#8821 RFE: add option to request to add CA chain to requested certificate file
Opened 2 years ago by pcech. Modified 2 years ago

Ticket was cloned from Red Hat Bugzilla (product Red Hat Enterprise Linux 8): Bug 1770178

Description of problem:
Since httpd 2.4.8, mod_ssl's SSLCertificateChainFile directive is deprecated and intermediate CAs are to be stored in SSLCertificateFile itself: https://httpd.apache.org/docs/current/mod/mod_ssl.html#SSLCertificateChainFile
As such, certmonger should either write the chain into cert file (-f option) by default or when requested by some new option

Version-Release number of selected component (if applicable):
certmonger-0.79.7-3.el8.x86_64

How reproducible:
discovered on el7 where this is non-issue (httpd there is 2.4.6), el8/f31 help/man don't mention such an option either

Metadata Update from @pcech:
- Custom field rhbz adjusted to https://bugzilla.redhat.com/show_bug.cgi?id=1770178

2 years ago

Login to comment on this ticket.

Metadata