Forum Discussion
Difference between Root Cert, Intermediate Cert and SSL Cert
1.If the server sends only its own certificate and the intermediate one then there’s no need to send the root CA certificate, as the client should already have this – otherwise the whole point of the PKI is defeated. why should we include root CA in the chain?
You're absolutely correct that the server should (normally) send all certs in the chain up to but not including the root CA. To your question, the chain or trusted certificate authorities options are for validating the client certificate and have nothing to do with the server certificate.
2.As it is mentioned each certificate is trusted by the parent one i.e server is trusted by intermediate CA and intermediate by root and finally root is trusted(cryptographically),then why can't we send root alone?
Because PKI is based on a "CHAIN OF TRUST". To your first point, the root CA cert is never sent because it requires an explicit trust mechanism - you have to manually assign trust.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
