Uploaded image for project: 'Qpid'
  1. Qpid
  2. QPID-5356

Windows can provide an unspecified client certificate in SSL negotiation

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 0.24
    • 0.27
    • C++ Client
    • None
    • Windows, SSL

    Description

      By default, the SChannel package from Microsoft will attempt to guess an appropriate client certificate during SSL/TLS negotiation if a client certificate is requested by the server and none is supplied by the client in its credentials structure. This behavior can be changed to only work with an explicitly specified certificate (if any) by the client.

      By doing so, the behavior of clients is made more consistent across platforms and this eliminates unexpected false positives in testing.

      Attachments

        1. QPID-5356-0.patch
          4 kB
          Clifford Jansen

        Activity

          People

            cliffjansen Clifford Jansen
            cliffjansen Clifford Jansen
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: