpguilloteau
I will be out of the office starting Sat 08/05/10 and will not return until Mon 17/05/10. I will respond to your message when I return. __ Apache Interface to OpenSSL (mod_ssl) www.modssl.org User Support

SSLRequire on OID extension DER encoded field value

2010-05-10 Thread Lionel Falise
hey guys, I hope you're all doing fine. I need a little support here on ssl client verification, tell me please if this is not the right place. I need to check for specific extensions field value from x509 client certificates to grant access to defined users. I read this could be possible