<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Certificate order for SSL ChainGroup on ACE in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/certificate-order-for-ssl-chaingroup-on-ace/m-p/1944189#M37313</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Only if you use a PKCS12 format file. See &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/message/3141328#3141328"&gt;https://supportforums.cisco.com/message/3141328#3141328&lt;/A&gt;&lt;SPAN&gt; for more details.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cathy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 23 Apr 2012 08:22:59 GMT</pubDate>
    <dc:creator>ciscocsoc</dc:creator>
    <dc:date>2012-04-23T08:22:59Z</dc:date>
    <item>
      <title>Certificate order for SSL ChainGroup on ACE</title>
      <link>https://community.cisco.com/t5/application-networking/certificate-order-for-ssl-chaingroup-on-ace/m-p/1944186#M37310</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;Am trying to determine the correct order for listing intermeadiate certs in a&amp;nbsp; chain group on the ACE &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;In the URL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;A href="http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/ace_appliances/vA4_1_0/configuration/ssl/guide/certkeys.html#wp999546" rel="nofollow" style="border-collapse: collapse; list-style-type: none; outline-style: none; color: #2f6681; text-decoration: none;"&gt;http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/ace_appliances/vA4_1_0/configuration/ssl/guide/certkeys.html#wp999546&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;"Typically, it is not necessary to add the&amp;nbsp; certificates to the chain group in any type of hierarchical order&amp;nbsp; because the device that verifies the certificates determines the correct&amp;nbsp; order. However, some mobile devices may not be able to order the&amp;nbsp; certificates properly and will display an error message. In this case,&amp;nbsp; you need to add the certificates to the chain group in the correct&amp;nbsp; order. "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;However I can not find any reference to what is ' the correct&amp;nbsp; order '&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;For example for an Thawte SSL cert the chain could include&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;THAWTE_PREMIUM_SERVER_CA&amp;nbsp;&amp;nbsp;&amp;nbsp; (normaly in list of browser root CA's but might not be on mobile device)&lt;/P&gt;&lt;P&gt; - THAWTE_PRIMARY_ROOT_CA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - THAWTE_SSL_CA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - ISSUED_CERT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So for a mobile devices freindly chaingroup is the correct order "big-endian"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; chaingroup THAWTECHAIN&lt;/P&gt;&lt;P&gt;&amp;nbsp; cert THAWTE_PREMIUM_SERVER_CA.CER&lt;/P&gt;&lt;P&gt;&amp;nbsp; cert THAWTE_PRIMARY_ROOT_CA.CER&lt;/P&gt;&lt;P&gt;&amp;nbsp; cert THAWTE_SSL_CA.CER&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or is the correct order "little-endian"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; chaingroup THAWTECHAIN&lt;/P&gt;&lt;P&gt;&amp;nbsp; cert THAWTE_SSL_CA.CER&lt;/P&gt;&lt;P&gt;&amp;nbsp; cert THAWTE_PRIMARY_ROOT_CA.CER&lt;/P&gt;&lt;P&gt;&amp;nbsp; cert THAWTE_PREMIUM_SERVER_CA.CER&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;thanks,&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;Sez&lt;/P&gt;</description>
      <pubDate>Fri, 20 Apr 2012 15:50:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/certificate-order-for-ssl-chaingroup-on-ace/m-p/1944186#M37310</guid>
      <dc:creator>sez sharp</dc:creator>
      <dc:date>2012-04-20T15:50:16Z</dc:date>
    </item>
    <item>
      <title>Certificate order for SSL ChainGroup on ACE</title>
      <link>https://community.cisco.com/t5/application-networking/certificate-order-for-ssl-chaingroup-on-ace/m-p/1944187#M37311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sez,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The preferred order is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issued Cert&lt;/P&gt;&lt;P&gt;Intermediates&lt;/P&gt;&lt;P&gt;Root&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cathy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Apr 2012 16:33:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/certificate-order-for-ssl-chaingroup-on-ace/m-p/1944187#M37311</guid>
      <dc:creator>ciscocsoc</dc:creator>
      <dc:date>2012-04-20T16:33:08Z</dc:date>
    </item>
    <item>
      <title>Certificate order for SSL ChainGroup on ACE</title>
      <link>https://community.cisco.com/t5/application-networking/certificate-order-for-ssl-chaingroup-on-ace/m-p/1944188#M37312</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the quick answer Cathy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wwas also wondering if on the ACE you could use a crypto import to import a full PEM cert/key "file"&lt;/P&gt;&lt;P&gt;i.e. a PEM that not only contained the cert/key pair but also all the intermediate and root certs as well&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this crypto import was done to say&amp;nbsp; MYCERT.PEM&amp;nbsp; Then on the ACE&amp;nbsp; ssl-proxy service you could just reference this file and not require a seperate chaingroup listing?&amp;nbsp; i.e.: -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssl-proxy service MY-SSL-SERVICE&lt;/P&gt;&lt;P&gt; key MYCERT.PEM&lt;/P&gt;&lt;P&gt; cert MYCERT.PEM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is was the setup on CSS's - wondering is same true for ACE (but not had op to try out yet)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rgds, Sez&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Apr 2012 16:45:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/certificate-order-for-ssl-chaingroup-on-ace/m-p/1944188#M37312</guid>
      <dc:creator>sez sharp</dc:creator>
      <dc:date>2012-04-20T16:45:15Z</dc:date>
    </item>
    <item>
      <title>Certificate order for SSL ChainGroup on ACE</title>
      <link>https://community.cisco.com/t5/application-networking/certificate-order-for-ssl-chaingroup-on-ace/m-p/1944189#M37313</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Only if you use a PKCS12 format file. See &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/message/3141328#3141328"&gt;https://supportforums.cisco.com/message/3141328#3141328&lt;/A&gt;&lt;SPAN&gt; for more details.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cathy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2012 08:22:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/certificate-order-for-ssl-chaingroup-on-ace/m-p/1944189#M37313</guid>
      <dc:creator>ciscocsoc</dc:creator>
      <dc:date>2012-04-23T08:22:59Z</dc:date>
    </item>
    <item>
      <title>Certificate order for SSL ChainGroup on ACE</title>
      <link>https://community.cisco.com/t5/application-networking/certificate-order-for-ssl-chaingroup-on-ace/m-p/1944190#M37314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for pointing that one out Cathy &lt;/P&gt;&lt;P&gt; - I had fallen for that old trap of believing the doco which still says PEM only &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;About time that doco got fixed up if the ACE has always supported PKCS / DER / PEM and we're on f/w ver A5 now...!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks again,&lt;/P&gt;&lt;P&gt;Sez&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2012 10:33:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/certificate-order-for-ssl-chaingroup-on-ace/m-p/1944190#M37314</guid>
      <dc:creator>sez sharp</dc:creator>
      <dc:date>2012-04-23T10:33:24Z</dc:date>
    </item>
  </channel>
</rss>

