more than only one certificate per server

more than only one certificate per server

Secure Home | Search | About
 Computer Software Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
more than only one certificate per server toralf 06-21-2008
Posted by toralf on June 21, 2008, 7:44 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello,


We serve at work many customers within a client/server architecture
and would like to have different certs for different customer - but
we've only one server where all customers connect to.

Therefor I'm wondering, whether it is possible for a server providing a
SSL connection to its web service to accept more than only one
certificate.

--
MfG/Sincerely

Toralf Förster
pgp finger print: 7B1A 07F4 EC82 0F90 D4C2 8936 872A E508 7DB6 9DA3



Posted by Felix Tiede on June 21, 2008, 4:07 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
toralf wrote:

> Hello,
>
>
> We serve at work many customers within a client/server architecture
> and would like to have different certs for different customer - but
> we've only one server where all customers connect to.
>
> Therefor I'm wondering, whether it is possible for a server providing a
> SSL connection to its web service to accept more than only one
> certificate.
>

A web service using SSL/TLS can accept more than one client certificate,
f.ex. one for each customer. If your web service supports specifying
certification authorities to sign client certificates (like apache does),
you can create a CA to sign client certificates. This would enable you to
issue new client certificates without reconfiguring your web service. And
if you can specify certificate revocation lists as well, you can also
revoke certificates without reconfiguration. But this depends on what the
server behind your web service supports.

What a web service can't do is present different server certificates to each
customer, except each customer would use his own IP/Port combination.

Hope it helps,
Felix Tiede

Similar ThreadsPosted
successfully installed openssl on hosted server - host says there i sno security unless I buy separate certificate - is that right? December 19, 2005, 3:44 pm
Is this server secure enough? Is this server hackable? August 3, 2006, 1:45 pm
where do I buy a SSL certificate? May 18, 2006, 4:39 am
Where to get free digital certificate? September 18, 2005, 3:15 pm
simple question about certificate chains July 5, 2005, 3:36 am
Question about Security Certificate Notices November 21, 2008, 2:24 pm
want to create and install private key certificate using openssl July 31, 2006, 1:18 pm
Re: OpenSSL New Trusted Root Certificate PHP/HTML Integration June 18, 2008, 2:36 pm
Locating a server March 5, 2006, 12:38 pm
ftp server question June 23, 2006, 8:27 am

The site map in XML format XML site map

Contact Us | Privacy Policy