[77179] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

OT: SSL certificate chain problems

daemon@ATHENA.MIT.EDU (Travis H.)
Wed Jan 24 16:36:59 2007

X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
Date: Tue, 23 Jan 2007 20:47:26 -0600
From: "Travis H." <travis+ml-cryptography@subspacefield.org>
To: Cryptography <cryptography@metzdowd.com>
Mail-Followup-To: Cryptography <cryptography@metzdowd.com>


--NzB8fVQJ5HfG6fxh
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Hi,

This is not really typical of the traffic on this list, hence the OT.

I send it because I think this is one of the few places where I'll
find some people with deep understanding of SSL certs.

Recently I had an issue where Google checkout would not accept an
SSL certificate because Apache didn't present the entire hierarchy,
just the site certificate itself.  The CA was Thawte.  What Google
said was that many browsers supply missing certs as needed, but
apparently their software did not.

The fix would seem to be easy; just put the right CA root cert in the
SSLCACertFile directive. or point to the directory with SSLCACertPath.
However, I've tried over and over with various root CA certs
downloaded from Thawte, and with one intermediate CA cert, and various
combinations thereof, but with no sucess.

The troubleshooting command line Google gave us was:

openssl s_client -connect www.domain.com:443 -showcerts < /dev/null

Hi,

This is not really typical of the traffic on this list, hence the OT.

I send it because I think this is one of the few places where I'll
find some people with deep understanding of SSL certs.

Recently I had an issue where Google checkout would not accept an
SSL certificate because Apache didn't present the entire hierarchy,
just the site certificate itself.  The CA was Thawte.  What Google
said was that many browsers supply missing certs as needed, but
apparently their software did not.

The fix would seem to be easy; just put the right CA root cert in the
SSLCACertFile directive. or point to the directory with SSLCACertPath.
However, I've tried over and over with various root CA certs
downloaded from Thawte, and with one intermediate CA cert, and various
combinations thereof, but with no sucess.

The troubleshooting command line Google gave us was:

openssl s_client -connect www.domain.com:443 -showcerts < /dev/null

Which shows:
depth=3D0 /C=3DUS/ST=3DCalifornia/L=3DLos Angeles/O=3DCompany, LLC/OU=3DCOM=
PANY, LLC/CN=3Dwww.domain.com
verify error:num=3D20:unable to get local issuer certificate
verify return:1
depth=3D0 /C=3DUS/ST=3DCalifornia/L=3DLos Angeles/O=3DCompany, LLC/OU=3DCOM=
PANY, LLC/CN=3Dwww.domain.com
verify error:num=3D27:certificate not trusted
verify return:1
depth=3D0 /C=3DUS/ST=3DCalifornia/L=3DLos Angeles/O=3DCompany, LLC/OU=3DCOM=
PANY, LLC/CN=3Dwww.domain.com
verify error:num=3D21:unable to verify the first certificate
verify return:1
CONNECTED(00000003)
---
Certificate chain
 0 s:/C=3DUS/ST=3DCalifornia/L=3DLos Angeles/O=3DCompany, LLC/OU=3DCOMPANY,=
 LLC/CN=3Dwww.domain.com
   i:/C=3DZA/O=3DThawte Consulting (Pty) Ltd./CN=3DThawte SGC CA
-----BEGIN CERTIFICATE-----
[...]
-----END CERTIFICATE-----
---
Server certificate
subject=3D/C=3DUS/ST=3DCalifornia/L=3DLos Angeles/O=3DCompany, LLC/OU=3DCOM=
PANY, LLC/CN=3Dwww.domain.com
issuer=3D/C=3DZA/O=3DThawte Consulting (Pty) Ltd./CN=3DThawte SGC CA
---
No client certificate CA names sent
---
SSL handshake has read 1396 bytes and written 340 bytes
---
New, TLSv1/SSLv3, Cipher is DHE-RSA-AES256-SHA
Server public key is 1024 bit
Compression: NONE
Expansion: NONE
SSL-Session:
    Protocol  : TLSv1
    Cipher    : DHE-RSA-AES256-SHA
    Session-ID: 0DD3301C8B8AF7BD3706A991475B22580AA32FCF85A141D753E2F051A69=
1ED86
    Session-ID-ctx:
    Master-Key: ...
    Key-Arg   : None
    Start Time: 1169584627
    Timeout   : 300 (sec)
    Verify return code: 21 (unable to verify the first certificate)
---
DONE

I can't seem to get that certificate chain to have any contents other
than what you see above, no matter what I do, and hence can't get rid
of the Verify return code: 21... does anyone have any advice on what
to do next?  URLs or references to other mailing lists welcome.
--=20
``Unthinking respect for authority is the greatest enemy of truth.''
-- Albert Einstein -><- <URL:http://www.subspacefield.org/~travis/>

--NzB8fVQJ5HfG6fxh
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.1 (OpenBSD)

iQIVAwUBRbbIvmQVZZEDJt9HAQKvhw//eeczFjrY+L6u8Tz1ZmnUxm4X7ZhlfuTF
j5DmUEY5fAXLop5A5IjOXH8zxorxv3dj2uv32sf88j3oYLGbPI91AZ+EjdLbLUJx
f0a3y9m6nu6klPfpXYfismuGU00nbz18Agyu4jcMvb/k6lHycDs2G2V4kh6AaYMP
eagTT+n/SSlLcQ+oeRoLwu/xgo4KO2jrCHOiDkd52BW0HNsLi/OPzAH6GgDLzb5O
MfMq3NiEplqP14vJmgcHZ/mlenJsxx1gksrfkLAUDtmL9Hwyzm1RtSy/ne+ywFlG
JFzuWZdGKLLLjOjE+EnVkCcoP+zYIdNn86f34TTSwoAwzU+vsa5ubzWSDsLowBLP
ELI2VRDZDYAG3PdXbxg5L8qaMdhVcSyPMYNyFNxW1WVkX9kMn7hahDzqCphpZxyS
R8u7+Z84db08pLOXk9eQvqVeyMXlYkW7zlCEjbL81cQoRScCyyTlTzMz/zEJY/WM
6GTJXtXQba9ZIdHJ1okMDLmb2pRzHITRgJiTdcmkhKyi0vy4oE8vk89b3G0u6W2N
kYy7WdbWL5YS17x6b4fqHiydUxyTShcMN25NE3AgxxTRhHOxjiKz9gWAKYe/eiWB
uHnzXRIM+8azCcJU9QZ1nyOcuX0rVyTCIgcdOeeuGwFN0069GNu2GST/N1SKppZ4
3T6fVTqlJ20=
=X3to
-----END PGP SIGNATURE-----

--NzB8fVQJ5HfG6fxh--

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post