Re: [openssl-users] Openssl not properly validating certificates?

2012-12-06 Thread Jakob Bohm
On 12/5/2012 6:44 PM, Will Nordmeyer wrote: On Wed, Dec 5, 2012 at 12:18 PM, Jakob Bohm jb-open...@wisemo.com wrote: On 12/5/2012 5:30 PM, Will Nordmeyer wrote: On Wed, Dec 5, 2012 at 11:22 AM, Dr. Stephen Henson st...@openssl.org wrote: On Wed, Dec 05, 2012, Will Nordmeyer wrote: On Wed,

Re: [openssl-users] Openssl not properly validating certificates?

2012-12-05 Thread Erwann Abalea
OpenSSL 1.0.1 works fine here, both with expired and revoked certificates (i.e. correctly reports the status). Could you share your elements (certs, CRLs)? -- Erwann ABALEA - chlorophytophonie: musique pour les plantes vertes Le 05/12/2012 15:11, Will Nordmeyer a écrit : Hi, I've done

Re: [openssl-users] Openssl not properly validating certificates?

2012-12-05 Thread Will Nordmeyer
They are US. gov't certificates CRLs, so providing them is a little complicated. Before I had the proper root intermediate CAs loaded and hashed, I would get errors about missing certs in the chain. Similarly, before I loaded the CRL, it would have issues. The CERTs are in PEM formats, as well

Re: [openssl-users] Openssl not properly validating certificates?

2012-12-05 Thread Dr. Stephen Henson
On Wed, Dec 05, 2012, Will Nordmeyer wrote: They are US. gov't certificates CRLs, so providing them is a little complicated. Before I had the proper root intermediate CAs loaded and hashed, I would get errors about missing certs in the chain. Similarly, before I loaded the CRL, it would

Re: [openssl-users] Openssl not properly validating certificates?

2012-12-05 Thread Will Nordmeyer
On Wed, Dec 5, 2012 at 10:47 AM, Dr. Stephen Henson st...@openssl.org wrote: On Wed, Dec 05, 2012, Will Nordmeyer wrote: They are US. gov't certificates CRLs, so providing them is a little complicated. Before I had the proper root intermediate CAs loaded and hashed, I would get errors

Re: [openssl-users] Openssl not properly validating certificates?

2012-12-05 Thread Dr. Stephen Henson
On Wed, Dec 05, 2012, Will Nordmeyer wrote: On Wed, Dec 5, 2012 at 10:47 AM, Dr. Stephen Henson st...@openssl.org wrote: On Wed, Dec 05, 2012, Will Nordmeyer wrote: They are US. gov't certificates CRLs, so providing them is a little complicated. Before I had the proper root

Re: [openssl-users] Openssl not properly validating certificates?

2012-12-05 Thread Will Nordmeyer
On Wed, Dec 5, 2012 at 11:22 AM, Dr. Stephen Henson st...@openssl.org wrote: On Wed, Dec 05, 2012, Will Nordmeyer wrote: On Wed, Dec 5, 2012 at 10:47 AM, Dr. Stephen Henson st...@openssl.org wrote: On Wed, Dec 05, 2012, Will Nordmeyer wrote: They are US. gov't certificates CRLs, so

Re: [openssl-users] Openssl not properly validating certificates?

2012-12-05 Thread Jakob Bohm
On 12/5/2012 5:30 PM, Will Nordmeyer wrote: On Wed, Dec 5, 2012 at 11:22 AM, Dr. Stephen Henson st...@openssl.org wrote: On Wed, Dec 05, 2012, Will Nordmeyer wrote: On Wed, Dec 5, 2012 at 10:47 AM, Dr. Stephen Henson st...@openssl.org wrote: On Wed, Dec 05, 2012, Will Nordmeyer wrote: They

Re: [openssl-users] Openssl not properly validating certificates?

2012-12-05 Thread Will Nordmeyer
On Wed, Dec 5, 2012 at 12:18 PM, Jakob Bohm jb-open...@wisemo.com wrote: On 12/5/2012 5:30 PM, Will Nordmeyer wrote: On Wed, Dec 5, 2012 at 11:22 AM, Dr. Stephen Henson st...@openssl.org wrote: On Wed, Dec 05, 2012, Will Nordmeyer wrote: On Wed, Dec 5, 2012 at 10:47 AM, Dr. Stephen Henson