The Thawte key in question is certified for signing other CAs, the
Equifax certificate is not. You have to explicitly add that level of
trust to it because they didn't get it created that way.
Taco Scargo wrote:
> I knew I could manually accept a certain CA, but what I am not understanding
> is that I need to do that.
>
> A. for www.yournic.com the chain is: Thawte (trusted in Netscape) ->
> Equifax (not listed in Netscape) -> www.yournic.com
>
> This works as expected.
>
> B. for www.nlfactory.com the chain is: Thawte (trusted in Netscape) ->
> Equifax (not listed in Netscape) -> www.yournic.com (not listed in
> Netscape)-> www.nlfactory.com
>
> I don't get why A works without any warnings and B not. Maybe Netscape is
> limited to 1 intermediate CA only?
>
> Taco
> -
> ----- Original Message -----
> From: "Schaefer,Lorrayne J." <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Sent: Tuesday, March 06, 2001 3:55 PM
> Subject: Re: Chaining CA's
>
>
>
>> Taco,
>>
>> You need to explicitly trust the CAs in your chain in Netscape. To do
>
> this,
>
>> you need to click on the Security icon, select Signers, and then edit
>
> each of
>
>> the CAs in your chain. When you edit each of the CAs, you will see three
>> checkboxes. Click on each of the check boxes to accept the CA for each of
>
> the
>
>> three items. This should resolve the problem you're experiencing. Also,
>
> you
>
>> can test to ensure this works by highlighting one of your CAs (I would
>
> pick the
>
>> intermediate CA) and click on the "verify" button. It should return with
>
> a
>
>> this CA was verified correctly message.
>>
>> Lorrayne
>>
>> Taco Scargo wrote:
>>
>>
>>> Hi,
>>>
>>> I've been experimenting a bit with signing a certificate request with my
>>> key/cert combination that was issued/certified by Equifax Secure (which
>>
> is
>
>>> certified by Thawte). I added my certified certificate to the
>>> SSLCACertificate and SSLCertificateChain files. This works fine in MSIE
>>
> and
>
>>> Opera browsers.
>>> When I view the chain in MSIE I see:
>>>
>>> Thawte->Equifax Secure->www.yournic.com (my certified
>>> certificate)->www.nlfactory.com
>>>
>>> In Netscape browsers however I get a warning that the browser does not
>>> recognise the signing authority. This probably means that Netscape does
>>
> not
>
>>> work correctly with Chained CAs.
>>> Is this correct or am I doing something wrong ?
>>>
>>> The urls to try out:
>>>
>>> https://www.yournic.com (no warning in Netscape)
>>> https://www.nlfactory.com (warning in Netscape
>>>
>>> Thanks,
>>>
>>> Taco Scargo
>>>
>>> ______________________________________________________________________
>>> Apache Interface to OpenSSL (mod_ssl) www.modssl.org
>>> User Support Mailing List [EMAIL PROTECTED]
>>> Automated List Manager [EMAIL PROTECTED]
>>
______________________________________________________________________
Apache Interface to OpenSSL (mod_ssl) www.modssl.org
User Support Mailing List [EMAIL PROTECTED]
Automated List Manager [EMAIL PROTECTED]