Re: Issue 650, SSL certificate authority validation questions
From: <jerenkrantz_at_apache.org>
Date: 2003-01-25 01:57:53 CET
--On Friday, January 24, 2003 16:58:01 -0700 David Waite mass@akuma.org
I'm trying to tackle issue 650, starting with SSL server certificate
Cool. (Ditto on CRLs. If someone wants 'em, they can add support.)
I assume all of these should be in the servers file. Other than names
I think the CA options you have listed would be system wide rather than per
- should ssl-authorities-file have a default if not specified? If so,
Yes, I think so. ~/.subversion/certs/ sounds like a reasonable starting
Perhaps you could do some registry entries on Win32, but I've seen Brane
- should ignore-ssl-host-mismatch allow you to specify an alternate
I don't think so. An 'alternate-ssl-host-name' per-server option might be
- should there be prompting on the above errors?
My hunch is no, but it should print out a warning at the very least.
I would also probably suggest that you do this on a branch rather than
---------------------------------------------------------------------
|
This is an archived mail posted to the Subversion Dev mailing list.
This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.