LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 12-06-2011, 07:03 PM   #1
4Paul4
Member
 
Registered: Jul 2011
Posts: 51

Rep: Reputation: Disabled
SSL Intermediate Chain warning


I have paid for a wildcard certificate and installed it on a SQUID reverse proxy.

If I go to https://my.website.com in IE9, it's fine and no warning pop up.

If I try to do this in any other browser, I get warnings (at the bottom of this post)

I ran this test:
http://www.sslshopper.com/ssl-checke...sites.com/blah and got the following:

Code:
my.website.com resolves to 50.xx.xxx.xx

 	Server Type: squid/3.0.STABLE26

 		The certificate will expire in 363 days. 	Remind me


 	The hostname (my.websites.com) is correctly listed in the certificate.

 	The certificate is not trusted in all web browsers. You may need to install an Intermediate/chain certificate to link it to a trusted root certificate. Learn more about this error. The fastest way to fix this problem is to contact your SSL provider.

I guess I need to install these intermediate/chain certificate links on my Squid3 server right? Unfortunately the website doesn't have instructions for SQUID.
https://support.comodo.com/index.php...d=1&nav=0,96,1

Any ideas?

Warnings:

Firefox:
Code:
my.websites.com uses an invalid security certificate. The certificate is not trusted because no issuer chain was provided. (Error code: sec_error_unknown_issuer)

Opera:
Code:
Site not secure: The connection to my.website.com is not secure.  The server attempted to apply security measures, but failed.
Chrome:
Code:
You connection to <ommitted> is encrypted, however this pages includes resources which are not secure.
 
Old 12-06-2011, 07:41 PM   #2
klearview
Member
 
Registered: Aug 2006
Location: London
Distribution: Debian, Kubuntu
Posts: 572

Rep: Reputation: 75
Simply append your intermediate certificate to the same file.
 
1 members found this post helpful.
Old 12-06-2011, 08:54 PM   #3
4Paul4
Member
 
Registered: Jul 2011
Posts: 51

Original Poster
Rep: Reputation: Disabled
I had tried that and it failed.

I fixed the problem. Turns out Copy/Paste from notepad into an RDP session on a remote server running putty which was connected to the squid server must have put some bad characters in it.

I sftp'd the certificates and appended them and ran:
Code:
cat cert.pem >> bundle.crt
Problem solved. Thanks for the reply.
 
Old 08-10-2012, 11:59 AM   #4
ggalan
Member
 
Registered: Oct 2010
Posts: 57

Rep: Reputation: 0
I am having the same issue but im not understanding your fix

can someone explain this please
thank you
 
Old 08-12-2012, 06:39 PM   #5
chrism01
LQ Guru
 
Registered: Aug 2004
Location: Sydney
Distribution: Rocky 9.2
Posts: 18,360

Rep: Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751
MS and Linux have different line-ending conventions ... eg http://linux.die.net/man/1/dos2unix
 
Old 08-13-2012, 01:33 AM   #6
4Paul4
Member
 
Registered: Jul 2011
Posts: 51

Original Poster
Rep: Reputation: Disabled
If you copy from notepad++ rather than notepad, the line ending problem does not occur.
 
Old 01-13-2015, 08:09 PM   #7
!! hack-back !!
Member
 
Registered: Nov 2009
Posts: 183

Rep: Reputation: 2
any one here face this issue , i have same but cant solve !
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Looking for Intermediate Distribution gh4ever Linux - General 15 12-14-2010 12:39 AM
how to import SSL CA chain in my linux ? kachijs Linux - Security 1 07-02-2009 04:24 AM
iptables good packet chain (instead of bad packet chain) win32sux Linux - Security 6 11-06-2008 06:02 AM
SSL Certificate Warning help me karthi26 Linux - Server 3 03-18-2008 08:14 AM
Intermediate user NicholasA LinuxQuestions.org Member Intro 2 08-03-2007 11:02 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 06:26 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration