A new vendor has noted that we are not using a "valid cert." They are getting an invalid cert error and have sent us the following link asking if we can make any changed to resolve their problem connecting to us.
http://forum.java.sun.com/thread.jspa?threadID=304493&messageID=1224367Specifically: We have a similar problem and have traced it to the client certificate containing the NetscapeCertType extension with the SSLServer bit set but not the SSLClient bit.
The problem goes away if the NetscapeCertType SSLClient bit is set in the certificate, or if the certificate does not use the NetscapeCertType extension (uses the X509v3 standard extension "Extended Key Usage" instead)