[stunnel-users] stunnel not seeing ca bundle files

This is a discussion on [stunnel-users] stunnel not seeing ca bundle files within the Stunnel Users forums, part of the Networking and Network Related category; --===============0807205773== Content-Type: multipart/alternative; boundary="----=_Part_2227_22143489.1205300791939" ------=_Part_2227_22143489.1205300791939 Content-Type: text/plain; charset=ISO-8859-1 ...


Go Back   Usenet Forums > Networking and Network Related > Stunnel Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 03-12-2008
sf.techguy@gmail.com
 
Posts: n/a
Default [stunnel-users] stunnel not seeing ca bundle files

--===============0807205773==
Content-Type: multipart/alternative;
boundary="----=_Part_2227_22143489.1205300791939"

------=_Part_2227_22143489.1205300791939
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

I'm running stunnel 4.14 on Darwin 7.0.0 (Mac OS X Server 10.4.11), with
OpenSSL 0.9.71.

I purchased a security certificate from comodo, and was able to get it
installed and working (mostly) with stunnel, but when I browse to the
website, I get an error that the the browser can't verify the identity of
the site, due to a problem w/the security cert.

I called comodo, and they the error is caused by stunnel not seeing the
intermediate certificate files that they told me need to be installed in
order for their certificate to work. These files were:

ComodoUTNServerCA.crt
UTNAddTrustServerCA.crt
AddTrustExternalCARoot.crt
EssentialSSLCA.crt
my_server_net.crt

I modified stunnel.conf, and included this line:

CApath = ca-certs/ (<- dir path, relative to chroot, containing above files)

But the error persists. Can anyone tell me if what comodo support is telling
me is even correct? I've verified that my .key and .crt files match by
running:

$ openssl x509 -noout -modulus -in server.crt | openssl md5
$ openssl rsa -noout -modulus -in server.key | openssl md5

And the output of both matches. Not sure what to try next.

Any help much appreciated!

Thanks in advance...

------=_Part_2227_22143489.1205300791939
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

I'm running stunnel 4.14 on Darwin 7.0.0 (Mac OS X Server 10.4.11), with OpenSSL 0.9.71.<br><br>I purchased a security certificate from comodo, and was able to get it installed and working (mostly) with stunnel, but when I browse to the website, I get an error that the the browser can't verify the identity of the site, due to a problem w/the security cert.<br>
<br>I called comodo, and they the error is caused by stunnel not seeing the intermediate certificate files that they told me need to be installed in order for their certificate to work. These files were:<br><br>ComodoUTNServerCA.crt<br>
UTNAddTrustServerCA.crt<br>AddTrustExternalCARoot. crt<br>EssentialSSLCA.crt<br>my_server_net.crt<br> <br>I modified stunnel.conf, and included this line:<br><br>CApath = ca-certs/ (&lt;- dir path, relative to chroot, containing above files)<br>
<br>But the error persists. Can anyone tell me if what comodo support is telling me is even correct? I've verified that my .key and .crt files match by running:<br><br>$ openssl x509 -noout -modulus -in server.crt | openssl md5<br>
$ openssl rsa -noout -modulus -in server.key | openssl md5<br><br>And the output of both matches. Not sure what to try next.<br><br>Any help much appreciated!<br><br>Thanks in advance...<br><br>

------=_Part_2227_22143489.1205300791939--

--===============0807205773==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
stunnel-users mailing list
stunnel-users@mirt.net
http://stunnel.mirt.net/mailman/listinfo/stunnel-users

--===============0807205773==--
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 02:41 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0