[stunnel-users] Stunnel and configuration

This is a discussion on [stunnel-users] Stunnel and configuration within the Stunnel Users forums, part of the Networking and Network Related category; Hi all, I have configured stunnel to do the client authetication, but I have some question. I have used following ...


Go Back   Usenet Forums > Networking and Network Related > Stunnel Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-22-2005
Bohdan Linda
 
Posts: n/a
Default [stunnel-users] Stunnel and configuration

Hi all,

I have configured stunnel to do the client authetication, but I have
some question.

I have used following config:

cert = /etc/certificates/server.pem - file with signed
server cert and key
(passwordless)

chroot = /var/run/stunnel/

CAfile = /etc/certificates/certs -file where first item is my
CA certificate followed by list of
all client certificates sgined by my CA.

setuid = nobody
setgid = nogroup
pid = /stunnel.pid
verify = 3

This setup is working, but this seems to me very "unlogical".
If I create for me "more logic" setup:

cert = /etc/certificates/server.pem
chroot = /var/run/stunnel/
CAfile = /etc/certificates/CA/cacert.pem - only certificate of my CA
CRLfile = /etc/certificates/crls - only certificates signed by my CA

I get the following error:
2005.02.22 15:15:10 LOG5[22418:81926]: VERIFY OK: depth=1, /C= .....
2005.02.22 15:15:10 LOG4[22418:81926]: VERIFY ERROR ONLY MY: no cert for /C=


The question is ... why? Why CAfile has to contain all client
certificates, when clients certs are not CA? Why I cannot have separate
file for CA and separate file for certificates that I want accept? If I
do the similar setup in mod_ssl, the configuration works as expected.

Anyway, I'am newbie to deploy stunnel, thus I would like to ask you for
giving me you opinion of this configuration, caveats and possible
enhancements.

Thanks for any comments,
Bohdan Linda
_______________________________________________
stunnel-users mailing list
stunnel-users@mirt.net
http://stunnel.mirt.net/mailman/listinfo/stunnel-users
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 08:14 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0