Henning Hucke wrote:
just to verify that I understand this correct: Beside checking the
validity of a client certificate with its issuing certification authority no further checks are processed by default?
Correct. And even if the cert cannot be verified the TLS handshake
is NOT aborted.
Uh! I think I'll write an appropriate rule set in the next few weeks to verify more than that! :-)
What requirements do you want to enforce?
And if you enforce them for TLS what happens when the client tries
again without a cert?
AFAICT many (most?) systems do not even present a client cert.
It doesn't seem to make much sense to penalize those which do...
IMHO it only makes sense to check certain conditions so allow a
client to do more things, e.g., get around certain other (anti-spam) requirements or allow relaying.
--
Note: please read the netiquette before posting. I will almost never
reply to top-postings which include a full copy of the previous
article(s) at the end because it's annoying, shows that the poster
is too lazy to trim his article, and it's wasting the time of all readers.
--- SoupGate-Win32 v1.05
* Origin: fsxNet Usenet Gateway (21:1/5)