Re: Certificate chain validation

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



No, you must have a chain up to a local trust anchor.

 

You can install the intermediate in your trust store.

 

-- 

Senior Architect, Akamai Technologies

Member, OpenSSL Dev Team

IM: richsalz@xxxxxxxxx Twitter: RichSalz

 

From: Lei Kong [mailto:leikong@xxxxxxx]
Sent: Thursday, April 20, 2017 9:38 PM
To: openssl-users@xxxxxxxxxxx
Subject: Certificate chain validation

 

When validating a certificate issued by an intermediate certificate authority, I noticed that I need to install both the root and the intermediate CA certificate locally (with update-ca-certificates on ubuntu 16.04). Verification fails if only root CA cert is installed (intermediate is not installed), is this expected behavior? Why do I need to install intermediate CA cert locally? Locally installed root CA cert is not enough to validate intermediate CA cert?

 

Is it possible to make chain validation work with only root CA cert installed locally?

 

Thanks.

 

-- 
openssl-users mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-users

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Index of Archives]     [Linux ARM Kernel]     [Linux ARM]     [Linux Omap]     [Fedora ARM]     [IETF Annouce]     [Security]     [Bugtraq]     [Linux]     [Linux OMAP]     [Linux MIPS]     [ECOS]     [Asterisk Internet PBX]     [Linux API]

  Powered by Linux