Re: [stunnel-users] Stunnel and configuration

This is a discussion on Re: [stunnel-users] Stunnel and configuration within the Stunnel Users forums, part of the Networking and Network Related category; On Tue, 22 Feb 2005, Bohdan Linda wrote: > CAfile = /etc/certificates/certs -file where first item is my CA &...


Go Back   Usenet Forums > Networking and Network Related > Stunnel Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-22-2005
Jan Meijer
 
Posts: n/a
Default Re: [stunnel-users] Stunnel and configuration

On Tue, 22 Feb 2005, Bohdan Linda wrote:

> CAfile = /etc/certificates/certs -file where first item is my CA
> certificate followed by list of
> all client certificates sgined by my CA.


I use the CApath = directory directive for my client certificates. The
client certificates are pointed to by hashed symlinks. Also makes it a
lot easier to remove a client certificate if you want to revoke access to
your stunnel for that particular certificate.

> cert = /etc/certificates/server.pem
> chroot = /var/run/stunnel/
> CAfile = /etc/certificates/CA/cacert.pem - only certificate of my CA
> CRLfile = /etc/certificates/crls - only certificates signed by my CA


CRL file is *not* 'only certificates signed by my CA', it stands for: do
not let any certificates *revoked* by my CA in.

Jan

--
http://www.surfnet.nl/organisatie/jame
_______________________________________________
stunnel-users mailing list
stunnel-users@mirt.net
http://stunnel.mirt.net/mailman/listinfo/stunnel-users
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 05:04 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0