<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: ETOOMANYCERTS</title>
	<atom:link href="http://www.outflux.net/blog/archives/2009/01/13/etoomanycerts/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.outflux.net/blog/archives/2009/01/13/etoomanycerts/</link>
	<description>code is freedom -- patching my itch</description>
	<lastBuildDate>Fri, 12 Mar 2010 03:50:35 -0800</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: kees</title>
		<link>http://www.outflux.net/blog/archives/2009/01/13/etoomanycerts/comment-page-1/#comment-707</link>
		<dc:creator>kees</dc:creator>
		<pubDate>Wed, 14 Jan 2009 18:43:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.outflux.net/blog/?p=179#comment-707</guid>
		<description>Yeah, it seems that my problem stemmed from a misunderstanding about the proper use of &quot;CAfile&quot;.  Once the TLS extensions got enable, I got spanked.  :)  Thanks for everyone&#039;s details!</description>
		<content:encoded><![CDATA[<p>Yeah, it seems that my problem stemmed from a misunderstanding about the proper use of &#8220;CAfile&#8221;.  Once the TLS extensions got enable, I got spanked.  :)  Thanks for everyone&#8217;s details!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kurt Roeckx</title>
		<link>http://www.outflux.net/blog/archives/2009/01/13/etoomanycerts/comment-page-1/#comment-706</link>
		<dc:creator>Kurt Roeckx</dc:creator>
		<pubDate>Wed, 14 Jan 2009 18:16:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.outflux.net/blog/?p=179#comment-706</guid>
		<description>The most important change in openssl is probably enabling tls extensions.  I&#039;ve seen various reports that it breaks something, and I wouldn&#039;t be surprised if outlooks also has a problem with it.  Debian turned it on in version 0.9.8g-5, there was a security update for it (CVE-2008-1672, 0.9.8g-10.1) and then we backported a fix from 0.9.8h in 0.9.8g-13 that prevented iceweasel from connecting.  Openssl upstream has changed the default to on in their latest release (a week ago) and I&#039;ve already seen at least 2 bug reports about that since.


Kurt</description>
		<content:encoded><![CDATA[<p>The most important change in openssl is probably enabling tls extensions.  I&#8217;ve seen various reports that it breaks something, and I wouldn&#8217;t be surprised if outlooks also has a problem with it.  Debian turned it on in version 0.9.8g-5, there was a security update for it (CVE-2008-1672, 0.9.8g-10.1) and then we backported a fix from 0.9.8h in 0.9.8g-13 that prevented iceweasel from connecting.  Openssl upstream has changed the default to on in their latest release (a week ago) and I&#8217;ve already seen at least 2 bug reports about that since.</p>
<p>Kurt</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Simon Josefsson</title>
		<link>http://www.outflux.net/blog/archives/2009/01/13/etoomanycerts/comment-page-1/#comment-705</link>
		<dc:creator>Simon Josefsson</dc:creator>
		<pubDate>Wed, 14 Jan 2009 13:19:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.outflux.net/blog/?p=179#comment-705</guid>
		<description>Trusting tons of CA&#039;s is the root problem here, I think.  If you do not use client authentication and accept client certificates signed by all of these CAs, removing the CAs is the right thing to do.  I think what changed between Hardy and Intrepid was likely the ca-certificates package.  Perhaps the default was to not trust many CAs before, and this changed recently?</description>
		<content:encoded><![CDATA[<p>Trusting tons of CA&#8217;s is the root problem here, I think.  If you do not use client authentication and accept client certificates signed by all of these CAs, removing the CAs is the right thing to do.  I think what changed between Hardy and Intrepid was likely the ca-certificates package.  Perhaps the default was to not trust many CAs before, and this changed recently?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mirabilos</title>
		<link>http://www.outflux.net/blog/archives/2009/01/13/etoomanycerts/comment-page-1/#comment-704</link>
		<dc:creator>mirabilos</dc:creator>
		<pubDate>Wed, 14 Jan 2009 09:17:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.outflux.net/blog/?p=179#comment-704</guid>
		<description>Hi, please see the second part of https://www.mirbsd.org/permalinks/wlog-10_e20090114-tg.htm
for an answer which might be able to help.

A fellow DM</description>
		<content:encoded><![CDATA[<p>Hi, please see the second part of <a href="https://www.mirbsd.org/permalinks/wlog-10_e20090114-tg.htm" rel="nofollow">https://www.mirbsd.org/permalinks/wlog-10_e20090114-tg.htm</a><br />
for an answer which might be able to help.</p>
<p>A fellow DM</p>
]]></content:encoded>
	</item>
</channel>
</rss>
