Forum Discussion
Brian_Kenworthy
Nimbostratus
Jul 22, 2009Add root CA to ca-bundle?
Hi all,
VeriSign has started signing certificates with a new intermediate root CA for their PKI customers - VeriSign Class 3 Secure Server CA - G2. I do not see this certificate in the...
hc_andy_35682
Nimbostratus
Sep 13, 2011Hi All,
Two quick questions in relation to adding the intermediate CA bundle to the F5?
I've followed the instructions for sol6401 but am a bit lost at the part where they go:
cat intermediateCA_1.crt intermediateCA_2.crt rootCA.crt > chain.crt
1/ What do I use for the rootCA.crt? I don't see this file in /config/ssl/ssl.crt ??
2/ The rootCA is suppose to be optional, so I've tried it without using the rootCA but when I run that against the site's crt, I get this error:
[root] ssl.crt openssl verify -purpose sslserver -CAfile chain.crt mysite.crt
mysite.crt: /C=US/O=VeriSign, Inc./OU=VeriSign Trust Network/OU=(c) 2006 VeriSign, Inc. - For authorized use only/CN=VeriSign Class 3 Public Primary Certification Authority - G5
error 2 at 2 depth lookup:unable to get issuer certificate
Does that error message mean anything? I found some other forums where some users just ignored this error and their site still functioned ok.
Help please...
Thanks.
Andy
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects