Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Apache: Users

Apache proxy sending client certificate on behalf of the client

 

 

Apache users RSS feed   Index | Next | Previous | View Threaded


duarte.silva at serializing

May 28, 2012, 1:13 PM

Post #1 of 2 (196 views)
Permalink
Apache proxy sending client certificate on behalf of the client

Hi all,

I know this should be imposssible ("sounds" to me like a MITM), but bare with
me for a second and please tell me if this is in any way possible:

Client (HTTPS request) -> Apache (Forward Proxy) -> Server (HTTPS)
\___________________/
\/
Sends the client certificate on behalf of
the client


Note that the client is able to create SSL connections but it is not able to
send client certificate. Since the Apache is the one openning the connection
to the end Server, isn't there a way to force Apache to send a specific client
cert? I know the handshake is done in the Client even thought the server is
opening the connection.

If it isn't, is there any alternatives that do this? Maybe if it was a
transparent proxy?

Thanks for all your time, regards,
Duarte Silva
Attachments: smime.p7s (3.99 KB)


duarte.silva at serializing

May 31, 2012, 2:13 AM

Post #2 of 2 (176 views)
Permalink
Re: Apache proxy sending client certificate on behalf of the client [In reply to]

Nevermind, got around the problem.

Thanks anyway, regards,
Duarte

On Monday 28 May 2012 21:13:02 Duarte Silva wrote:
> Hi all,
>
> I know this should be imposssible ("sounds" to me like a MITM), but bare
> with me for a second and please tell me if this is in any way possible:
>
> Client (HTTPS request) -> Apache (Forward Proxy) -> Server (HTTPS)
> \___________________/
> \/
> Sends the client certificate on behalf of
> the client
>
>
> Note that the client is able to create SSL connections but it is not able to
> send client certificate. Since the Apache is the one openning the
> connection to the end Server, isn't there a way to force Apache to send a
> specific client cert? I know the handshake is done in the Client even
> thought the server is opening the connection.
>
> If it isn't, is there any alternatives that do this? Maybe if it was a
> transparent proxy?
>
> Thanks for all your time, regards,
> Duarte Silva
Attachments: smime.p7s (3.99 KB)

Apache users RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.