Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #264715
| From | Pocket <pocket@columbus.rr.com> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: update-ca-certificates |
| Date | 2023-12-14 04:00 +0100 |
| Message-ID | <HKK77-dqvm-5@gated-at.bofh.it> (permalink) |
| References | <HKIeZ-dpqU-1@gated-at.bofh.it> <HKJXs-dqse-3@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On 12/13/23 21:47, Jeffrey Walton wrote: > On Wed, Dec 13, 2023 at 7:55 PM Pocket <pocket@columbus.rr.com> wrote: >> What formats does certs need to be to work with update-ca-certificates? >> >> PEM or DER? > PEM Ok since I am using an intermediate cert to sign, I am creating a combined PEM with the root CA and the intermediate cert like this cat "$directory"/certs/intermediate.cert.pem "$ca_directory"/certs/ca.cert.pem > "$directory"/certs/ca-chain.cert.pem Will that work or does the cert have to be a single cert? > >> I have just finished writing some scripts to generate certs for my email >> server and nginx server. >> >> [...] >> Will pem format type certs work? > Yes. > > You should also place the certificates in > /usr/local/share/ca-certificates . Make the directory if it does not > exist. And then run update-ca-certificates from the directory. > > Jeff That sub directory does indeed exist, so I need to run update-cert-certificates from /usr/local/share/ca-certificates or can I just run update-cert-certificates as root? Thanks -- It's not easy to be me
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
update-ca-certificates Pocket <pocket@columbus.rr.com> - 2023-12-14 02:00 +0100
Re: update-ca-certificates Roberto C. Sánchez <roberto@debian.org> - 2023-12-14 02:30 +0100
Re: update-ca-certificates Pocket <pocket@columbus.rr.com> - 2023-12-14 03:00 +0100
Re: update-ca-certificates jeremy ardley <jeremy.ardley@gmail.com> - 2023-12-14 02:40 +0100
Re: update-ca-certificates Pocket <pocket@columbus.rr.com> - 2023-12-14 03:00 +0100
Re: update-ca-certificates Charles Curley <charlescurley@charlescurley.com> - 2023-12-14 04:00 +0100
Re: update-ca-certificates Pocket <pocket@columbus.rr.com> - 2023-12-14 04:10 +0100
letsencrypt certs for disconnected hosts (Was Re: update-ca-certificates) Andy Smith <andy@strugglers.net> - 2023-12-14 13:20 +0100
Re: update-ca-certificates Jeffrey Walton <noloader@gmail.com> - 2023-12-14 03:50 +0100
Re: update-ca-certificates Pocket <pocket@columbus.rr.com> - 2023-12-14 04:00 +0100
Re: update-ca-certificates Jeffrey Walton <noloader@gmail.com> - 2023-12-14 05:00 +0100
Re: update-ca-certificates Jeffrey Walton <noloader@gmail.com> - 2023-12-14 12:40 +0100
Re: update-ca-certificates Henning Follmann <hfollmann@itcfollmann.com> - 2023-12-14 14:20 +0100
Re: update-ca-certificates Pocket <pocket@columbus.rr.com> - 2023-12-14 14:50 +0100
Re: update-ca-certificates Linux-Fan <Ma_Sys.ma@web.de> - 2023-12-14 20:30 +0100
Re: update-ca-certificates Pocket <pocket@columbus.rr.com> - 2023-12-14 20:40 +0100
Re: update-ca-certificates Linux-Fan <Ma_Sys.ma@web.de> - 2023-12-14 21:00 +0100
csiph-web