certificate profile

Reply
Highlighted
L4 Transporter

certificate profile

Hi

 

I want to use/setup a certificate profile for use with an EDL.

 

The site - internal running minemeld. has multiple int CA.

So for the profile, do I add only the last int CA or all of them.

How does certificate profile work will it say okay if any certificate signed by any of the ca's work ?

how can i limit it to just the last intCA... do i do that by adding in only the last ca ?

Highlighted
Cyber Elite

@Alex_Samad,

The certificate profile would have to include the intermediate server that actually signed the minemeld certificate, along with any other certificate that it's presenting in its certificate chain. Also you are correct, if you would want to limit this to just one intermediate CA you would only have that certificate in the certificate profile. 

Highlighted
L4 Transporter

Hi

Yes did some testing.

 

so lets stay I have 

RootCA

IntC1

IntC2

Server cert.

 

RooCa signs intC1 which signs intC2 which signs Server Cert.

 

If my cert profile only has intC2.. it fails to verify. I need RootCa + IntC1 + IntC2 for it to authenticate server Cert.

 

which I think is actually more of a security flaw.

if I present a leaf cert signed by intC1 it would work, but thats not my intention !

 

 

 

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!