TransWikia.com

Importing ca-certificate chain (.crt) - RHEL7

Server Fault Asked by daelas on December 27, 2021

I am fairly new to this but I’ve done some internet research the last 2 days and I couldn’t find an suitable answer.

I have been given a ca-certificate chain (cacertchain.crt) which I need to import to a server running RHEL7 (no GUI). The server has the ca-bundle.crt file. I have tried to put cacertchain.crt to /etc/pki/ca-trust/source/anchors/ and run update-ca-trust and update-ca-trust extract but I couldn’t see any changes to the ca-bundle.crt file.

So my question: is there a way of importing a ca-certificate chain (.crt) to RHEL7 keystore?

The certificate chain (cacertchain.crt) includes:

Root Certificate Subject CN – VeriSign Class 3 Public Primary
Certification Authority – G5 (I believe this is already available in
ca-bundle.crt)

Intermediate Certificate Subject CN – Symantec Class 3 EV SSL CA – G3

3 Answers

3 steps works for me on this cases:

  1. certificate to /etc/pki/ca-trust/source/anchors/
  2. update-ca-trust force-enable
  3. update-ca-trust extract

Answered by Judavi on December 27, 2021

I appears by including the ca-cert bundle in /etc/pki/ca-trust/source/ and running update-ca-trust extract worked fine.

Answered by daelas on December 27, 2021

Copy the certificates to /etc/pki/ca-trust/source/anchors/ and after that execute update-ca-trust extract.

They should be available to all application that check that path for certificates (for example wget and curl).

Answered by cristi on December 27, 2021

Add your own answers!

Ask a Question

Get help from others!

© 2024 TransWikia.com. All rights reserved. Sites we Love: PCI Database, UKBizDB, Menu Kuliner, Sharing RPP