[77261] in cryptography@c2.net mail archive
Re: OT: SSL certificate chain problems
daemon@ATHENA.MIT.EDU (Erik Tews)
Thu Jan 25 14:01:24 2007
X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
From: Erik Tews <erik@debian.franken.de>
To: "Travis H." <travis+ml-cryptography@subspacefield.org>
Cc: Cryptography <cryptography@metzdowd.com>
In-Reply-To: <20070124024726.GA20273@subspacefield.org>
Date: Wed, 24 Jan 2007 23:53:15 +0100
--=-uXfOdik1/RSdwSZNegae
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable
Am Dienstag, den 23.01.2007, 20:47 -0600 schrieb Travis H.:
> Verify return code: 21 (unable to verify the first certificate)
> ---
> DONE
>=20
> I can't seem to get that certificate chain to have any contents other
> than what you see above, no matter what I do, and hence can't get rid
> of the Verify return code: 21... does anyone have any advice on what
> to do next? URLs or references to other mailing lists welcome.
Did you try -CAfile, with this command you can give s_client a file with
CAs you trust. If the Thawte Consulting certificate is in this file, you
should have no problems with verifying.
--=-uXfOdik1/RSdwSZNegae
Content-Type: application/pgp-signature; name=signature.asc
Content-Description: Dies ist ein digital signierter Nachrichtenteil
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQBFt+Nb1V7s4RB7CAcRAlF/AJ9SCBwpKsObmg3vZhMOtQd/fudeQACeNdGB
Rcl6I7Us0XmpSLUvksOEF3A=
=X1i5
-----END PGP SIGNATURE-----
--=-uXfOdik1/RSdwSZNegae--
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com