From 197322455d61829572d1792da03e4d0750d5638a Mon Sep 17 00:00:00 2001 From: Lutz Jänicke Date: Tue, 17 Apr 2001 13:18:56 +0000 Subject: Clarify request of client certificates. This is a FAQ. --- FAQ | 8 ++++++++ 1 file changed, 8 insertions(+) (limited to 'FAQ') diff --git a/FAQ b/FAQ index e9cc698100..019c016beb 100644 --- a/FAQ +++ b/FAQ @@ -47,6 +47,7 @@ OpenSSL - Frequently Asked Questions * Why do I get errors about unknown algorithms? * Why can't the OpenSSH configure script detect OpenSSL? * Can I use OpenSSL's SSL library with non-blocking I/O? +* Why doesn't my server application receive a client certificate? =============================================================================== @@ -519,5 +520,12 @@ requiring a bi-directional message exchange; both SSL_read() and SSL_write() will try to continue any pending handshake. +* Why doesn't my server application receive a client certificate? + +Due to the TLS protocol definition, a client will only send a certificate, +if explicitely asked by the server. Use the SSL_VERIFY_PEER flag of the +SSL_CTX_set_verify() function to enable the use of client certificates. + + =============================================================================== -- cgit v1.2.3