Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 06 Apr 2011 09:33:26 -0400
From:      "Frank J. Cameron" <cameron@ctc.com>
To:        jhell <jhell@DataIX.net>
Cc:        freebsd-security <freebsd-security@freebsd.org>
Subject:   Re: SSL is broken on FreeBSD
Message-ID:  <1302096806.3271.122.camel@linux116.ctc.com>
In-Reply-To: <20110406054537.GA2332@DataIX.net>
References:  <AANLkTin_zZgHRg7QtEwH2V8WOd=nvBcKdYvJkshGCt-R@mail.gmail.com> <BANLkTi=zOG0_tWbkAOex4ojXHdC8f-1v1w@mail.gmail.com> <1302042612.3271.100.camel@linux116.ctc.com>	<4D9BACF6.4060205@obluda.cz> <651452BB-74F3-4039-8E77-E332CC35A713@mac.com>	<4D9BBB6A.9020200@obluda.cz> <20110406054537.GA2332@DataIX.net>

next in thread | previous in thread | raw e-mail | index | archive | help
On Wed, 2011-04-06 at 01:45 -0400, jhell wrote:
> If you truss the command above before and after creating so said links
> in /usr/local/etc/ssl and in /etc/ssl youll see that there is no
> default
> CAfile or CApath searched for.

Interesting, thanks.  I don't have a FreeBSD box around at present so my
guess was just from starting with s_client.c and reading through to the
Makefile.

> s_client(1)
>    The s_client command implements a generic SSL/TLS client which
>    connects to a remote host using SSL/TLS. It is a very useful
>    diagnostic tool for SSL servers
> [...]
> Maybe there should be an emphasis on ``diagnostic''

Agreed.  From openssl(1): "s_client ... It's intended for testing
purposes only..."

------------------------------------------------------------
This message and any files transmitted within are intended
solely for the addressee or its representative and may
contain company sensitive information.  If you are not the
intended recipient, notify the sender immediately and delete
this message.  Publication, reproduction, forwarding, or 
content disclosure is prohibited without the consent of the
original sender and may be unlawful.

Concurrent Technologies Corporation and its Affiliates.
www.ctc.com  1-800-282-4392
------------------------------------------------------------



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?1302096806.3271.122.camel>