Ask a Question
Ask Question Login
Corporate Training
  1. Community
  2. SQL Server
  3. Question
SQL Server

How do you create and use CAs and certificate using cross-signing?

Asked by Angela Baker Nov 30, 2021 500 views 1 answer
Share

About this question

I'm trying to create an CA using cross-singing, and verify a certificate issued against one of the CAs, all using openssl. The best I got so far is getting openssl into an endless loop while verifying (the loop is terminated at level 100).

I've published all of the certs I created. Now, there are a number of assumptions that I'm making, and largely based on this Oasis document to build the model. Here are my assumptions:


  • There should be 4 certificates, self-signed from authorities #1 and #2, and cross-signed, where authority #1 is signed by authority #2 and vice versa.
  • There are only 2 actual subjects (DNs) used (the same subject used by an authority for self-signed is what it has signed by the other authority, albeit in a different cert).
  • All 4 certificates should be the part of the end-user trust.
  • The keys used by the same authority, for both self- and cross- signed certificates should be the same
  • AKI should not be used (May be "shouldn't" is too of a strong word, but not using it shouldn't hurt. Because of the same keys rule, it shouldn't matter though)
  • I tried setting CA:TRUE for cross-signed certs, with the same result.

  • What I understand from cross-signing, is that it gives the verification process alternative paths. Considering that I see openssl loop, it seems to be picking certificates with cross-signing every time. So the crux of the question is - what would make the verification process to favor the self-signed certificate over the one with cross-signing, considering both have the same subject.

    Here is a test leaf certificate, I can't make openssl verify to verify it successfully.


Your answer

1 Answer

More SQL Server discussions

Learn & Explore

Free tutorials and interview questions from industry experts — learn the skill, then get ready to prove it.

Latest SQL Server Blogs

Guides, tips and career advice on SQL Server from JanBask experts.