1 Rookie

 • 

6 Posts

848

November 15th, 2023 21:05

Certification Chain issue

Hey All,

I'm trying to migrate OME from 3.10.2 to v4 but I'm keep getting certificate chain issue. I created a new CSR and new cert from CA server. Uploading the stand alone cert is not an issue and it shows the certificate and it works fine but I cannot upload the chain. I try to download the chain from CA as p7b file, exporting the certs and combining them as cer file (int. first and root under), I try to combine them cert+int+root non of them worked. Anyone has any idea?

Thanks

Moderator

 • 

4.1K Posts

November 16th, 2023 02:48

Hi,

 

I'm attaching the steps that resolved one of the case that I found in our database, similar to your issue. Give it a try, if it doesn't work, I may suggest contacting the OME support to check on the issue via remote.

 

In Certificate Authority, Right Click on Certificate template and click on Manage

 

Select one of the existing templates and duplicate it(I chose Web Server template), Right Click on template and Duplicate


Change the Name of the template in General tab, make sure to select the Validity and the renewal period as it suits your organization

 

Click on Extensions tab and select Application Policies -> Edit, (If the Application policies only shows Server Authentication, please make sure to click Add and select Client Authentication as well), Once both are added, click Ok


On Extensions Tab, select on Key Usage -> Edit, make sure Allow Key Exchange only with Key encryption(key encipherment) is selected


Click Ok for the new template to be created

In Certification Authority page, please right-click on the Certificate templates -> New -> Certificate template to issue and add the new certificate that was created.

 

Make sure to wait few minutes before this is reflected on the certsrv page as below

 

You don’t need to create a new template if you already have a template with both Server Authentication and Client Authentication and you wish to use it. All you have to do is to make sure the correct template is selected and create the certificate.

Once the certificate is created, download the certificate chain and upload in OME, this will upload the certificate chain without issues.

1 Rookie

 • 

6 Posts

November 16th, 2023 19:43

@DELL-Joey C​  Thank you for the help. This resolved my issue.

1 Rookie

 • 

4 Posts

November 21st, 2024 06:52

Tried the above solution, still unable to import the chain.

Should the imported chain be a .cer or .p7b? 

I've enabled logging on the appliance, and can see the errors are relating to an invalid chain - however I've checked the chain and it looks perfect. I have a root and intermediate, and then the device certificate at the end.

I am using the create CSR option to sign the certificate via our internal PKI, and then upload the signed certificate which includes our internal chain.

The certificate template I am using has both Client/Server Authentication, and the Key Enchipherment attributes.

Top