Chaining x.509 certificates

wdtj_at_yahoo.com
Date: 04/28/05


Date: 27 Apr 2005 15:48:48 -0700

I'm fairly new to x.509 certificates, etc. Please forgive a novice
question...

I work for a software development organization. We've used a Verisign
x.509 certificate (via keytool and jarsigner) to sign our jars before
they get shipped to customers for a few years. Now we're going to be
shipping a new product enhancement that uses https for security.

It looks like, with https, our customer will need their own x.509
certificate. They can, of course generate their own self-signed
certificate, or get one from Verisign, et al.

I'm wondering if there is a third option. For us to create a
sub-certificate off of our current one.

After digging through keytool and a whole pile of stuff on Google for a
day (and barely scratching the surface), I still have not figured out
the magical step of chaining a x.509 certificate. Keytool refers to
importing a chained certificate from the CA, but nothing about how the
CA creates it.

I suppose, if it were easy, Verisign would quickly go out of business
:{)>

Any suggestions or references would be greatly appreciated.



Relevant Pages

  • Re: RSA vs AES
    ... > Verisign, MS took the extra burden of issuing a critical patch to ... > those stolen root CAs. ... if any of these other keys ever got compromised ... ... BBN Certificate Services ...
    (sci.crypt)
  • Re: Your digital ID name cannot be found by the underlying security system
    ... This morning I received email from VeriSign indicating that apparently I ... Although I do not have a private key recovery feature, ... replaced the certificate 3 times already and still it will not work. ...
    (microsoft.public.outlook)
  • Re: [Full-Disclosure] PGP vs. certificate from Verisign
    ... What I wonder - will Verisign have set up CRL servers yet? ... PGP vs. certificate from Verisign ...
    (Full-Disclosure)
  • Re: what certificate to buy from Verisign ?
    ... > Server certificate is used by server service, ... For client side, there has Client Authentication Certificate ... > like Verisign will have much more types of certificates available, ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • Re: what certificate to buy from Verisign ?
    ... \par Microsoft Online Support ... \par Subject: Re: what certificate to buy from Verisign? ... \par> secure communication channel between client/server, ...
    (microsoft.public.dotnet.framework.webservices.enhancements)