Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Add Intermediate an issued Certificate Server

    Scheduled Pinned Locked Moved Cache/Proxy
    9 Posts 3 Posters 812 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jirobaye
      last edited by

      Hi all, i've been made a little mistake probably i've already issued an Digicert certificate without the intermediate certificate and when i run an ssl check of course the Chain results incomplete, can i simply add it to the Certificata Data following the setup --begin-- --end-- -begin--end-- ? and then HaProxy will manage that?

      V johnpozJ 2 Replies Last reply Reply Quote 0
      • V
        viragomann @jirobaye
        last edited by

        @jirobaye
        Import both, the CA and the intermediate as a separate certificate into the CA section System > Certificate Manager > CAs.

        J 1 Reply Last reply Reply Quote 0
        • J
          jirobaye @viragomann
          last edited by

          @viragomann so i've to fill only with the Intermediate certifica the section Certificate Data and Import an existing certificate right?

          like this i've to add something in "Next Certificate Serial" or not?

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @jirobaye
            last edited by

            @jirobaye
            No, only the certificate data and a description for your reference.

            J 1 Reply Last reply Reply Quote 0
            • J
              jirobaye @viragomann
              last edited by

              @viragomann and then in HAProxy in SSL offloading i've to add something other than the actual certificat or i've in someway the intermediate?

              V 1 Reply Last reply Reply Quote 0
              • V
                viragomann @jirobaye
                last edited by

                @jirobaye
                No, nothing to do else.

                Just assign the server certificates. If one is requested HAproxy provides the whole chain automatically.

                J 1 Reply Last reply Reply Quote 0
                • J
                  jirobaye @viragomann
                  last edited by

                  @viragomann does not work, i've added the intermediate Certificate in System > Certificate Manager > Ca

                  then i've not touched anything in haproxy and i've tried an ssl check and say that the chain is still incomplete because of that

                  V 1 Reply Last reply Reply Quote 0
                  • V
                    viragomann @jirobaye
                    last edited by

                    @jirobaye
                    And what exactly is it complaining? What is it missing?

                    Ensure that you have the proper intermediate CA certificate.

                    I've it set up as I told you and the ssl test says "sent by server" for the intermediate certificate.

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator @jirobaye
                      last edited by

                      @jirobaye said in Add Intermediate an issued Certificate Server:

                      Digicert

                      What intermediate are you looking for?

                      https://www.digicert.com/kb/digicert-root-certificates.htm

                      DigiCert Customers: If you are looking for your certificate’s intermediate root, please download it from inside your DigiCert account or contact your account manager or DigiCert Support.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.