【问题标题】:Certificate Chain Failing and getting 502 Bad Gateway证书链失败并获得 502 Bad Gateway
【发布时间】:2022-12-01 18:18:07
【问题描述】:

我已经获得了 certificate.crt、intermediate.crt、root.crt 和私钥。我通过将中间证书和根证书合并在一起创建了一个新的证书文件,并且运行了以下命令将它们转换为似乎有效的 PFX。

openssl pkcs12 -export -out certificate.pfx -inkey private.key -in certificate.crt -certfile rootca.crt

然后我将 PFX 上传到 Azure 应用程序网关。当我尝试转到 URL 时,出现以下错误502错误的网关.

检查网关的运行状况时,出现以下错误:

 The root certificate of the server certificated used by the backend does not match the trusted root certificate added to the application gateway. Ensure that you add the correct root certificate to whitelist the backend.

我遇到的问题是我无法访问 Linux 后端服务器,而且我对 Linux 也没有信心,所以我不确定证书是否已在后端正确创建。我的问题是,我是否使用上述 OPENSSL 命令正确创建了证书?

【问题讨论】:

    标签: azure ssl openssl ssl-certificate certificate


    【解决方案1】:
    • 我试图在我的环境中重现同样的问题并得到了预期的结果。

    • 使用下面给出的 PowerShell 命令创建证书

    • 步骤1

    $cert = New-SelfSignedCertificate -Type Custom -KeySpec Signature `  
    -Subject "CN=P2SRootCert" -KeyExportPolicy Exportable `  
    -HashAlgorithm sha256 -KeyLength 2048 `  
    -CertStoreLocation "Cert:CurrentUserMy" -KeyUsageProperty Sign -KeyUsage CertSign
    
    • 第2步
    New-SelfSignedCertificate -Type Custom -DnsName P2SChildCert -KeySpec Signature `  
    -Subject "CN=P2SChildCert" -KeyExportPolicy Exportable `  
    -HashAlgorithm sha256 -KeyLength 2048 `  
    -CertStoreLocation "Cert:CurrentUserMy" `  
    -Signer $cert -TextExtension @("2.5.29.37={text}1.3.6.1.5.5.7.3.2")
    
    • 运行命令后,证书将创建如下

    • 点击Windows + r并运行以下命令→单击好的
         certmgr.msc
    
    • 转到→个人的→证书→ 右键单击​​要导出的证书并转到所有任务如下

    • 我们需要CER & PFX两个证书才能出口

    • 单击后获取 CXR 证书出口→下一个→ 选择不→选择Base-64 编码 x.509(CER)点击下一个→选择文件夹位置和文件夹名称 → 单击结束.

    • 单击后获取 PFX 证书出口→Next→SelectYes→ SelectExport all extended propertieswith other options by default click onNext→Click onPassword Checkboxand enter the password Click onNext→Selectfolder locationand folder name → Click onfinish

    • I have created the application gateway and I have imported the certificate

    • I am able to access the URL.

    Reference taken from MS-Doc

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 1970-01-01
      • 2017-08-15
      • 2014-01-18
      • 1970-01-01
      • 2020-11-28
      • 2017-06-11
      • 2020-09-01
      • 2021-09-17
      相关资源
      最近更新 更多