博客
关于我
强烈建议你试试无所不能的chatGPT,快点击我
Chrome 显示 err_cert_authority_invalid 的处理方式
阅读量:6973 次
发布时间:2019-06-27

本文共 3231 字,大约阅读时间需要 10 分钟。

hot3.png

前段时间将本站的 SSL 证书改为 AlphaSSL 的泛域名证书,今天突然发现用 chrome 访问会报err_cert_authority_invalid错误,网上找了一下,解决办法就是,粘贴下面的证书放在crt 文件的后面。
-----BEGIN CERTIFICATE-----MIIETTCCAzWgAwIBAgILBAAAAAABRE7wNjEwDQYJKoZIhvcNAQELBQAwVzELMAkGA1UEBhMCQkUxGTAXBgNVBAoTEEdsb2JhbFNpZ24gbnYtc2ExEDAOBgNVBAsTB1Jvb3QgQ0ExGzAZBgNVBAMTEkdsb2JhbFNpZ24gUm9vdCBDQTAeFw0xNDAyMjAxMDAwMDBaFw0yNDAyMjAxMDAwMDBaMEwxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWduIG52LXNhMSIwIAYDVQQDExlBbHBoYVNTTCBDQSAtIFNIQTI1NiAtIEcyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2gHs5OxzYPt+j2q3xhfjkmQy1KwA2aIPue3ua4qGypJn2XTXXUcCPI9A1p5tFM3D2ik5pw8FCmiiZhoexLKLdljlq10dj0CzOYvvHoN9ItDjqQAu7FPPYhmFRChMwCfLew7sEGQAEKQFzKByvkFsMVtI5LHsuSPrVU3QfWJKpbSlpFmFxSWRpv6mCZ8GEG2PgQxkQF5zAJrgLmWYVBAAcJjI4e00X9icxw3A1iNZRfz+VXqG7pRgIvGu0eZVRvaZxRsIdF+ssGSEj4k4HKGnkCFPAm694GFn1PhChw8K98kEbSqpL+9Cpd/do1PbmB6B+Zpye1reTz5/olig4hetZwIDAQABo4IBIzCCAR8wDgYDVR0PAQH/BAQDAgEGMBIGA1UdEwEB/wQIMAYBAf8CAQAwHQYDVR0OBBYEFPXN1TwIUPlqTzq3l9pWg+Zp0mj3MEUGA1UdIAQ+MDwwOgYEVR0gADAyMDAGCCsGAQUFBwIBFiRodHRwczovL3d3dy5hbHBoYXNzbC5jb20vcmVwb3NpdG9yeS8wMwYDVR0fBCwwKjAooCagJIYiaHR0cDovL2NybC5nbG9iYWxzaWduLm5ldC9yb290LmNybDA9BggrBgEFBQcBAQQxMC8wLQYIKwYBBQUHMAGGIWh0dHA6Ly9vY3NwLmdsb2JhbHNpZ24uY29tL3Jvb3RyMTAfBgNVHSMEGDAWgBRge2YaRQ2XyolQL30EzTSo//z9SzANBgkqhkiG9w0BAQsFAAOCAQEAYEBoFkfnFo3bXKFWKsv0XJuwHqJL9csCP/gLofKnQtS3TOvjZoDzJUN4LhsXVgdSGMvRqOzm+3M+pGKMgLTSxRJzo9P6Aji+Yz2EuJnB8br3n8NA0VgYU8Fi3a8YQn80TsVD1XGwMADH45CuP1eGl87qDBKOInDjZqdUfy4oy9RU0LMeYmcI+Sfhy+NmuCQbiWqJRGXy2UzSWByMTsCVodTvZy84IOgu/5ZR8LrYPZJwR2UcnnNytGAMXOLRc3bgr07i5TelRS+KIz6HxzDmMTh89N1SyvNTBCVXVmaU6Avu5gMUTu79bZRknl7OedSyps9AsUSoPocZXun4IRZZUw== -----END CERTIFICATE-----
如果后续再出现类似的情况的话,可以在 查看最新的中间证书。  

What are Intermediate CA certificates? All customers installing an AlphaSSL Certificate will need to install the Alpha CA Intermediate CA onto their web servers.  The installation needs to only be conducted once.  Once installed, all browsers, applications and mobiles will trust AlphaSSL Certificates transparently. The Intermediate CA certificate needs only be installed on the web server and does NOT need to be installed by visitors to your web site.

 
Why does AlphaSSL use an Intermediate CA certificate? AlphaSSL has always adopted a high security model when issuing digital certificates.  We use a trust chain that ensures that the primary root CA used to create the Alpha CA Intermediate CA (i.e. the GlobalSign Root CA certificate that is pre-installed with all browsers, applications and mobiles) is “offline” and kept in a highly secure environment with stringently limited access.  This means the root CA is not used to directly sign end entity SSL Certificates, as such AlphaSSL employs a best practices approach for it Public Key Infrastructure therefore protecting against the major effects of a “key compromise”.  For example, a key compromise of the primary Root CA would render the root and all certificates issued by the root untrustworthy, and because we keep our root offline this (somewhat unlikely event) is significantly less likely to happen. The use of Intermediate CAs is utilized by all major Certification Authorities because of the extra security level they provide.  

tips:

本文由导入,原文链接:

转载于:https://my.oschina.net/yangyan/blog/859529

你可能感兴趣的文章
linux0.11下的中断机制分析
查看>>
Watashi's BG(01背包思想+深搜+剪枝)
查看>>
mysql数据库之数据类型,约束条件
查看>>
Struts2、SpringMVC、Servlet(Jsp)性能对比 测试
查看>>
2017ACM/ICPC广西邀请赛
查看>>
layui使用 ——父,子页面传值
查看>>
Linux Netcat 命令——网络工具中的瑞士军刀
查看>>
Python Day32
查看>>
高并发思路
查看>>
.NET应用服务器
查看>>
Entity Framework Core的坑:Skip/Take放在Select之前造成Include的实体全表查询
查看>>
脱敏小软件
查看>>
Android 在Android代码中执行命令行
查看>>
修改VirtualBox虚拟机默认存储路径及虚拟机迁移方法
查看>>
hdu 3440 House Man
查看>>
Error && MFC
查看>>
深入理解Servlet3.0异步请求
查看>>
Lua C API 遍历 table
查看>>
Harbor镜像迁移
查看>>
实验六 在应用程序中播放音频和视频
查看>>