<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CSS11501 and client certificate processing in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/css11501-and-client-certificate-processing/m-p/383247#M6713</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what's your version ?&lt;/P&gt;&lt;P&gt;Are you re-encrypting traffic in the backend ?&lt;/P&gt;&lt;P&gt;Or ar you using the header insert feature ?&lt;/P&gt;&lt;P&gt;What is your config ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do not think we touch the certificate.&lt;/P&gt;&lt;P&gt;We simply forward it as we receive it.&lt;/P&gt;&lt;P&gt;But I can verify.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 06 Mar 2005 10:58:05 GMT</pubDate>
    <dc:creator>Gilles Dufour</dc:creator>
    <dc:date>2005-03-06T10:58:05Z</dc:date>
    <item>
      <title>CSS11501 and client certificate processing</title>
      <link>https://community.cisco.com/t5/application-networking/css11501-and-client-certificate-processing/m-p/383246#M6712</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;I use CSS 11501 to accelerate ssl sessions and autheticate users.&lt;/P&gt;&lt;P&gt;CSS gets the certificate from the client browser. The certificate DN contains for example:&lt;/P&gt;&lt;P&gt;"CN=info1, SERIALNUMBER=REGON: 321123321, OU=info2, O=info3, C=PL".&lt;/P&gt;&lt;P&gt;The CSS sends the certificate to beckend servers as:&lt;/P&gt;&lt;P&gt;"C=PL, O=info3, OU=info2 ADR, SN=REGON: 321123321, CN=info1".&lt;/P&gt;&lt;P&gt;There are two incorrect things:&lt;/P&gt;&lt;P&gt;1. The order of attributes in DN is reversed. This is not compliant with RCF 1779.&lt;/P&gt;&lt;P&gt;2. SERIALNUMBER is replaced to SN string.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How to resolve this problem ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2005 21:42:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css11501-and-client-certificate-processing/m-p/383246#M6712</guid>
      <dc:creator>robert</dc:creator>
      <dc:date>2005-03-04T21:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: CSS11501 and client certificate processing</title>
      <link>https://community.cisco.com/t5/application-networking/css11501-and-client-certificate-processing/m-p/383247#M6713</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what's your version ?&lt;/P&gt;&lt;P&gt;Are you re-encrypting traffic in the backend ?&lt;/P&gt;&lt;P&gt;Or ar you using the header insert feature ?&lt;/P&gt;&lt;P&gt;What is your config ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do not think we touch the certificate.&lt;/P&gt;&lt;P&gt;We simply forward it as we receive it.&lt;/P&gt;&lt;P&gt;But I can verify.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 06 Mar 2005 10:58:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css11501-and-client-certificate-processing/m-p/383247#M6713</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2005-03-06T10:58:05Z</dc:date>
    </item>
  </channel>
</rss>

