[Spice-devel] problems with intermediate certificates

Dietmar Maurer dietmar at proxmox.com
Mon Aug 25 09:09:56 PDT 2014


> To make sure I understand, you start with a Root CA which I assume you
> generated yourself and is self-signed? 

We use official certs from "StartCom Certification Authority" using  
" StartCom Class 2 Primary Intermediate Server CA" intermediate CA.

But we just observed that the same setup works for some users
when using  GeoTrust with "RapidSSL CA" intermediate CAs.

I have no idea why one setup works and one fails.


Using exactly the same certificate  files with https works fine. Also

# openssl verify -CAfile /etc/pve/pve-root-ca.pem /etc/pve/local/pve-ssl.pem

works fine.





More information about the Spice-devel mailing list