Guidance on obtaining certificate chain for Apache SSL setup
Asma Aljarai <[email protected]> Fri, 26 Dec 2025 11:51:25 +0200
| Newsgroups | gmane.comp.apache.user |
|---|---|
| Message-ID | <[email protected]> |
--Apple-Mail-48DDC705-2645-46BF-BC90-2797B29C0059 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: quoted-printable Hello Apache Community, I have configured SSL on Apache HTTP Server running on CentOS 9. Environment: - Operating System: CentOS 9 - Apache Version: 2.4.62 Certificate setup: - Private key generated on the server - CSR generated on the server and signed by our internal CA (Key Manager Plu= s) - Server certificate (.crt) issued successfully Issue: I did not receive the certificate chain (intermediate certificates). Without= the chain, browsers may not fully trust the site, and I want to ensure the S= SL configuration is complete and secure. Questions: 1. What is the recommended way to obtain the certificate chain from an inter= nal CA such as Key Manager Plus? 2. Is it acceptable to run Apache securely using only the server certificate= and private key if the chain is not available? 3. Could the missing chain be the reason the site appears as not fully secur= e in browsers? Any guidance or best practices would be greatly appreciated. Thank you. --Apple-Mail-48DDC705-2645-46BF-BC90-2797B29C0059 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable <html class=3D"apple-mail-supports-explicit-dark-mode"><head><meta http-equi= v=3D"content-type" content=3D"text/html; charset=3Dutf-8"></head><body dir=3D= "auto"><div style=3D"direction: rtl;"><div style=3D"direction: ltr;" dir=3D"= ltr">Hello Apache Community,</div><div style=3D"direction: rtl;"><br></div><= div style=3D"direction: rtl;">I have configured SSL on Apache HTTP Server ru= nning on CentOS 9.</div><div style=3D"direction: rtl;"><br></div><div style=3D= "direction: rtl;">Environment:</div><div style=3D"direction: rtl;">- Operati= ng System: CentOS 9</div><div style=3D"direction: rtl;">- Apache Version: 2.= 4.62</div><div style=3D"direction: rtl;"><br></div><div style=3D"direction: r= tl;">Certificate setup:</div><div style=3D"direction: rtl;">- Private key ge= nerated on the server</div><div style=3D"direction: rtl;">- CSR generated on= the server and signed by our internal CA (Key Manager Plus)</div><div style= =3D"direction: rtl;">- Server certificate (.crt) issued successfully</div><d= iv style=3D"direction: rtl;"><br></div><div style=3D"direction: rtl;">Issue:= </div><div style=3D"direction: rtl;">I did not receive the certificate chain= (intermediate certificates). Without the chain, browsers may not fully trus= t the site, and I want to ensure the SSL configuration is complete and secur= e.</div><div style=3D"direction: rtl;"><br></div><div style=3D"direction: rt= l;">Questions:</div><div style=3D"direction: rtl;">1. What is the recommende= d way to obtain the certificate chain from an internal CA such as Key Manage= r Plus?</div><div style=3D"direction: rtl;">2. Is it acceptable to run Apach= e securely using only the server certificate and private key if the chain is= not available?</div><div style=3D"direction: rtl;">3. Could the missing cha= in be the reason the site appears as not fully secure in browsers?</div><div= style=3D"direction: rtl;"><br></div><div style=3D"direction: rtl;">Any guid= ance or best practices would be greatly appreciated.</div><div style=3D"dire= ction: rtl;"><br></div><div style=3D"direction: rtl;">Thank you.</div></div>= <div dir=3D"ltr"></div></body></html>= --Apple-Mail-48DDC705-2645-46BF-BC90-2797B29C0059--