cURL / Mailing Lists / curl-users / Single Mail

curl-users

Re: SSL certificate problem

From: Ravi Dhanshetty <rdhanshetty_at_gmail.com>
Date: Fri, 30 Mar 2007 16:14:44 +0530

Thanks Eygene,

I tried this command on my linux machine, openssl has no sub command option
like -issuer_checks -verbose, please correct me if am wrong.
"openssl -issuer_checks -verbose -untrusted curl-ca-bundle.crt -CAfile
curl-ca-bundle.crt your-certificate.PEM"

thanks,
Ravi Dhanshetty

On 3/30/07, Eygene Ryabinkin <rea-curly_at_codelabs.ru> wrote:
>
> Ravi, good day.
>
> Fri, Mar 30, 2007 at 01:05:23PM +0530, Ravi Dhanshetty wrote:
> > 4.We also have trial root and intermediate CA certificates from Verisign
>
> Do you have that root and intermediate CA certificates in
> the curl-ca-bundle.crt (in a PEM format)? If yes, then try to spawn
> openssl against your client and/or server certificate:
>
> openssl -issuer_checks -verbose -untrusted curl-ca-bundle.crt -CAfile
> curl-ca-bundle.crt your-certificate.PEM
>
> I do not know how CURL processes the trust chains (not looked into the
> code yet, sorry), but the check above will help to make sure that
> the chain is good and everything is in place.
> --
> Eygene
>
Received on 2007-03-30