Forum Discussion
Brian_Kenworthy
Nimbostratus
Jul 22, 2009Add root CA to ca-bundle?
Hi all,
VeriSign has started signing certificates with a new intermediate root CA for their PKI customers - VeriSign Class 3 Secure Server CA - G2. I do not see this certificate in the ca-bundle.crt file.
I am running LTM 9.4.7 and I was wondering if it is possible to add this root CA to the ca-bundle? I used to be able to update java's cacerts trust store with the keytool program, so maybe we can do something similar with openssl? Or should I just create a new chain altogether?
Thanks in advance for the help!!
- hoolio
Cirrostratus
Yes, you can append certs to the CA bundle, by editing it with a text editor like vi or pico. Or if you already have the new cert on the filesystem, you can use: - Brian_Kenworthy
Nimbostratus
Thanks Aaron!! I was using a single > instead of double >> and it basically overwrote all of the exisiting certificates, doh! - RYoungVail_8043
Nimbostratus
Aaron, - RYoungVail_8043
Nimbostratus
Answering my own question; F5 says the ca-bundle file is only for root CAs not intermediate CAs. - hc_andy_35682
Nimbostratus
Hi All, - nitass_89166
Noctilucent
1/ What do I use for the rootCA.crt? I don't see this file in /config/ssl/ssl.crt ??- Nath
Cirrostratus
Hi Nitass, I am a little bit confused on I put my SSL cert and rootCA and create a bundle then use this bundle to Trusted Certificate Authorities but still no luck. Do you have any suggestions Sir?
- nitass
Employee
1/ What do I use for the rootCA.crt? I don't see this file in /config/ssl/ssl.crt ??- Nath
Cirrostratus
Hi Nitass, I am a little bit confused on I put my SSL cert and rootCA and create a bundle then use this bundle to Trusted Certificate Authorities but still no luck. Do you have any suggestions Sir?
- hc_andy_35682
Nimbostratus
Thanks, ignored the openssl errors and the ssl certificate is now verified on the web site.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects