Forum Discussion
Network Solutions EV SSL Not Trusted
Hey Guys, Ok I'm past frustrated with trying to find the correct combo to get a NS EV SSL cert to work correctly on my LTM (10.2.4). I have one client that uses NS and renewed their NS cert, but this year it's a EV SSL. The zip file he sent me came with the below files and i have yet to get the combo to work. I called NS about an intermediate cert and they told me to just append them all into one cert. They gave me the correct order to do this in and still no luck. Anybody have an idea what the correct combo is to get these to work on my LTM?
Clientcert.crt EV_NetwrokSolutionsEVServerCA2.crt EV_NetworksolutionsCertificateAuthority.crt AddTrustExternalCARoot.crt
Append Order (T->B) according to NS. Client Cert EV_NetworksolutionsCertificateAuthority.crt EV_NetwrokSolutionsEVServerCA2.crt AddTrustExternalCARoot.crt
At first i was trying just the new EV cert/key in the cert/key fields in the LTM, then i tried different combo's for the Chain and Trusted Certificate Authorities fields with the other 3 certs, with none of the combo's working. I also tried all individual EV certs located on the below URL, which had no affect...same error. Anybody have any idea's? http://www.networksolutions.com/support/where-can-i-locate-the-network-solutions-nsprotect-root-and-intermediate-certificate-files/
9 Replies
- shaggy
Nimbostratus
are you getting an error message on the F5, or is your browser throwing not-trusted errors after you update the certificate? can you share the issuer of the server certificate you received? run 'openssl x509 -text -noout | grep Issuer' - after running the command, paste your certificate text and hit 'enter' - this should result in a line similar to - 'Issuer: C=US, O=Network Solutions L.L.C., CN=Network Solutions Certificate Authority' as you mentioned, you should be able to use the server-cert+intermediate-certs+root-cert(opt.) as the certificate portion of your SSL certificate in the F5 configuration. alternately, you can simply specify the server-cert in the certificate portion of the SSL certificate file in the F5 configuration, and use the intermediate-certs+root-cert(opt.) as a certificate bundle that is specified as the "chain" in the client-SSL profile. - shifterracer_16
Nimbostratus
No errors installing the certs at all. The problem is when people go to the site they get that pop up stating the cert isn't trusted and they should not proceed. this seems to be only affecting firefox users. Also, when i go to digicert.com/help it's reporting the cert is not trusted because a intermediate cert is missing. I've tried different combo's to try to figure out what would make up the intermediate cert, none of them seem to work when i apply it to the Profile - Chain field.
- shifterracer_16
Nimbostratus
Oh the issuer is: Issuer = Network Solutions EV Server CA sorry about that.
- shifterracer_16
Nimbostratus
yeah i tried that combo Shaggy...no luck.
I also tried the NetSolEV-Post.p7b, but i couldn't install it because it's a p7b cert and it needs to be converted. F5 Import Cert error:
So to convert it i ran the following command to try to convert it.
- nitass
Employee
So i combined those and installed them into the F5 without a problem. I then tried it in the Profile -> Chain as well as in the Trusted Certificate field. Digicert still returns chain not trusted.
can you post the clientssl profile?
tmsh list ltm profile client-ssl (profile name)
what certificate are you using as a chain in the clientssl profile now? is it this one?
-----BEGIN CERTIFICATE----- MIIE8DCCA9igAwIBAgIQeqyiHVOdFFQRPARe2DX46jANBgkqhkiG9w0BAQUFADBi MQswCQYDVQQGEwJVUzEhMB8GA1UEChMYTmV0d29yayBTb2x1dGlvbnMgTC5MLkMu MTAwLgYDVQQDEydOZXR3b3JrIFNvbHV0aW9ucyBDZXJ0aWZpY2F0ZSBBdXRob3Jp dHkwHhcNMTAxMTI2MDAwMDAwWhcNMjAwNTMwMTA0ODM4WjBZMQswCQYDVQQGEwJV UzEhMB8GA1UEChMYTmV0d29yayBTb2x1dGlvbnMgTC5MLkMuMScwJQYDVQQDEx5O ZXR3b3JrIFNvbHV0aW9ucyBFViBTZXJ2ZXIgQ0EwggEiMA0GCSqGSIb3DQEBAQUA A4IBDwAwggEKAoIBAQDQNVzi55UamI/YT9bV3H5cgr+fzEv6PEqBvNrFp+mtmiaP 3BksYxI+Vt915kis40eQf18I8aOA0dDNJc1Z860uw+sGCf45JDmioezExJrXoAhV /sjFZC785waIlcE+MVpV8B2YBJS0f17ckKmhhceqErmH0aNxEQJsfpvJOevstVgn i6OYEaCrg/skMACuAlf+gOLKj0hgYznbr5Z0g7s7bO+zM8am3DHp+byqtx7I9H9Y aXLuWo82Cv4yERw0PXmIadfaMHM2aOH8EChB7mx/iAg+k3djiqrIqHvLNHAEoWw7 bUgn1D0Xugyj4Ypaqx/hcibDjiYyKNlySQ7u5XVDAgMBAAGjggGpMIIBpTAfBgNV HSMEGDAWgBQhMMn7ANdOmNqHqirQpy6xQDGnTDAdBgNVHQ4EFgQUijXkNTq8EaGe +/VPNGbVS6xMYmgwDgYDVR0PAQH/BAQDAgEGMBIGA1UdEwEB/wQIMAYBAf8CAQAw ZgYDVR0gBF8wXTBbBgRVHSAAMFMwUQYIKwYBBQUHAgEWRWh0dHA6Ly93d3cubmV0 d29ya3NvbHV0aW9ucy5jb20vbGVnYWwvU1NMLWxlZ2FsLXJlcG9zaXRvcnktZXYt Y3BzLmpzcDBSBgNVHR8ESzBJMEegRaBDhkFodHRwOi8vY3JsLm5ldHNvbHNzbC5j b20vTmV0d29ya1NvbHV0aW9uc0NlcnRpZmljYXRlQXV0aG9yaXR5LmNybDCBggYI KwYBBQUHAQEEdjB0MEsGCCsGAQUFBzAChj9odHRwOi8vY3J0LnVzZXJ0cnVzdC5j b20vTmV0d29ya1NvbHV0aW9uc0FkZFRydXN0RVZTZXJ2ZXJDQS5jcnQwJQYIKwYB BQUHMAGGGWh0dHA6Ly9vY3NwLm5ldHNvbHNzbC5jb20wDQYJKoZIhvcNAQEFBQAD ggEBADtBp7D2JBjlyHcOqAW86EhXzoEj/xeYaAGJxWmewqtFq3NMJclvdwVyEOue XnIM99N/vGMcsOVMRAGZH+He/HDjd+XY6aktld0Fz27Fx9ncL9FAfo/pR4uH2YEz pStMuS6k4ajMHGvPBDZaqqSgdDAbUSDHYblQGOS/K8P4pvqMiRYhmadaQ5kDbXTg i+qweI4gAdIpsozxeyoIsmJqMDZdXKc7Su73BzJHLfaIYgypJOBw36KmQgx7fSgF 1wtt5YT78MmIs6nZAcOcmNzLg0fs+dGeoFxdpzFSuF2wkQNvHmrv4zYC4xpdMUqQ FhvXMwUw+wCqKOtfDecUViddfLQ= -----END CERTIFICATE-----
- shifterracer_16
Nimbostratus
Here's the profile minus the key names.
ltm profile client-ssl XXXX.XXX { ca-file NS_Netsolevroot.crt cert XXXXX.crt chain NS_Chain_CA2_CA.crt ciphers DEFAULT:!ADH:!EXPORT40:!EXP:!LOW defaults-from clientssl key XXXX.key options { dont-insert-empty-fragments no-sslv2 no-sslv3 }What's the name of that cert you listed?
- nitass
Employee
What's the name of that cert you listed?
[root@ve10a:Active] config cat /var/tmp/Network_Solutions_EV_Server_CA.cer -----BEGIN CERTIFICATE----- MIIE8DCCA9igAwIBAgIQeqyiHVOdFFQRPARe2DX46jANBgkqhkiG9w0BAQUFADBi MQswCQYDVQQGEwJVUzEhMB8GA1UEChMYTmV0d29yayBTb2x1dGlvbnMgTC5MLkMu MTAwLgYDVQQDEydOZXR3b3JrIFNvbHV0aW9ucyBDZXJ0aWZpY2F0ZSBBdXRob3Jp dHkwHhcNMTAxMTI2MDAwMDAwWhcNMjAwNTMwMTA0ODM4WjBZMQswCQYDVQQGEwJV UzEhMB8GA1UEChMYTmV0d29yayBTb2x1dGlvbnMgTC5MLkMuMScwJQYDVQQDEx5O ZXR3b3JrIFNvbHV0aW9ucyBFViBTZXJ2ZXIgQ0EwggEiMA0GCSqGSIb3DQEBAQUA A4IBDwAwggEKAoIBAQDQNVzi55UamI/YT9bV3H5cgr+fzEv6PEqBvNrFp+mtmiaP 3BksYxI+Vt915kis40eQf18I8aOA0dDNJc1Z860uw+sGCf45JDmioezExJrXoAhV /sjFZC785waIlcE+MVpV8B2YBJS0f17ckKmhhceqErmH0aNxEQJsfpvJOevstVgn i6OYEaCrg/skMACuAlf+gOLKj0hgYznbr5Z0g7s7bO+zM8am3DHp+byqtx7I9H9Y aXLuWo82Cv4yERw0PXmIadfaMHM2aOH8EChB7mx/iAg+k3djiqrIqHvLNHAEoWw7 bUgn1D0Xugyj4Ypaqx/hcibDjiYyKNlySQ7u5XVDAgMBAAGjggGpMIIBpTAfBgNV HSMEGDAWgBQhMMn7ANdOmNqHqirQpy6xQDGnTDAdBgNVHQ4EFgQUijXkNTq8EaGe +/VPNGbVS6xMYmgwDgYDVR0PAQH/BAQDAgEGMBIGA1UdEwEB/wQIMAYBAf8CAQAw ZgYDVR0gBF8wXTBbBgRVHSAAMFMwUQYIKwYBBQUHAgEWRWh0dHA6Ly93d3cubmV0 d29ya3NvbHV0aW9ucy5jb20vbGVnYWwvU1NMLWxlZ2FsLXJlcG9zaXRvcnktZXYt Y3BzLmpzcDBSBgNVHR8ESzBJMEegRaBDhkFodHRwOi8vY3JsLm5ldHNvbHNzbC5j b20vTmV0d29ya1NvbHV0aW9uc0NlcnRpZmljYXRlQXV0aG9yaXR5LmNybDCBggYI KwYBBQUHAQEEdjB0MEsGCCsGAQUFBzAChj9odHRwOi8vY3J0LnVzZXJ0cnVzdC5j b20vTmV0d29ya1NvbHV0aW9uc0FkZFRydXN0RVZTZXJ2ZXJDQS5jcnQwJQYIKwYB BQUHMAGGGWh0dHA6Ly9vY3NwLm5ldHNvbHNzbC5jb20wDQYJKoZIhvcNAQEFBQAD ggEBADtBp7D2JBjlyHcOqAW86EhXzoEj/xeYaAGJxWmewqtFq3NMJclvdwVyEOue XnIM99N/vGMcsOVMRAGZH+He/HDjd+XY6aktld0Fz27Fx9ncL9FAfo/pR4uH2YEz pStMuS6k4ajMHGvPBDZaqqSgdDAbUSDHYblQGOS/K8P4pvqMiRYhmadaQ5kDbXTg i+qweI4gAdIpsozxeyoIsmJqMDZdXKc7Su73BzJHLfaIYgypJOBw36KmQgx7fSgF 1wtt5YT78MmIs6nZAcOcmNzLg0fs+dGeoFxdpzFSuF2wkQNvHmrv4zYC4xpdMUqQ FhvXMwUw+wCqKOtfDecUViddfLQ= -----END CERTIFICATE----- [root@ve10a:Active] config openssl x509 -in /var/tmp/Network_Solutions_EV_Server_CA.cer -noout -subject -issuer subject= /C=US/O=Network Solutions L.L.C./CN=Network Solutions EV Server CA issuer= /C=US/O=Network Solutions L.L.C./CN=Network Solutions Certificate Authority
- shifterracer_16
Nimbostratus
It doesn't appear i do. When i try to import that i get the following error:
- shifterracer_16
Nimbostratus
ah...you pasted it. Didn't know you could do that! that did it my friend!!!!
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com