From owner-freebsd-questions@FreeBSD.ORG Fri Apr 2 16:19:03 2010 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 7021C1065673 for ; Fri, 2 Apr 2010 16:19:03 +0000 (UTC) (envelope-from amvandemore@gmail.com) Received: from qw-out-2122.google.com (qw-out-2122.google.com [74.125.92.26]) by mx1.freebsd.org (Postfix) with ESMTP id 297ED8FC19 for ; Fri, 2 Apr 2010 16:19:02 +0000 (UTC) Received: by qw-out-2122.google.com with SMTP id 3so741308qwe.7 for ; Fri, 02 Apr 2010 09:19:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:in-reply-to:references :date:received:message-id:subject:from:to:content-type; bh=PrCmuKNwW7cjzZsp6E3gU18qjxXNNEOOGxpe+I3ZWMs=; b=GK9Gu5+IIYEpjfu+O+z+0mJZRLUSp9+Hx1aiEPBcsPZqhIIUGrUH+cjI88rmKHpt0z gAD5Cg/MHLAa3mT3KIGWY+AS9aHEjJ6Uyg9/QuaIH1DFQFSf5hzL3xVg3MrzD9RHd9Fm +NSMIdWC0Ie0MbGojyfE0yhXD+l5a2iSyjUXA= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :content-type; b=xJbvvM7KcbzsxsLGoVQhotMqrsiNkqRjizsgrbJcfjNvfgELyqdFBSNCmoK0kKClVI EFze+W//zge0PUSA9Y/kSm5zQTQMtU9TpuyKyYIVu08QAKhXZbBVRWUpeRtgb9vjsl1F /w2VmTCSgJ3yfB9nuglsCiu0kt7EpYxkKqZ/E= MIME-Version: 1.0 Received: by 10.229.82.14 with HTTP; Fri, 2 Apr 2010 09:19:02 -0700 (PDT) In-Reply-To: <20100402110430.13bcdc03@scorpio.seibercom.net> References: <20100402110430.13bcdc03@scorpio.seibercom.net> Date: Fri, 2 Apr 2010 10:19:02 -0600 Received: by 10.229.251.72 with SMTP id mr8mr3846548qcb.30.1270225142188; Fri, 02 Apr 2010 09:19:02 -0700 (PDT) Message-ID: From: Adam Vande More To: freebsd-questions@freebsd.org Content-Type: text/plain; charset=ISO-8859-1 X-Content-Filtered-By: Mailman/MimeDel 2.1.5 Subject: Re: Combining SSL certificates X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 02 Apr 2010 16:19:03 -0000 On Fri, Apr 2, 2010 at 9:04 AM, Jerry wrote: > Is it possible to combine all of the certificates in a chain into one > *.pem file? > > EXAMPLE: > > openssl s_client -connect imap.gmail.com:993 -crlf -showcerts > > This would show, in this case anyway, two certificates. Could I combine > both certs into on file, example: gmail-imap.pem and then run > 'c_rehash' on the file or do I have to save both certs in separate > files to complete the chain? > Doesn't it work to simply concatenate pem's together? I was my understanding it was possible to do that, but perhaps order of concatenation matters. So make sure you're dealing with pem's and cat together with root being last and I think it should work. -- Adam Vande More