Re: tlsv1 alert iso-8859-1 ca error on cert authentication

Поиск
Список
Период
Сортировка
От Jacob Champion
Тема Re: tlsv1 alert iso-8859-1 ca error on cert authentication
Дата
Msg-id CAOYmi+=fbH0_9sCkWaj0s-3AUNd1W=H2AyU088RfiGD+AEeKaQ@mail.gmail.com
обсуждение исходный текст
Ответ на Re: tlsv1 alert iso-8859-1 ca error on cert authentication  (Tom Lane <tgl@sss.pgh.pa.us>)
Ответы Re: tlsv1 alert iso-8859-1 ca error on cert authentication
Список pgsql-bugs
On Sun, Jun 8, 2025 at 9:14 AM Tom Lane <tgl@sss.pgh.pa.us> wrote:
> Hm.  This example works fine for me on RHEL8.  Evidently your
> openssl installation is set up to reject self-signed certificates
> by default.

I wonder if this setup is somewhat undefined/underdefined behavior.

Andrus, if I understand correctly, you have
- two certificates (one client, one server _and_ CA)
- with the same(!) Subject, according to the logs
- one signed the other (so it's "self-signed")
- one is marked CA, one is not

I have no idea how OpenSSL or the RFCs resolve this situation. Do you
really intend to have the CA share the same Subject as the client?

--Jacob



В списке pgsql-bugs по дате отправления: