- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-17-2020 12:09 AM
Hi
I want to use/setup a certificate profile for use with an EDL.
The site - internal running minemeld. has multiple int CA.
So for the profile, do I add only the last int CA or all of them.
How does certificate profile work will it say okay if any certificate signed by any of the ca's work ?
how can i limit it to just the last intCA... do i do that by adding in only the last ca ?
10-17-2020 09:24 PM
The certificate profile would have to include the intermediate server that actually signed the minemeld certificate, along with any other certificate that it's presenting in its certificate chain. Also you are correct, if you would want to limit this to just one intermediate CA you would only have that certificate in the certificate profile.
10-18-2020 12:26 AM
Hi
Yes did some testing.
so lets stay I have
RootCA
IntC1
IntC2
Server cert.
RooCa signs intC1 which signs intC2 which signs Server Cert.
If my cert profile only has intC2.. it fails to verify. I need RootCa + IntC1 + IntC2 for it to authenticate server Cert.
which I think is actually more of a security flaw.
if I present a leaf cert signed by intC1 it would work, but thats not my intention !
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!