Discussion:
[devinfo] Basic selfcertified SSL Certifcate produces Errors?
r***@vielnascher.net
2017-10-05 11:44:09 UTC
Permalink
Hi Everybody,

I have one Server named "tegea.at" and there is no special SSL Certificate
Module installed .. pure SME 9.2, last Version

But when i try to open the URL https://www.tegea.at .. i get this error from
the Browser:

NET::ERR_CERT_AUTHORITY_INVALID
Subject: www.tegea.at
Issuer: www.tegea.at
Expires on: 12.12.2017
Current date: 05.10.2017
PEM encoded chain:
-----BEGIN CERTIFICATE-----
MIID6DCCAtCgAwIBAgIEWE4IJTANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMC
LS0xDTALBgNVBAgMBC0tLS0xDzANBgNVBAcMBk90dGF3YTEYMBYGA1UECgwPWFla
IENvcnBvcmF0aW9uMQ0wCwYDVQQLDARNYWluMRUwEwYDVQQDDAx3d3cudGVnZWEu
YXQxHTAbBgkqhkiG9w0BCQEWDmFkbWluQHRlZ2VhLmF0MB4XDTE2MTIxMjAyMTUw
MVoXDTE3MTIxMjAyMTUwMVowgYwxCzAJBgNVBAYTAi0tMQ0wCwYDVQQIDAQtLS0t
MQ8wDQYDVQQHDAZPdHRhd2ExGDAWBgNVBAoMD1hZWiBDb3Jwb3JhdGlvbjENMAsG
A1UECwwETWFpbjEVMBMGA1UEAwwMd3d3LnRlZ2VhLmF0MR0wGwYJKoZIhvcNAQkB
Fg5hZG1pbkB0ZWdlYS5hdDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEB
ANJdQ05OQ0hMrIffMCWP+FaRa/HxozXnl3oZnWw47hx/bgKqr+X03+dvj2aJprw+
v7LHk2eF3QoIeuergdoJZNkLFWVgFuQrfv/ezmDetO+ml3aSRUqrsK0g/f32T6Ld
VnyYvs5gJePYXMNZ/s+hufvf0l5dv5ZbcpEXPeU5/BpOnLBK7n10af8+cITbiFle
Gywq2DC7CjsI06L+xYNVsmqwilakRtAspYmsmfOXPTuMF0uYL1dbqG6hcjAd9IKK
aR7Ux42NfQgYqzQ2FYK4301RwQ+W3PHETbVzQt7MbUWkKH3ehDSXTeQwmtIJphZt
a+9YTzU6/JN6xUsvXDGHt9sCAwEAAaNQME4wHQYDVR0OBBYEFL0Twcyi0/Fi2uow
B2iGIEOAPaNfMB8GA1UdIwQYMBaAFL0Twcyi0/Fi2uowB2iGIEOAPaNfMAwGA1Ud
EwQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAK4L6Edv3r31z4HtNwyG1HsVTPPp
G++qLZF139+0GH/Y3pHrhicYA8PCw0FEOeCCpE0kH69IvbRF0mQkHQ4lIe+MYDLe
h0P/n699vJ1bM8BPn/caWeKSKhbq5yTg9FkQ9bSxLQ0mWztO30tanzUUzdvMz/no
l+rwAP2GTAMkcyFVzO8FEfz/0EyB94Z0AW/MhDrtHUkSyVLhPRCR16zsu1yetihh
YETogdjOflMuou/BdCDit3aA2ocdLqUT4t4pGHsAOkOjY+UE88StpITSLCnWvco9
pijvIX6ml90w1rRMc9EQ3TggyYS7xrueeuXi8I9RFs+p9y6wR+tCbuDDXpo=
-----END CERTIFICATE-----


See yourself: https://www.tegea.at
Is this a BUG? Or am i doing something wrong?
Best
Rudi



_______________________________________________
Server Development Discussion
To unsubscribe, e-mail devinfo-***@lists.contribs.org
Searchable archive at https://lists.contribs.org/mailman/public/devinfo/
Daniel Berteaud
2017-10-05 11:59:46 UTC
Permalink
Post by r***@vielnascher.net
Hi Everybody,
I have one Server named "tegea.at" and there is no special SSL
Certificate Module installed .. pure SME 9.2, last Version
But when i try to open the URL https://www.tegea.at .. i get this
NET::ERR_CERT_AUTHORITY_INVALID
[...]
Post by r***@vielnascher.net
See yourself: https://www.tegea.at
Is this a BUG? Or am i doing something wrong?
The default SSL certificate is self-signed, which means it won't be
recognized as a valid cert out of the box (there are many reasons we
can't provide completely OOB a valid certificate). But you can either:

* Buy a trusted certificate (be it simple or wildcard)
* Get a trusted certificate for free using Let's Encrypt

You'll find info on the wiki on how to do this. Check
https://wiki.contribs.org/Letsencrypt


++
--
Logo FWS

*Daniel Berteaud*

FIREWALL-SERVICES SAS.
Société de Services en Logiciels Libres
Tel : 05 56 64 15 32 <tel:0556641532>
Visio : http://vroom.fws.fr/dani
/www.firewall-services.com/
r***@vielnascher.net
2017-10-05 12:19:03 UTC
Permalink
that was helpful ..
going straight there ..
Thanks,
Rudi



From: Daniel Berteaud
Sent: Thursday, October 05, 2017 1:59 PM
To: ***@lists.contribs.org
Subject: Re: [devinfo] Basic selfcertified SSL Certifcate produces Errors?





Le 05/10/2017 à 13:44, ***@vielnascher.net a écrit :

Hi Everybody,

I have one Server named "tegea.at" and there is no special SSL Certificate Module installed .. pure SME 9.2, last Version

But when i try to open the URL https://www.tegea.at .. i get this error from the Browser:

NET::ERR_CERT_AUTHORITY_INVALID

[...]

See yourself: https://www.tegea.at
Is this a BUG? Or am i doing something wrong?


The default SSL certificate is self-signed, which means it won't be recognized as a valid cert out of the box (there are many reasons we can't provide completely OOB a valid certificate). But you can either:

a.. Buy a trusted certificate (be it simple or wildcard)
b.. Get a trusted certificate for free using Let's Encrypt
You'll find info on the wiki on how to do this. Check https://wiki.contribs.org/Letsencrypt



++
--
Daniel Berteaud

FIREWALL-SERVICES SAS.
Société de Services en Logiciels Libres
Tel : 05 56 64 15 32
Visio : http://vroom.fws.fr/dani
www.firewall-services.com



--------------------------------------------------------------------------------
_______________________________________________
Server Development Discussion
To unsubscribe, e-mail devinfo-***@lists.contribs.org
Searchable archive at https://lists.contribs.org/mailman/public/devinfo/
Loading...