<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[(solved) SSL cert chaining w&#x2F; multiple CA files (bundled not working)?]]></title><description><![CDATA[<p dir="auto">Our Thawte SSL123 cert expired and so we renewed but now they require a chained CA file (boo) and I cannot get it to work.</p>
<p dir="auto">I have done the following (this is on 1.2.3, hdd install):</p>
<ul>
<li>downloaded pem bundled CA file from thawte article AR1372 <a href="https://search.thawte.com/support/ssl-digital-certificates/index?page=content&amp;actp=CROSSLINK&amp;id=AR1372" target="_blank" rel="noopener noreferrer nofollow ugc">1</a></li>
<li>copied above file to pfSense box and made corresponding ssl.ca-file entry in lighty-CaptivePortal-SSL.conf file per the article <a href="http://forum.pfsense.org/index.php/topic,2966.0.html" target="_blank" rel="noopener noreferrer nofollow ugc">2</a> on this forum</li>
<li>restarted lighttpd</li>
</ul>
<p dir="auto">with no luck, clients still get certificate not trusted errors.</p>
<p dir="auto">On the same Thawte article there is a link to non-bundled CA files so I'm thinking maybe lighttpd doesn't support bundled CA files but I cannot find out how to include two CA files in the lighty-CaptivePortal-SSL.conf file.</p>
<p dir="auto">Any help would be greatly appreciated (on either what I did wrong w/ the bundled version of the CA file or on how to add a second CA file to the config - I don't want to risk messing up the box so I didn't just try adding another line for the second file).</p>
<p dir="auto">Thanks in advance.</p>
]]></description><link>https://forum.netgate.com/topic/30509/solved-ssl-cert-chaining-w-multiple-ca-files-bundled-not-working</link><generator>RSS for Node</generator><lastBuildDate>Sun, 15 Mar 2026 17:51:22 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/30509.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 10 Feb 2011 18:04:29 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to (solved) SSL cert chaining w&#x2F; multiple CA files (bundled not working)? on Thu, 10 Feb 2011 19:45:30 GMT]]></title><description><![CDATA[<p dir="auto">Man, almost a whole day of messing with this and it turns out that the CA/chain file I downloaded was in DOS format (CRLF rather than just CR).  I ran it through "dos2unix" and re-copied it and all is well.  cat -v is your friend!</p>
]]></description><link>https://forum.netgate.com/post/265161</link><guid isPermaLink="true">https://forum.netgate.com/post/265161</guid><dc:creator><![CDATA[jpod]]></dc:creator><pubDate>Thu, 10 Feb 2011 19:45:30 GMT</pubDate></item></channel></rss>