Example of a list of certificates sent to the client
The client receives a list of certificates from the server that the client uses when determining which certificates to respond with. This list of certificates is sent at the end of the servers hello reply.
The client uses this list to scan its truststore for a certificate that is an exact match (for example, a self-signed certificate), or for a certificate that is signed by one of these certificates. If no match is found, no certificate is sent and the login fails.
*** CertificateRequest
Cert Types: RSA, DSS, ECDSA
Cert Authorities:
<C=TX, O="BMC Software, Inc.", OU=AtriumSSO, CN=GoodSSO>
<CN=DOD CA-16, OU=PKI, OU=DoD, O=U.S. Government, C=US>
<CN=BIRGER.CHET.1160156917, OU=USA, OU=PKI, OU=DoD, O=U.S. Government, C=US>
<CN=iBMC-JBHBBK1.adprod.bmc.com, O=BMC Software, OU=AtriumSSO Server>
<CN=Atrium SSO Internal LDAP, OU=Atrium SSO, O="BMC Software, Inc.", L=Austin, ST=TX, C=US>
*** ServerHelloDone
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*