Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


ajobbins

5053 posts

Uber Geek
+1 received by user: 1279

Trusted

#193464 11-Mar-2016 22:05
Send private message

I have a site on my Apache server that I have secured with certificate authentication. The client certificates are signed by the CA I created with OpenSSL and the HTTPS SSL certificate is from StartSSL.

 

If I open the site in Firefox, confirm the client certificate at the prompt it works beautifully! But if I do the same in IE or Chrome, I get a generic unhelpful message in IE, and Chrome reports "ERR_SSL_CLIENT_AUTH_SIGNATURE_FAILED".

 

I've done some googling to no avail. All the responses seem to be limited to old browsers/OS that do not support TLS1.2. I can see from Firefox that the connection is working nicely with TLS1.2 so I am stumped as to why it's not working in the other browsers. If I turn the auth off in Apache the site loads on all browsers fine and passes with an A rating on SSLLabs.com

 

There is nothing in my apache error log, so it seems to be a client side error.

 

Anyone come across this before or have any ideas?





Twitter: ajobbins


View this topic in a long page with up to 500 replies per page Create new topic

This is a filtered page: currently showing replies marked as answers. Click here to see full discussion.

ajobbins

5053 posts

Uber Geek
+1 received by user: 1279

Trusted

  #1512225 13-Mar-2016 11:34
Send private message

OK I have resolved it. I'm not 100% sure this is what it was, but when I created the initial key pair for the client cert, I used 2028 bits instead of 2048 (Assume a typo in the guide I was following).

 

I generated a new cert with 2048 instead and it's all working now. Guess Windows was fussier about it than other things were.





Twitter: ajobbins


View this topic in a long page with up to 500 replies per page Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.