[BlueOnyx:17555] Re: Bad ca-cert stopped the apache server on 5107R

Ernie ernie at info.eis.net.au
Sun May 10 18:30:16 -05 2015


Hi Micheal,
on closer inspection it wasn't just text. The ca-cert which was uploaded,
came from Thawte and it didn't just contain the ca-cert but also
3 other certs. I think they were the site cert and the CSR or something like
that. It's a bit hard for me to tell exactly what they are.

- Ernie.


> Hi Ernie,
> 
> > I just had a web developer upload a ca-cert to their vsite but he didn't
> > check it and it had text comments in it from the CA which you are supposed to
> > edit out first.
> 
> I just checked this and cannot reproduce it.
> 
> I uploaded a valid intermediate. Worked.
> 
> I uploaded a valid intermediate with comments at the bottom. That worked
> as well and the comments were removed so that only the actual
> intermediate itself was added to the Apache config.
> 
> I uploaded a random textfile that was not an intermediate and as
> expected I got the error message that this wasn't a certificate.
> 
> So .... generally this seems to work as expected. But certainly in your
> case it didn't.
> 
> Could you please email me the intermediate (with the comments) that your
> client used to break Apache? I'd love to see what he did there and which
> usage case we didn't catch.
> 
> Please email it to me offlist - if you can - and I'll take another look.
> 
> -- 
> With best regards
> 
> Michael Stauber
> _______________________________________________
> Blueonyx mailing list
> Blueonyx at mail.blueonyx.it
> http://mail.blueonyx.it/mailman/listinfo/blueonyx

-- 
"I Ping therefore I am."



More information about the Blueonyx mailing list