Chaining x.509 certificates

wdtj_at_yahoo.com
Date: 04/28/05


Date: 27 Apr 2005 15:48:48 -0700

I'm fairly new to x.509 certificates, etc. Please forgive a novice
question...

I work for a software development organization. We've used a Verisign
x.509 certificate (via keytool and jarsigner) to sign our jars before
they get shipped to customers for a few years. Now we're going to be
shipping a new product enhancement that uses https for security.

It looks like, with https, our customer will need their own x.509
certificate. They can, of course generate their own self-signed
certificate, or get one from Verisign, et al.

I'm wondering if there is a third option. For us to create a
sub-certificate off of our current one.

After digging through keytool and a whole pile of stuff on Google for a
day (and barely scratching the surface), I still have not figured out
the magical step of chaining a x.509 certificate. Keytool refers to
importing a chained certificate from the CA, but nothing about how the
CA creates it.

I suppose, if it were easy, Verisign would quickly go out of business
:{)>

Any suggestions or references would be greatly appreciated.



Relevant Pages

  • Digital sign a driver for XP and Vista
    ... My company has just bought a Class 3 certificate from Verisign to digitally sign some drivers. ... The driver is made up by a .inf file, a .sys file and a .dll file. ... SHA1 hash: 8FBE4D070EF8AB1BCCAF2A9D5CCAE7282A2C66B3 ...
    (microsoft.public.development.device.drivers)
  • Re: RSA vs AES
    ... > Verisign, MS took the extra burden of issuing a critical patch to ... > those stolen root CAs. ... if any of these other keys ever got compromised ... ... BBN Certificate Services ...
    (sci.crypt)
  • Re: Your digital ID name cannot be found by the underlying security system
    ... This morning I received email from VeriSign indicating that apparently I ... Although I do not have a private key recovery feature, ... replaced the certificate 3 times already and still it will not work. ...
    (microsoft.public.outlook)
  • Re: [Full-Disclosure] PGP vs. certificate from Verisign
    ... What I wonder - will Verisign have set up CRL servers yet? ... PGP vs. certificate from Verisign ...
    (Full-Disclosure)
  • Re: Certificates -Annoyed
    ... There are cheaper alternatives to verisign such as RapidSSL. ... .Net code signing is different from a verisign SSL certificate. ... You don't need to purchase a certificate from anyone to sign your code. ... you put a datafile on your webserver that gets hit by your installation with a secure password and login. ...
    (microsoft.public.dotnet.general)