SSL - can you insite on having certificate?

SSL - can you insite on having certificate?

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
SSL - can you insite on having certificate? Dave 01-09-2006
Posted by Dave on January 9, 2006, 9:47 am
If you were  Registered and logged in, you could reply and use other advanced thread options
If you connect to an SSL secure site that does not have a certificate
from one of the big CAs, or the certificate has expired, you get asked
if you will accept the certificate or not.

I implemented an SSL site at

https://www.3gshare.info/

which is for private use, so such messages are not an issue.

However, is it possible to configure the site such that unless you have
already have a certificate on your machine, you are unable to connect?
i.e the user has no choice to accept it or not - they either have it, or
they can't connect?

I don't think this is possible, but if it is, please let me know how.
The server runs Apache 2.x.


--
Dave K

http://www.southminster-branch-line.org.uk/

Please note my email address changes periodically to avoid spam.
It is always of the form: month-year@domain. Hitting reply will work
for a couple of months only. Later set it manually. The month is
always written in 3 letters (e.g. Jan, not January etc)

Posted by Rob Skedgell on January 9, 2006, 10:29 am
If you were  Registered and logged in, you could reply and use other advanced thread options
wrote:

> If you connect to an SSL secure site that does not have a
> certificate from one of the big CAs, or the certificate has
> expired, you get asked if you will accept the certificate or not.
>
> I implemented an SSL site at
>
> https://www.3gshare.info/
>
> which is for private use, so such messages are not an issue.
>
> However, is it possible to configure the site such that unless you
> have already have a certificate on your machine, you are unable to
> connect? i.e the user has no choice to accept it or not - they
> either have it, or they can't connect?
>
> I don't think this is possible, but if it is, please let me know
> how. The server runs Apache 2.x.

Could you use the mod_ssl "SSLRequireSSL" and "SSLVerifyClient
require" directives together with SSL/TLS client certificates you
generate, sign & issue? I haven't tried this myself, but
<http://httpd.apache.org/docs/2.0/mod/mod_ssl.html> might be a good
place to start.

--
From: address is a spamtrap, Reply-To: is valid.
GnuPG/PGP: 7DA3 1579 C0DD 8748 C05A B984 E2A2 3234 D14B 6DD7


Similar ThreadsPosted
Howto setup a certificate authority and create a signed certificate using openssl on Debian sarge March 16, 2005, 10:39 am
What is a Certificate? April 21, 2005, 10:21 am
TLS/SSL certificate format August 6, 2004, 10:32 am
Certificate generation via WEB January 21, 2005, 3:45 am
certificate distribution February 17, 2007, 12:41 am
Digital Machine Certificate - Win XP Pro SP1 May 12, 2004, 1:43 pm
PKCS12 certificate usage November 29, 2004, 10:52 am
Certificate Management Tools April 27, 2005, 9:35 am
Key pair & Certificate lifetimes April 28, 2005, 12:15 pm
X.509 certificate pkcs#1 v2.1 support January 28, 2006, 11:17 am

The site map in XML format XML site map

Contact Us | Privacy Policy