Skip to content

Commit

Permalink
Document the effects of RADSECPROXY-43.
Browse files Browse the repository at this point in the history
  • Loading branch information
Linus Nordberg committed Sep 14, 2012
1 parent db965c9 commit 9885649
Showing 1 changed file with 9 additions and 0 deletions.
9 changes: 9 additions & 0 deletions radsecproxy.conf.5.xml
Original file line number Diff line number Diff line change
Expand Up @@ -544,6 +544,15 @@ blocktype name {
<literal>default</literal>. If the specified TLS block name does
not exist, or the option is not specified and none of the
defaults exist, the proxy will exit with an error.

NOTE: All versions of radsecproxy up to and including 1.6
erroneously verify client certificate chains using the CA in the
very first matching client block regardless of which block is
used for the final decision. This was changed in version 1.6.1
so that a client block with a different <literal>tls</literal>
option than the first matching client block is no longer
considered for verification of clients.

</para>
<para>
For a TLS/DTLS client, the option
Expand Down

0 comments on commit 9885649

Please sign in to comment.