SSL certificate chains

1向2飛發表於2017-11-30
    Some browsers may complain(抱怨) about a certificate signed by a well-known certificate authority, while other browsers may accept the certificate without issues. This occurs because the issuing authority has signed the server certificate using an intermediate certificate that is not present(出現) in the certificate base of well-known trusted(信任) certificate authorities which is distributed(釋出) with a particular browser. In this case the authority provides a bundle of(一束) chained certificates which should be concatenated(連線) to the signed server certificate. The server certificate must appear before the chained certificates in the combined file:
解釋:
        某些瀏覽器有時可能會抱怨知名證書頒發機構簽名的證書,但是另一些瀏覽器可能會接受改證書而不會產生任何問題。產生該問題的原因就是證書頒發機構採用了“中間證書”來
作為伺服器認證,但是該中間證書卻沒有包含在知名證書頒發機構對特定瀏覽器頒發的可信任基證書庫中。解決方案就是權威證書頒發機構提供一系列的“chained certificates”,
這些鏈證書被連結用於簽名伺服器認證。在同一個證書檔案中 “伺服器證書” 必須出現在 “chained certificates”的前面。
參考:http://lukejin.iteye.com/blog/587200
生產實際使用:

來自 “ ITPUB部落格 ” ,連結:http://blog.itpub.net/23890223/viewspace-2148071/,如需轉載,請註明出處,否則將追究法律責任。

相關文章