Openssl: cannot validate client certificate issued by Root CA certificate

Viewed 210

Im sorry for raising yet another Openssl topic, but here's an issue I can't really solve.

I have an app, that connects to server (an a form of another app) which is in the same network. SSL certificate is needed for this connection.

Server accepts self-signed certificate created this way:

openssl genrsa -out privkey.pem 4096

openssl req -x509 -config certconfig.txt -new -nodes -key privkey.pem -days 3650 -out newcert.pem

openssl pkcs12 -inkey privkey.pem -in newcert.pem -export -out newcert.pfx -passout pass:

certconfig.txt assigns the only Common Name that is accepted by server, and this is correct according to specification.

Self-signed cert is accepted by the server, but security requirements changed and now only Root CA - signed certificates are to be accepted. And here a problem stars:

I create Root CA certificate and client certificate.

Root CA certificate: openssl genrsa -out rootca.pem 4096

openssl req -x509 -new -nodes -key rootca.pem -days 3650 -config certconfig_root.txt -out rootca.crt

Client app key: openssl genrsa -out privkey.pem 4096

Client app cert sign reques (certconfig_client has a proper Common Name inside): openssl req -new -key privkey.pem -config certconfig_client.txt -out newcert.csr

Client app cert: openssl x509 -req -in newcert.csr -CA rootca.crt -CAkey rootca.pem -CAcreateserial -out newcert.pem -days 3650

Client app cert -> *.pfx openssl pkcs12 -inkey privkey.pem -in newcert.pem -export -out newcert.pfx -passout pass:

Root CA cert -> *.pfx openssl pkcs12 -inkey rootca.pem -in rootca.crt -export -out rootca.pfx -passout pass:

I move client certificate to the app, and install Root CA certificate in Windows, in Trusted Root Certification Authorities.

Now, actual problem:

When I try to connect with this client app cert newcert.pfx, server closes connection due to SSL handshake failed. App returns an exception:

{"The certificate chain was issued by an authority that is not trusted"}

When I try to debug this connection via OpenSSL command:

s_client -connect {server_address) -showcerts

it shows that:

Verify return code: 21 (unable to verify the first certificate)

If I dobug it with specifying Root CA cert file via

s_client -connect {server_address) -showcerts -CAfile {Root CA cert location}

if actually sees the cert chain but returns error:

verify return:1 13728:error:14094410:SSLroutines:ssl3_read_bytes:sslv3 alert handshake failure:ssl\record\rec_layer_s3.c:1544:SSL alert number 40

It seems that when my app connects to server, somehow it's cert does not have a "link" to Root CA cert, which is installed on this machine.

Now the big question is: why?

0 Answers
Related