Im sorry for raising yet another Openssl topic, but here's an issue I can't really solve.
I have an app, that connects to server (an a form of another app) which is in the same network. SSL certificate is needed for this connection.
Server accepts self-signed certificate created this way:
openssl genrsa -out privkey.pem 4096
openssl req -x509 -config certconfig.txt -new -nodes -key privkey.pem -days 3650 -out newcert.pem
openssl pkcs12 -inkey privkey.pem -in newcert.pem -export -out newcert.pfx -passout pass:
certconfig.txt assigns the only Common Name that is accepted by server, and this is correct according to specification.
Self-signed cert is accepted by the server, but security requirements changed and now only Root CA - signed certificates are to be accepted. And here a problem stars:
I create Root CA certificate and client certificate.
Root CA certificate:
openssl genrsa -out rootca.pem 4096
openssl req -x509 -new -nodes -key rootca.pem -days 3650 -config certconfig_root.txt -out rootca.crt
Client app key:
openssl genrsa -out privkey.pem 4096
Client app cert sign reques (certconfig_client has a proper Common Name inside):
openssl req -new -key privkey.pem -config certconfig_client.txt -out newcert.csr
Client app cert:
openssl x509 -req -in newcert.csr -CA rootca.crt -CAkey rootca.pem -CAcreateserial -out newcert.pem -days 3650
Client app cert -> *.pfx
openssl pkcs12 -inkey privkey.pem -in newcert.pem -export -out newcert.pfx -passout pass:
Root CA cert -> *.pfx
openssl pkcs12 -inkey rootca.pem -in rootca.crt -export -out rootca.pfx -passout pass:
I move client certificate to the app, and install Root CA certificate in Windows, in Trusted Root Certification Authorities.
Now, actual problem:
When I try to connect with this client app cert newcert.pfx, server closes connection due to SSL handshake failed. App returns an exception:
{"The certificate chain was issued by an authority that is not trusted"}
When I try to debug this connection via OpenSSL command:
s_client -connect {server_address) -showcerts
it shows that:
Verify return code: 21 (unable to verify the first certificate)
If I dobug it with specifying Root CA cert file via
s_client -connect {server_address) -showcerts -CAfile {Root CA cert location}
if actually sees the cert chain but returns error:
verify return:1 13728:error:14094410:SSLroutines:ssl3_read_bytes:sslv3 alert handshake failure:ssl\record\rec_layer_s3.c:1544:SSL alert number 40
It seems that when my app connects to server, somehow it's cert does not have a "link" to Root CA cert, which is installed on this machine.
Now the big question is: why?