Koozali.org: home of the SME Server

EV SSL cert slight problem

Offline jameswilson

  • *
  • 795
  • +0/-0
    • Security Warehouse, professional security equipment
EV SSL cert slight problem
« on: October 03, 2010, 08:49:53 PM »
Hi all
I have a sme 7.5.1 running very well indeed (always has) a couple of months ago i the ssl cert ran out and we purchased an ev ssl cert.
Following the existing guides I got it to work. But for some reason there are 3 parts to the ssl cert.
I used to 2 parts i recognised (its a globalsign cert) and it works fine. Or so i thought.

If you visit https globalsign then the cert on my site works correctly. If i dont then the browser reports an untrusted cert until you visit globalsign https.
I assume the 3rd cert is a rotot cert that is required? But i dont know how to add this to the system. They call it if i recall a cross cert.

Any suggestions please?

James

Offline jameswilson

  • *
  • 795
  • +0/-0
    • Security Warehouse, professional security equipment
Re: EV SSL cert slight problem
« Reply #1 on: October 07, 2010, 07:57:12 AM »
any ideas?

Offline janet

  • *****
  • 4,812
  • +0/-0
Re: EV SSL cert slight problem
« Reply #2 on: October 07, 2010, 09:27:19 AM »
jameswilson

Guessing that the globalsign root certificate needs to be updated in the web browser, so the browser accepts your site certificate.
Perhaps just try updating the web browser.

Other than that you should really ask globalsign

Look here
http://www.globalsign.com/ssl-information-center/certificate-authority-root.html
for the clients supported.

When using the EV cert, only recent releases of browsers & email clients are supported.
Extended Validation Browsers
• Microsoft Internet Explorer 7+ (Vista)
• Microsoft Internet Explorer 7+ ( XP)*
• Opera 9.5+
• Firefox 3+
• Google Chrome 0.3.154.9 +
• Apple Safari 3.2 +
• Apple iPhone 3.0 +
« Last Edit: October 07, 2010, 09:32:48 AM by mary »
Please search before asking, an answer may already exist.
The Search & other links to useful information are at top of Forum.

Offline jameswilson

  • *
  • 795
  • +0/-0
    • Security Warehouse, professional security equipment
Re: EV SSL cert slight problem
« Reply #3 on: October 09, 2010, 11:39:22 AM »
Thanks Mary.
If you test my webserver with https you will find that it shows an unverified cert. However once you visit globalsign https then the ev works fine on my site.

Now looking into the cert info they have sent me i have 3 parts to the cert
Quote
MUST BE INSTALLED ON YOUR WEB SERVER:
Your SSL Certificate (Formatted for the majority of web server
software including IIS and Apache based servers):
and
Quote
MUST BE INSTALLED ON YOUR WEB SERVER:
ExtendedSSL Intermediate Certificate:
and
Quote
MUST BE INSTALLED ON YOUR WEB SERVER:
Extended Validation Cross Certificate:
I have only installed the ssl cert which is what im assuming is the problem

Globalsign do give instructions for centos but as sme is 'different' i dont like following centos guides as the results can be unpredictable.

Im not 100% on ssl certs at the best of time but this has totally fixed me.
ANy suggestions.

James

Offline jameswilson

  • *
  • 795
  • +0/-0
    • Security Warehouse, professional security equipment
Re: EV SSL cert slight problem
« Reply #4 on: October 09, 2010, 11:44:11 AM »
http://nl.globalsign.com/en/support/ssl+certificates/redhat/red+hat+enterprise+linux/install+certificate/

I can see i need to install the intermediate cert, but i also have a cross certificate.
I have no idea what to put where and how.

Offline janet

  • *****
  • 4,812
  • +0/-0
Re: EV SSL cert slight problem
« Reply #5 on: October 09, 2010, 01:00:55 PM »
jameswilson

Perhaps you should tell us what your domain is, so we can take a look.
Please search before asking, an answer may already exist.
The Search & other links to useful information are at top of Forum.

Offline jameswilson

  • *
  • 795
  • +0/-0
    • Security Warehouse, professional security equipment
Re: EV SSL cert slight problem
« Reply #6 on: October 09, 2010, 01:57:14 PM »
securitywarehouse.co.uk
thats one of the domains and the ssl one.

Offline Stefano

  • *
  • 10,894
  • +3/-0
Re: EV SSL cert slight problem
« Reply #7 on: October 09, 2010, 02:20:21 PM »
I have no problem/message or other if I go to https:///www.securitywarehouse.co.uk/, it simply works for me

I'm using FF on ubuntu 10.04 and I see the green label "Security Warehouse LTD (GB)"

IMO it's an issue on your side

Offline jameswilson

  • *
  • 795
  • +0/-0
    • Security Warehouse, professional security equipment
Re: EV SSL cert slight problem
« Reply #8 on: October 09, 2010, 02:24:14 PM »
thats what i thought but what i think is if anyone has visited a correctly configured site with a globalsign ev cert then mine works as expected. But if someone hasnt then the cert fails. If you then visit globalsign https then it starts working. Can i clear out the certs etc on my local machine for testing?

Offline Stefano

  • *
  • 10,894
  • +3/-0
Re: EV SSL cert slight problem
« Reply #9 on: October 09, 2010, 02:51:47 PM »
installed chrome and works flawlessy.. I never used chrome before

HTH

Offline janet

  • *****
  • 4,812
  • +0/-0
Re: EV SSL cert slight problem
« Reply #10 on: October 10, 2010, 12:23:16 AM »
jameswilson

Quote
If you test my webserver with https you will find that it shows an unverified cert. However once you visit globalsign https then the ev works fine on my site.

What web browsers and version are you using ?
What OS and version are you trying from ?

My understanding is that the certificate issuers root certificate information is included in the root certificate "store location" of your browser. If you use an older browser or an out of date browser, then by updating the browser to the latest version then you will also update the root certificate details, which includes knowledge of globalsign certificates & other certificate issuers who pay their fees to the browser developers.
« Last Edit: October 10, 2010, 12:43:51 AM by mary »
Please search before asking, an answer may already exist.
The Search & other links to useful information are at top of Forum.

Offline janet

  • *****
  • 4,812
  • +0/-0
Re: EV SSL cert slight problem
« Reply #11 on: October 10, 2010, 02:15:54 AM »
jameswilson

Quote
Can i clear out the certs etc on my local machine for testing?

Look  in your browser to "clear those out" although I don't see how removing root certificates will help.
Updating your root certificate(s) will probably help.
In FireFox see, Tools Options Advanced Encryption View Certificates
Please search before asking, an answer may already exist.
The Search & other links to useful information are at top of Forum.