How to install company proxy certificateIIS 7.5 Unable to use self signed certificate on a per web site basis for https binding sharing port 443Install a root certificate in CentOS 6SSL certificate issueAdding trusted root certificates to the server cent osCurl: unable to get local issuer certificate. How to debug?Let's Encrypt certificate not recognized by Nginxnginx as reverse ssl proxy (Apache + Varnish) skips its own configurationcurl: (60) server certificate verification failedIIS 8.5 403.16 Untrusted Client CertificateInstall GeoTrust SSL CA - G3 certificates - curl error

How to implement float hashing with approximate equality

If 1. e4 c6 is considered as a sound defense for black, why is 1. c3 so rare?

Feels like I am getting dragged into office politics

How can I fairly adjudicate the effects of height differences on ranged attacks?

Selecting a secure PIN for building access

Was the ancestor of SCSI, the SASI protocol, nothing more than a draft?

Why do freehub and cassette have only one position that matches?

Copy line and insert it in a new position with sed or awk

Why is Thanos so tough at the beginning of "Avengers: Endgame"?

How to back up a running Linode server?

Why do money exchangers give different rates to different bills

Unidentified items in bicycle tube repair kit

LT Spice Voltage Output

Historically, were women trained for obligatory wars? Or did they serve some other military function?

Floor tile layout process?

Power LED from 3.3V Power Pin without Resistor

How can I close a gap between my fence and my neighbor's that's on his side of the property line?

What is the limiting factor for a CAN bus to exceed 1Mbps bandwidth?

How did Arya get back her dagger from Sansa?

Is balancing necessary on a full-wheel change?

Is Cola "probably the best-known" Latin word in the world? If not, which might it be?

A non-technological, repeating, phenomenon in the sky, holding its position in the sky for hours

Why was Germany not as successful as other Europeans in establishing overseas colonies?

What does air vanishing on contact sound like?



How to install company proxy certificate


IIS 7.5 Unable to use self signed certificate on a per web site basis for https binding sharing port 443Install a root certificate in CentOS 6SSL certificate issueAdding trusted root certificates to the server cent osCurl: unable to get local issuer certificate. How to debug?Let's Encrypt certificate not recognized by Nginxnginx as reverse ssl proxy (Apache + Varnish) skips its own configurationcurl: (60) server certificate verification failedIIS 8.5 403.16 Untrusted Client CertificateInstall GeoTrust SSL CA - G3 certificates - curl error






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








1















My CentOS 7 server which is in AWS private cloud(company network), is unable to connect to some sites. After some work I managed to narrow the problem down to following problem.



  1. The following internal site is not accessible (SSL by public CA)

curl -v https://git.company.com



which returns,



About to connect() to git.company.com port 443 (#0)
Trying 10.62.124.6...
Connected to git.company.com (10.62.124.6) port 443 (#0)
Initializing NSS with certpath: sql:/etc/pki/nssdb
CAfile: /etc/pki/tls/certs/ca-bundle.crt
CApath: none


  1. But following internal site works (SSL by public CA)

curl -v https://alm.company.com



which returns



About to connect() to alm.company.com port 443 (#0)
Trying 10.64.167.137...
Connected to alm.company.com (10.64.167.137) port 443 (#0)
Initializing NSS with certpath: sql:/etc/pki/nssdb
CAfile: /etc/pki/tls/certs/ca-bundle.crt
CApath: none
SSL connection using TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
...
...
...
Accept: */*


These are both internal sites trusted by same public CA.



How can debug this further?
I ran into some solutions where they ask to install company's into the server(though i'm wondering why one site works but other one doesnt), but not sure how to install this certificate correctly.



Can someone help please?



Thanks for the help.










share|improve this question



















  • 1





    You could start by posting the error that curl returned. Your post did not include this information.

    – Michael Hampton
    Oct 8 '18 at 19:04

















1















My CentOS 7 server which is in AWS private cloud(company network), is unable to connect to some sites. After some work I managed to narrow the problem down to following problem.



  1. The following internal site is not accessible (SSL by public CA)

curl -v https://git.company.com



which returns,



About to connect() to git.company.com port 443 (#0)
Trying 10.62.124.6...
Connected to git.company.com (10.62.124.6) port 443 (#0)
Initializing NSS with certpath: sql:/etc/pki/nssdb
CAfile: /etc/pki/tls/certs/ca-bundle.crt
CApath: none


  1. But following internal site works (SSL by public CA)

curl -v https://alm.company.com



which returns



About to connect() to alm.company.com port 443 (#0)
Trying 10.64.167.137...
Connected to alm.company.com (10.64.167.137) port 443 (#0)
Initializing NSS with certpath: sql:/etc/pki/nssdb
CAfile: /etc/pki/tls/certs/ca-bundle.crt
CApath: none
SSL connection using TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
...
...
...
Accept: */*


These are both internal sites trusted by same public CA.



How can debug this further?
I ran into some solutions where they ask to install company's into the server(though i'm wondering why one site works but other one doesnt), but not sure how to install this certificate correctly.



Can someone help please?



Thanks for the help.










share|improve this question



















  • 1





    You could start by posting the error that curl returned. Your post did not include this information.

    – Michael Hampton
    Oct 8 '18 at 19:04













1












1








1








My CentOS 7 server which is in AWS private cloud(company network), is unable to connect to some sites. After some work I managed to narrow the problem down to following problem.



  1. The following internal site is not accessible (SSL by public CA)

curl -v https://git.company.com



which returns,



About to connect() to git.company.com port 443 (#0)
Trying 10.62.124.6...
Connected to git.company.com (10.62.124.6) port 443 (#0)
Initializing NSS with certpath: sql:/etc/pki/nssdb
CAfile: /etc/pki/tls/certs/ca-bundle.crt
CApath: none


  1. But following internal site works (SSL by public CA)

curl -v https://alm.company.com



which returns



About to connect() to alm.company.com port 443 (#0)
Trying 10.64.167.137...
Connected to alm.company.com (10.64.167.137) port 443 (#0)
Initializing NSS with certpath: sql:/etc/pki/nssdb
CAfile: /etc/pki/tls/certs/ca-bundle.crt
CApath: none
SSL connection using TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
...
...
...
Accept: */*


These are both internal sites trusted by same public CA.



How can debug this further?
I ran into some solutions where they ask to install company's into the server(though i'm wondering why one site works but other one doesnt), but not sure how to install this certificate correctly.



Can someone help please?



Thanks for the help.










share|improve this question
















My CentOS 7 server which is in AWS private cloud(company network), is unable to connect to some sites. After some work I managed to narrow the problem down to following problem.



  1. The following internal site is not accessible (SSL by public CA)

curl -v https://git.company.com



which returns,



About to connect() to git.company.com port 443 (#0)
Trying 10.62.124.6...
Connected to git.company.com (10.62.124.6) port 443 (#0)
Initializing NSS with certpath: sql:/etc/pki/nssdb
CAfile: /etc/pki/tls/certs/ca-bundle.crt
CApath: none


  1. But following internal site works (SSL by public CA)

curl -v https://alm.company.com



which returns



About to connect() to alm.company.com port 443 (#0)
Trying 10.64.167.137...
Connected to alm.company.com (10.64.167.137) port 443 (#0)
Initializing NSS with certpath: sql:/etc/pki/nssdb
CAfile: /etc/pki/tls/certs/ca-bundle.crt
CApath: none
SSL connection using TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
...
...
...
Accept: */*


These are both internal sites trusted by same public CA.



How can debug this further?
I ran into some solutions where they ask to install company's into the server(though i'm wondering why one site works but other one doesnt), but not sure how to install this certificate correctly.



Can someone help please?



Thanks for the help.







linux centos ssl curl






share|improve this question















share|improve this question













share|improve this question




share|improve this question








edited Oct 8 '18 at 22:24









alexander.polomodov

1,0503712




1,0503712










asked Oct 8 '18 at 16:57









Chandima JayawickremaChandima Jayawickrema

62




62







  • 1





    You could start by posting the error that curl returned. Your post did not include this information.

    – Michael Hampton
    Oct 8 '18 at 19:04












  • 1





    You could start by posting the error that curl returned. Your post did not include this information.

    – Michael Hampton
    Oct 8 '18 at 19:04







1




1





You could start by posting the error that curl returned. Your post did not include this information.

– Michael Hampton
Oct 8 '18 at 19:04





You could start by posting the error that curl returned. Your post did not include this information.

– Michael Hampton
Oct 8 '18 at 19:04










1 Answer
1






active

oldest

votes


















0














You can use curl -k ... to make it ignore certificate irregularities.



Or you can use curl --cacert <CA certificate> to supply your company CA cert.



Or you can add your company CA cert to /etc/pki/tls/certs/ and run make there to make it available system-wide.



Ah, and to retrieve the company root CA use this: openssl s_client -connect git.company.com:443 -showcerts - that will dump all the certificates in the chain.






share|improve this answer

























    Your Answer








    StackExchange.ready(function()
    var channelOptions =
    tags: "".split(" "),
    id: "2"
    ;
    initTagRenderer("".split(" "), "".split(" "), channelOptions);

    StackExchange.using("externalEditor", function()
    // Have to fire editor after snippets, if snippets enabled
    if (StackExchange.settings.snippets.snippetsEnabled)
    StackExchange.using("snippets", function()
    createEditor();
    );

    else
    createEditor();

    );

    function createEditor()
    StackExchange.prepareEditor(
    heartbeatType: 'answer',
    autoActivateHeartbeat: false,
    convertImagesToLinks: true,
    noModals: true,
    showLowRepImageUploadWarning: true,
    reputationToPostImages: 10,
    bindNavPrevention: true,
    postfix: "",
    imageUploader:
    brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
    contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
    allowUrls: true
    ,
    onDemand: true,
    discardSelector: ".discard-answer"
    ,immediatelyShowMarkdownHelp:true
    );



    );













    draft saved

    draft discarded


















    StackExchange.ready(
    function ()
    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f934532%2fhow-to-install-company-proxy-certificate%23new-answer', 'question_page');

    );

    Post as a guest















    Required, but never shown

























    1 Answer
    1






    active

    oldest

    votes








    1 Answer
    1






    active

    oldest

    votes









    active

    oldest

    votes






    active

    oldest

    votes









    0














    You can use curl -k ... to make it ignore certificate irregularities.



    Or you can use curl --cacert <CA certificate> to supply your company CA cert.



    Or you can add your company CA cert to /etc/pki/tls/certs/ and run make there to make it available system-wide.



    Ah, and to retrieve the company root CA use this: openssl s_client -connect git.company.com:443 -showcerts - that will dump all the certificates in the chain.






    share|improve this answer





























      0














      You can use curl -k ... to make it ignore certificate irregularities.



      Or you can use curl --cacert <CA certificate> to supply your company CA cert.



      Or you can add your company CA cert to /etc/pki/tls/certs/ and run make there to make it available system-wide.



      Ah, and to retrieve the company root CA use this: openssl s_client -connect git.company.com:443 -showcerts - that will dump all the certificates in the chain.






      share|improve this answer



























        0












        0








        0







        You can use curl -k ... to make it ignore certificate irregularities.



        Or you can use curl --cacert <CA certificate> to supply your company CA cert.



        Or you can add your company CA cert to /etc/pki/tls/certs/ and run make there to make it available system-wide.



        Ah, and to retrieve the company root CA use this: openssl s_client -connect git.company.com:443 -showcerts - that will dump all the certificates in the chain.






        share|improve this answer















        You can use curl -k ... to make it ignore certificate irregularities.



        Or you can use curl --cacert <CA certificate> to supply your company CA cert.



        Or you can add your company CA cert to /etc/pki/tls/certs/ and run make there to make it available system-wide.



        Ah, and to retrieve the company root CA use this: openssl s_client -connect git.company.com:443 -showcerts - that will dump all the certificates in the chain.







        share|improve this answer














        share|improve this answer



        share|improve this answer








        edited Oct 8 '18 at 23:03

























        answered Oct 8 '18 at 22:54









        potompotom

        1107




        1107



























            draft saved

            draft discarded
















































            Thanks for contributing an answer to Server Fault!


            • Please be sure to answer the question. Provide details and share your research!

            But avoid


            • Asking for help, clarification, or responding to other answers.

            • Making statements based on opinion; back them up with references or personal experience.

            To learn more, see our tips on writing great answers.




            draft saved


            draft discarded














            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f934532%2fhow-to-install-company-proxy-certificate%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown





















































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown

































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown







            Popular posts from this blog

            Club Baloncesto Breogán Índice Historia | Pavillón | Nome | O Breogán na cultura popular | Xogadores | Adestradores | Presidentes | Palmarés | Historial | Líderes | Notas | Véxase tamén | Menú de navegacióncbbreogan.galCadroGuía oficial da ACB 2009-10, páxina 201Guía oficial ACB 1992, páxina 183. Editorial DB.É de 6.500 espectadores sentados axeitándose á última normativa"Estudiantes Junior, entre as mellores canteiras"o orixinalHemeroteca El Mundo Deportivo, 16 setembro de 1970, páxina 12Historia do BreogánAlfredo Pérez, o último canoneiroHistoria C.B. BreogánHemeroteca de El Mundo DeportivoJimmy Wright, norteamericano do Breogán deixará Lugo por ameazas de morteResultados de Breogán en 1986-87Resultados de Breogán en 1990-91Ficha de Velimir Perasović en acb.comResultados de Breogán en 1994-95Breogán arrasa al Barça. "El Mundo Deportivo", 27 de setembro de 1999, páxina 58CB Breogán - FC BarcelonaA FEB invita a participar nunha nova Liga EuropeaCharlie Bell na prensa estatalMáximos anotadores 2005Tempada 2005-06 : Tódolos Xogadores da Xornada""Non quero pensar nunha man negra, mais pregúntome que está a pasar""o orixinalRaúl López, orgulloso dos xogadores, presume da boa saúde económica do BreogánJulio González confirma que cesa como presidente del BreogánHomenaxe a Lisardo GómezA tempada do rexurdimento celesteEntrevista a Lisardo GómezEl COB dinamita el Pazo para forzar el quinto (69-73)Cafés Candelas, patrocinador del CB Breogán"Suso Lázare, novo presidente do Breogán"o orixinalCafés Candelas Breogán firma el mayor triunfo de la historiaEl Breogán realizará 17 homenajes por su cincuenta aniversario"O Breogán honra ao seu fundador e primeiro presidente"o orixinalMiguel Giao recibiu a homenaxe do PazoHomenaxe aos primeiros gladiadores celestesO home que nos amosa como ver o Breo co corazónTita Franco será homenaxeada polos #50anosdeBreoJulio Vila recibirá unha homenaxe in memoriam polos #50anosdeBreo"O Breogán homenaxeará aos seus aboados máis veteráns"Pechada ovación a «Capi» Sanmartín e Ricardo «Corazón de González»Homenaxe por décadas de informaciónPaco García volve ao Pazo con motivo do 50 aniversario"Resultados y clasificaciones""O Cafés Candelas Breogán, campión da Copa Princesa""O Cafés Candelas Breogán, equipo ACB"C.B. Breogán"Proxecto social"o orixinal"Centros asociados"o orixinalFicha en imdb.comMario Camus trata la recuperación del amor en 'La vieja música', su última película"Páxina web oficial""Club Baloncesto Breogán""C. B. Breogán S.A.D."eehttp://www.fegaba.com

            Vilaño, A Laracha Índice Patrimonio | Lugares e parroquias | Véxase tamén | Menú de navegación43°14′52″N 8°36′03″O / 43.24775, -8.60070

            Cegueira Índice Epidemioloxía | Deficiencia visual | Tipos de cegueira | Principais causas de cegueira | Tratamento | Técnicas de adaptación e axudas | Vida dos cegos | Primeiros auxilios | Crenzas respecto das persoas cegas | Crenzas das persoas cegas | O neno deficiente visual | Aspectos psicolóxicos da cegueira | Notas | Véxase tamén | Menú de navegación54.054.154.436928256blindnessDicionario da Real Academia GalegaPortal das Palabras"International Standards: Visual Standards — Aspects and Ranges of Vision Loss with Emphasis on Population Surveys.""Visual impairment and blindness""Presentan un plan para previr a cegueira"o orixinalACCDV Associació Catalana de Cecs i Disminuïts Visuals - PMFTrachoma"Effect of gene therapy on visual function in Leber's congenital amaurosis"1844137110.1056/NEJMoa0802268Cans guía - os mellores amigos dos cegosArquivadoEscola de cans guía para cegos en Mortágua, PortugalArquivado"Tecnología para ciegos y deficientes visuales. Recopilación de recursos gratuitos en la Red""Colorino""‘COL.diesis’, escuchar los sonidos del color""COL.diesis: Transforming Colour into Melody and Implementing the Result in a Colour Sensor Device"o orixinal"Sistema de desarrollo de sinestesia color-sonido para invidentes utilizando un protocolo de audio""Enseñanza táctil - geometría y color. Juegos didácticos para niños ciegos y videntes""Sistema Constanz"L'ocupació laboral dels cecs a l'Estat espanyol està pràcticament equiparada a la de les persones amb visió, entrevista amb Pedro ZuritaONCE (Organización Nacional de Cegos de España)Prevención da cegueiraDescrición de deficiencias visuais (Disc@pnet)Braillín, un boneco atractivo para calquera neno, con ou sen discapacidade, que permite familiarizarse co sistema de escritura e lectura brailleAxudas Técnicas36838ID00897494007150-90057129528256DOID:1432HP:0000618D001766C10.597.751.941.162C97109C0155020