Támogatás keresése

Kerülje el a támogatási csalásokat. Sosem kérjük arra, hogy hívjon fel egy telefonszámot vagy osszon meg személyes információkat. Jelentse a gyanús tevékenységeket a „Visszaélés bejelentése” lehetőséggel.

További tudnivalók

A témacsoportot lezárták és archiválták. Tegyen fel új kérdést, ha segítségre van szüksége.

Client certificate authentication with certificiates issued with Root CA without CN

  • 2 válasz
  • 1 embernek van ilyen problémája
  • 18 megtekintés
  • Utolsó üzenet ettől: cor-el

more options

Hi,

we are experiencing issues with client certificate authentication in Firefox and we suspect issue could be related to "badly" formatted root CA certificate. The root CA certificate (issued in 2003) contains Subject without CN (only OU, O and C). Also the value of extension 2.5.29.19 parameter "Path Lenght Constraint" is set to string value "None" - usually should be numeric, e.g. 0.

The issue occurs when web server requires client certificate authentication - Internet Explorer and Chrome will offer client certificate issued with such CA while Firefox won't. We tested with two web servers, Apache, which sends the CTL to browser and IIS, which does not (checked with openssl s_client) and results were the same - Firefox will not offer client certificate issued with mentioned CA. We tested scenarios with certificate (and root CA certificate) stored in Software security device and on smart card.

Is this behaviour by design?

Best regards,

    Blaz
Hi, we are experiencing issues with client certificate authentication in Firefox and we suspect issue could be related to "badly" formatted root CA certificate. The root CA certificate (issued in 2003) contains Subject without CN (only OU, O and C). Also the value of extension 2.5.29.19 parameter "Path Lenght Constraint" is set to string value "None" - usually should be numeric, e.g. 0. The issue occurs when web server requires client certificate authentication - Internet Explorer and Chrome will offer client certificate issued with such CA while Firefox won't. We tested with two web servers, Apache, which sends the CTL to browser and IIS, which does not (checked with openssl s_client) and results were the same - Firefox will not offer client certificate issued with mentioned CA. We tested scenarios with certificate (and root CA certificate) stored in Software security device and on smart card. Is this behaviour by design? Best regards, Blaz

Összes válasz (2)

more options

Are you still looking for an answer to this ? I do not know the answer, but may be able to find someone who can help.

more options

See this page for contact information: