[Date Prev][Date Next]
Re: web apps and client certificate authentication
Emmanuel Dreyfus wrote:
Michael Ströder<email@example.com> wrote:
Yes. However in theory the web app could run within a custom HTTP server
and intercept the SSL/TLS handshake.
In fact I thought a bit more about it and I do not think it can work: if
the HTTP server intercepts the SSL handshake and proxy it to slapd, then
the SSL connexion will be between the web browser and slapd. The HTTP
server will not be able to handle the request.
In fact we would need a double SSL handshake: one with the HTTP server
and another one with slapd, proxyied by the HTTP server. I am not even
sure it is possible.
Yes, now you see why the steps here
are necessary. You need secure handshakes between all three parties, and
secure credentials that all three parties can trust.
-- Howard Chu
CTO, Symas Corp. http://www.symas.com
Director, Highland Sun http://highlandsun.com/hyc/
Chief Architect, OpenLDAP http://www.openldap.org/project/