PDA

View Full Version : Explicit SSL - AUTH SSL Alternative Names


ThE_-_BliZZarD
03-28-2012, 04:56 PM
Hi,

I am having a bit of trouble with my FTPS Server: It seems as FlashFXP does not evaluate the "X509v3 Subject Alternative Name" entrys while validating the server certificate... Is it a problem/misconfiguration on my end or is it a bug in FlashFXP?

To test this, you may connect to my FTP Server at ftp.philippberger.de
The certificate is valid and is displayed as valid when using the address "ftp.philippberger.de", but when using only "philippberger.de" (for which the certificate contains an alternative name entry) it gets rejected.

* FlashFXP v4.2.1, build [1745], [x]registered, [ ]unregistered, [ ]pirated <- lol
* OS [x] Windows 7, [ ] Vista, [ ] WinXP, [ ] Other (specify)
* Running behind hardware router/firewall [x] Yes & Model [AVM FritzBox 7112], [ ] No, [ ] Not sure
* Running software firewall [ ] Yes, Name [ ], Ver. [ ], or [x] No
* Running Antivirus [x] Yes, Name [Microsoft Security Essentials] or [ ] No
* Internet Connection [x] DSL, [ ] CABLE, [ ] Other(specify)

additional info if related
* FTP server(s) name [ProFTPD], version [1.3.3a]

If you require more information, please specify what you desire ;)

bigstar
03-29-2012, 04:54 PM
Hello,

Thank you for bringing this to our attention.

After investigating this issue I have determined that FlashFXP is not evaluating the subject alternative name field extension in the X509 certificate, as a result it is reporting a name mismatch.

We will do our best to get this added into our next release.

bigstar
04-26-2012, 10:19 AM
Just wanted to let everyone know that we added official support for this in FlashFXP v4.2.2 build 1760.

ThE_-_BliZZarD
04-26-2012, 11:10 AM
Thank you very much, just tested with build 1760 and everything works as expected :)