Posted: Mon Jun 09, 2014 3:26 am Post subject: Certificate chain - two different root certificates
Novice
Joined: 19 Mar 2009 Posts: 20 Location: Prague
Hello,
one of our WS supplier will change CA from its own to VeriSign.
Supplier support people sent us certificates and certifiacate chain looks like this:
- VeriSignClass 3 Public Primary Certification Authority (PCA3 G1 SHA1) -- ROOT
-- VeriSign Class 3 Public Primary Certification Authority - G5 - inter
--- Symantec Class 3 Secure Server CA -G4 - inter
We already have certificate VeriSign Class 3 Public Primary Certification Authority - G5 in our truststore. But our is issued as ROOT certificate (issued by and issued for is the same).
Supplier's server will send both G5 and G4 (they are intermediate for him) during SSL handshake and we are not sure how WMB handle it.
Do we have to import VerSignClass 3 Public Primary Certification Authority (PCA3 G1 SHA1), which is suppliers ROOT CA into our truststore or WMB checks first intermediate (G4) against trustore and it passes because we have G5 as root?
Wonder how you got the G5 as root?
Anyways the G5 root and G5 inter are 2 different certs... so yes you will need the full chain... _________________ MQ & Broker admin
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum