Problems connecting to 389 directory server
Peter Schober
peter.schober at univie.ac.at
Tue Dec 5 15:21:03 EST 2017
* Cantor, Scott <cantor.2 at osu.edu> [2017-12-05 21:14]:
> > IIRC some openssl releases even
> > called the connection insecure (or the chain invalid) if the
> > "top-most" cert sent was self-signed (as would always be the case when
> > sending the root CA cert).
>
> No, it's actually the reverse. If the chain OpenSSL builds is rooted
> in a non-self-signed certificate, the verify routine fails. That bug
> still exists, AFAIK.
I'm pretty certain I saw exactly the behaviour I mentioned.
I've not seen the case you mention, where it should terminate the
chain successfully once it has a local trust anchor available matching
a cert in the chain that's not the "top-most" one.
-peter
More information about the users
mailing list