[Help-gnutls] Key usage violation in certificate

Joe Orton joe at manyfish.co.uk
Tue Nov 4 10:25:09 CET 2008


On Tue, Nov 04, 2008 at 08:25:50AM +0200, Nikos Mavrogiannopoulos wrote:
> Kevin P. Fleming wrote:
> > Nikos Mavrogiannopoulos wrote:
> > 
> >> It seems gnutls fails because the (client) certificate it uses for
> >> authentication it doesn't support signing (and TLS client certificates
> >> must support it).
...
> Could it be then that libneon selected a wrong certificate from the
> pkcs12 file?

I'm missing some context here, but current neon releases can indeed do 
that, this is a known neon bug, see:

http://lists.manyfish.co.uk/pipermail/neon/2008-October/000086.html

> Does it use gnutls_certificate_set_x509_simple_pkcs12_file()?

Just for the record - neon doesn't use that function, no.

Regards, Joe





More information about the Gnutls-devel mailing list