Quantcast
Channel: Ignite Realtime : Unanswered Discussions - Support
Viewing all articles
Browse latest Browse all 4979

SSL chaining cert not being passed to clients

$
0
0

So, I've followed several of the myriad of tutorials on importing a signed SSL cert and its corresponding key into openfire. After getting the chain certs imported into truststore and my cert/key pair imported into keystore, I have basic SSL working. However, clients are complaining that the certificate is untrusted. When I connect to port 5223 using openssl s_client, it appears that the server is not passing the chaining certificate to clients:

 

 

: jmalone@agrajag.cv; openssl s_client -connect im2.nrao.edu:5223

CONNECTED(00000003)

depth=2 /C=US/ST=Arizona/L=Scottsdale/O=GoDaddy.com, Inc./CN=Go Daddy Root Certificate Authority - G2

verify error:num=19:self signed certificate in certificate chain

verify return:0

---

Certificate chain

0 s:/OU=Domain Control Validated/CN=*.nrao.edu

   i:/C=US/ST=Arizona/L=Scottsdale/O=GoDaddy.com, Inc./OU=http://certs.godaddy.com/repository//CN=Go Daddy Secure Certificate Authority - G2

1 s:/C=US/ST=Arizona/L=Scottsdale/O=GoDaddy.com, Inc./OU=http://certs.godaddy.com/repository//CN=Go Daddy Secure Certificate Authority - G2

   i:/C=US/ST=Arizona/L=Scottsdale/O=GoDaddy.com, Inc./CN=Go Daddy Root Certificate Authority - G2

2 s:/C=US/ST=Arizona/L=Scottsdale/O=GoDaddy.com, Inc./CN=Go Daddy Root Certificate Authority - G2

   i:/C=US/ST=Arizona/L=Scottsdale/O=GoDaddy.com, Inc./CN=Go Daddy Root Certificate Authority - G2

---

Server certificate

-----BEGIN CERTIFICATE-----

<snip>

-----END CERTIFICATE-----

subject=/OU=Domain Control Validated/CN=*.nrao.edu

issuer=/C=US/ST=Arizona/L=Scottsdale/O=GoDaddy.com, Inc./OU=http://certs.godaddy.com/repository//CN=Go Daddy Secure Certificate Authority - G2

---

No client certificate CA names sent

---

SSL handshake has read 4227 bytes and written 288 bytes

---

New, TLSv1/SSLv3, Cipher is EDH-RSA-DES-CBC3-SHA

Server public key is 2048 bit

Secure Renegotiation IS supported

Compression: NONE

 

A proper session to a server that presents my chaining cert looks like:

 

Certificate chain

0 s:/OU=Domain Control Validated/CN=*.nrao.edu

   i:/C=US/ST=Arizona/L=Scottsdale/O=GoDaddy.com, Inc./OU=http://certs.godaddy.com/repository//CN=Go Daddy Secure Certificate Authority - G2

1 s:/C=US/ST=Arizona/L=Scottsdale/O=GoDaddy.com, Inc./OU=http://certs.godaddy.com/repository//CN=Go Daddy Secure Certificate Authority - G2

   i:/C=US/ST=Arizona/L=Scottsdale/O=GoDaddy.com, Inc./CN=Go Daddy Root Certificate Authority - G2

2 s:/C=US/ST=Arizona/L=Scottsdale/O=GoDaddy.com, Inc./CN=Go Daddy Root Certificate Authority - G2

   i:/C=US/O=The Go Daddy Group, Inc./OU=Go Daddy Class 2 Certification Authority

3 s:/C=US/O=The Go Daddy Group, Inc./OU=Go Daddy Class 2 Certification Authority

   i:/C=US/O=The Go Daddy Group, Inc./OU=Go Daddy Class 2 Certification Authority

 

Is there any way to coax Openfire into sending the chaining certificates during the handshake?


Viewing all articles
Browse latest Browse all 4979

Trending Articles