Digi-Sign, The Certificate Corporation
Published on Digi-Sign, The Certificate Corporation (http://www2.digi-sign.com)

Home > Enabling Client Authentication

By Digi-Sign
Created Feb 19 2008 - 12:32

Enabling Client Authentication

Enabling Client Certificate Authentication on Apache web server

To enable Client Certificate Authentication on Apache 1.3 you will need to obtain your own Digi-ID™ [1] Client Certificate, Certification Authority Certificate Chain (CA Chain) and setup Authentication Rules using the httpd.conf file and Apache configuration directives.

2.1 Obtaining the Digi-Sign Certification Authority Certificate Chain

Since Apache is using the SSLCACertificateFile configuration directive to point to the Certification Authority Chain for both SSL Certificates [2] and Client Certificate Authentication, assuming you have already setup this directive in step 1.2.2, you can omit this section.
If however, you have not obtained/received the ca-bundle file, you may download it from the following URLs:

CA Bundle for Digi-Acess™ setup with Digi-SSL™ Xp CA:
http://www.digi-sign.com/downloads/certificates/digi-access/BundledCAXp.pem [3]

CA Bundle for Digi-Acess™ setup with Digi-SSL™ Xs CA:
http://www.digi-sign.com/downloads/certificates/digi-access/BundledCAXs.pem [4]

  • Apache Implementation Guide

Source URL: http://www2.digi-sign.com/support/digi-access/apache-section2

Links:
[1] http://www2.digi-sign.com/digi-id
[2] http://www2.digi-sign.com/ssl+certificate
[3] http://www.digi-sign.com/downloads/certificates/digi-access/BundledCAXp.pem
[4] http://www.digi-sign.com/downloads/certificates/digi-access/BundledCAXs.pem