Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 3430960
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 18, 20262026-05-18T07:16:03+00:00 2026-05-18T07:16:03+00:00

my situation: I am working on a application that is using openssl and rsa-certificates

  • 0

my situation:
I am working on a application that is using openssl and rsa-certificates for secure communication with other parties.
so we need to exchange certificates.
so far so good.
mostly the partners certificate is a from a CA signed certificate (not a root certi or a selfsigend certi).
on my notebook (debian) I have from the distribution the most common rootCA-certificates installed in my openssl infrastrucutre. so I can verify the most partner-certificates because I have the issuer-root-certis.

my problem:
on my master-maschine I do not have pre-installed root-certis. so I need to check the partners-certi for the issuer, get this from the internet, put it into my trusted certi dir in openssl etc……

my question:
is this the normal way to do this???? Its a bit extensive and also a bit tricky if it is a longer chain.

thanks for help!

regards,chris

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-18T07:16:03+00:00Added an answer on May 18, 2026 at 7:16 am

    The purpose of having the root certificates preinstalled is because they serve as the top of the chain of trust (actually it’s more of a tree, or forest of trees…).

    By having them preinstalled we assume (although we all know what people say about assuming) that they are not compromised and can be used to verify any other certificate. While it could be possible to compromise them by e.g. hacking into an FTP server and messing with the DVD images of a Linux distribution, it’s not very easy and it’s not going to stay undetected for long, nor can it target a specific organization.

    In your case, you should do one of the following:

    • Install the root certificates in your system using a package from your system vendor. For a relatively high level of confidence, you should download the same package from two different locations, preferrably via different ISPs (e.g. from home and from work) and from two or three different mirrors. Then you can compare the downloaded files, which should be identical. If your system vendor provides checksums for their package files online you should verify those as well.

    • Take the root certificates from a trusted system via a USB drive and transfer them to your system. You should examine the security of the trusted system beforehand. Using a pristine Linux install from an official installation disk would be a good source.

    • Install at least one root certificate securely (e.g. via the USB drive method), then
      try to track down the issuer certificates for your partners. For each issuer certificate you should manually verify and install any other certificates up the chain of trust till you reach a preinstalled root certificate. This can be a very tedious procedure and you WILL get frustrated, since most CAs use multiple certificates for various reasons, from reducing the impact of a potential compromise to marketing and business reasons.

    You should NEVER install a certificate downloaded from the Internet as a trusted CA, unless you can verify its validity up to a preinstalled certificate.

    So as an answer to your question: Unless you have a lot of time and patience, along with a will to learn a lot more about PKIs than most people would want, just find a way to install the proper root certificate on your system.

    EDIT:

    I forgot to mention that some OS vendors (e.g. SuSE) have their own certificates preinstalled in their package management system. In that case downloading packages from the official repositories using that package management system should be secure enough that you don’t need to bother with any of the above to ensure the validity of the root certificate package.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I'm working on a Windows application that's written in VBScript and I need to
I'm working on a Cocoa application, and I've run into a situation where I
I've been working on optimizing a query and have ran into a situation that's
Situation: I have a simple XML document that contains image information. I need to
I am working on a .NET web application that uses an SQL Server database
So I am writing a mac application that parses SF Giants baseball statistics using
I'm working on a database-driven web application that must keep track of tasks that
I'm working on an ipad application that needs to work with images; it uses
I am working on a .net mvc web application that has a bunch of
Here’s the situation: We have a 3rd party application that intermittently displays an error

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.