{"id":1127,"date":"2023-02-14T00:34:24","date_gmt":"2023-02-14T00:34:24","guid":{"rendered":"http:\/\/wp.chaoyu.nl\/?p=1127"},"modified":"2023-07-25T00:13:18","modified_gmt":"2023-07-24T22:13:18","slug":"nginx-with-cabundle-crt-certificate-crt","status":"publish","type":"post","link":"https:\/\/chaoyu.nl\/?p=1127","title":{"rendered":"Nginx with cabundle.crt  certificate.crt ( seperated domain and intermedia+root certs"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Some SSL provider generates intermedia.crt root.crt and domain cert in 2 different files, when configure nginx 3 things need to happen first. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>cat domain &gt; itermedia &gt; root certs into one cert<\/li>\n\n\n\n<li>open the newly created file, make sure &#8212;&#8211;END CERTIFICATE&#8212;&#8212;&#8212;-BEGIN CERTIFICATE&#8212;&#8211; is not happening. if so, create new line<\/li>\n\n\n\n<li>if you still cannot start nginx , do this sudo setenforce 0<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code lang=\"bash\" class=\"language-bash line-numbers\"># in my case \n\ncat certificate.crt ca_bundle.crt &gt;&gt; ssl-bundle.crt\n\n#open file and edit it \nnano ssl-bundle.crt\n# find -----END CERTIFICATE----------BEGIN CERTIFICATE-----\n# make sure they are like this \n\n-----END CERTIFICATE-----\n\n-----BEGIN CERTIFICATE-----\n\n# update your nginx.config file with newly created ssl-bundle.crt\n\n# at last \n\nsudo setenforce 0\nsudo nginx -t\nsudo systemctl restart nginx<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/stackoverflow.com\/questions\/62514704\/ssl-on-nginx-throws-error-ssl-error0908f066pem-routinesget-header-and-data\" data-type=\"URL\" data-id=\"https:\/\/stackoverflow.com\/questions\/62514704\/ssl-on-nginx-throws-error-ssl-error0908f066pem-routinesget-header-and-data\">link1 for cat <\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/stackoverflow.com\/questions\/37994513\/nginx-ssl-certificate-permission-ssl-error-0200100dsystem\" data-type=\"URL\" data-id=\"https:\/\/stackoverflow.com\/questions\/37994513\/nginx-ssl-certificate-permission-ssl-error-0200100dsystem\" target=\"_blank\" rel=\"noreferrer noopener\">link2 for setenforce 0<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Funny thing is , if you provide only the domain crt in the nginx config file, browser would not complain. But if u do a curl or postman to the server. it complains that no root certs found. Better off using letsencrypt. I encounter this extra steps with a paid certs. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Some SSL provider generates intermedia.crt root.crt and domain cert in 2 different files, when configure nginx 3 things need to happen first. link1 for cat link2 for setenforce 0 Funny thing is , if you provide only the domain crt in the nginx config file, browser would not complain. But if u do a curl&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[17,53],"tags":[],"class_list":["post-1127","post","type-post","status-publish","format-standard","hentry","category-linux","category-nginx"],"_links":{"self":[{"href":"https:\/\/chaoyu.nl\/index.php?rest_route=\/wp\/v2\/posts\/1127","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/chaoyu.nl\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/chaoyu.nl\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/chaoyu.nl\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/chaoyu.nl\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1127"}],"version-history":[{"count":4,"href":"https:\/\/chaoyu.nl\/index.php?rest_route=\/wp\/v2\/posts\/1127\/revisions"}],"predecessor-version":[{"id":1134,"href":"https:\/\/chaoyu.nl\/index.php?rest_route=\/wp\/v2\/posts\/1127\/revisions\/1134"}],"wp:attachment":[{"href":"https:\/\/chaoyu.nl\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1127"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/chaoyu.nl\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1127"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/chaoyu.nl\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1127"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}