[openssl-users] cert chain file ordering question

Norm Green norm.green at gemtalksystems.com
Tue Jan 9 23:43:57 UTC 2018


Well that is not *at all* obvious from the documentation, but ok.

What is the correct order of intermediate CA certs in the untrusted 
chain file?



On 1/9/2018 3:36 PM, Viktor Dukhovni wrote:
> The correct way to verify a chain is to put the root CA in a CAfile,
> intermediate CAs in an "untrusted" chain file, and the leaf cert all
> by itself in a separate file.



More information about the openssl-users mailing list