Skip to Content.
Sympa Menu

shibboleth-dev - "Unfortunate" Thawte discovery

Subject: Shibboleth Developers

List archive

"Unfortunate" Thawte discovery


Chronological Thread 
  • From: Scott Cantor <>
  • To:
  • Subject: "Unfortunate" Thawte discovery
  • Date: Fri, 26 Jul 2002 01:12:51 -0400
  • Importance: Normal
  • Organization: The Ohio State University

Turns out the server certs Thawte issues have the EnhancedKeyUsage field
set to Server Authentication, which mod_ssl rejects for client
authentication, preventing a site from sharing that SSL cert between
mod_ssl on their site and the SHAR/mod_shib.

I wonder if that behavior is configurable in mod_ssl. Changing that code
would obviously not be attractive for numerous reasons.

-- Scott

------------------------------------------------------mace-shib-design-+
For list utilities, archives, subscribe, unsubscribe, etc. please visit the
ListProc web interface at

http://archives.internet2.edu/

------------------------------------------------------mace-shib-design--




Archive powered by MHonArc 2.6.16.

Top of Page