mercredi 7 janvier 2015

Self signed certificats, CA and stacking



I have a server running a number of virtual hosts. I have setup as a "self-CA" and then created and signed certs for each of the virtual hosts. In running the SSL labs testing, it always complains about "incomplete, extra certs". Stacking of the site cert with the CA cert just generates an additional error of "anchor".


Should I be at all concerned with the first error? Is there really a need for me to stack those two certs? (I'm fine with "in principle yes, in reality no" if that is the case)


And if so, can I ignore the second error as it would only be relevant for an anchor that is trusted and in the browser or OS by default?





Aucun commentaire:

Enregistrer un commentaire