CKB:The requested public SSL certificate cannot be imported

Aus Cryptshare Documentation
Wechseln zu:Navigation, Suche


Applies to:

All versions of Cryptshare Server

Symptom:

The requested SSL certificate cannot be imported into the keystore with the following error:

  • English: Could not establish trust for the CA Reply.
  • German: Vertrauenskette für die CA Antwort konnte nicht erstellt werden.

Screenshot-164846534133339.png

Cause:

The information in the SSL certificate from the CA doesn't match the information in the sent CSR.

Solution:

Export the private key from the keystore used for the creation of the CSR file and import it together with the requested SSL certificate into a new keystore.

1. open the existing keystore used for the generating of the CSR file

2. klick with the right mouse button on the entry in the keystore

3. open the menu entry 'Export --> Export Private Key'

Screenshot-164846584762787.png

4. save the private key in OpenSSL format to your local machine

Screenshot-1648465847627134.png Screenshot-1648465847627174.png

5. create new Java-Keystore of type JKS

Screenshot-1648047657171.png Screenshot-16484653413330.png

6. impot the available SSL certificate

Screenshot-1648047247778.png

7. select the certificate format, e.g. pkcs12 (.pfx) or OpenSSL (.crt, .cer, .pem)

Screenshot-164846584762718.png Screenshot-164846584762763.png Screenshot-1648465847627107.png

8. import and check the certificate chain

Screenshot-1648047586411.png Screenshot-1648047841061.png Screenshot-16484653413332.png

9. save the keystore

Screenshot-1648047621474.png

10. use the default password 'CA0AZhuFM4NogQh', to save the Keystore

Screenshot-1648046690861.png

11. install the created keystore on the Cryptshare server Setting up an SSL Certificate#InstallingtheKeystoreontheCryptshareServer