Article delegate-en/1146 of [1-5169] on the server localhost:119
  upper oldest olders older1 this newer1 newers latest
[Top/Up] [oldest] - [Older+chunk] - [Newer+chunk] - [newest + Check]
Newsgroups: mail-lists.delegate-en

[DeleGate-En] Re: sslway client auth problem
14 May 2001 06:02:41 GMT (Yutaka Sato)


On 05/13/01(13:24) you Roger Buck <> wrote
in <_A1145@delegate-en.ML_>
 |Unfortunately, the original problem remains.
 |I upgraded Delegate to V7.3 (latest release version), before applying
 |the sslway patch. I think I have applied the sslway patch correctly, and
 |followed your instructions for -Verify 0 switch.
 |I am attaching my test configuration and log files and hope they might
 |help. The log file is for a coplete session - from starting Delegate
 |through to browser connection - and final broser termination (browser
 |client crashes).

Thank you for your sending log. I saw verifications for each connection,
maybe for each in-line image, recorded in your log, and I noticed that
the situation is inevitable with the current SSLway+DeleGate approach
(with multiple independent processes for multiple connections in a
single session) because there is no persistent entity to care multiple
connections in a single client's side session with a single certificate.

Enabling "Keep-Alive" of a HTTP connection, with enclosed patch, even
when working with FCL filter may reduce the verification.

(The cause of browser crashing is out of my scope, of course :-p)

 |Please let me know if there is anything else I can test.

Tell me:
- isn't there a way to suppress the "prompt to load certificate"?
- how do you use "stunnel" which you said works without problem?
  is that works equivalently with DeleGate+SSLway?

  @ @ Yutaka Sato <>
 ( - ) National Institute of Advanced Industrial Science and Technology (AIST)
_<   >_ 1-1-4 Umezono, Tsukuba, Ibaraki, 305-8568 Japan

*** ../../delegate7.3.0/src/http.c	Fri Apr 20 16:19:05 2001
--- http.c	Mon May 14 14:59:59 2001
*** 1030,1037 ****
--- 1030,1039 ----
  			if( RX_errori )
  				clntClose(Conn,"s:bad status: %d",RX_errori);
+ /*
  			if( Conn->xf_filters & (XF_FTOCL|XF_FCL) )
  				clntClose(Conn,"x:external filter");
+ */

  admin search upper oldest olders older1 this newer1 newers latest
[Top/Up] [oldest] - [Older+chunk] - [Newer+chunk] - [newest + Check]