【问题标题】:Certificate Chain Failing and getting 502 Bad Gateway证书链失败并获得 502 Bad Gateway
【发布时间】:2022-12-01 18:18:07
【问题描述】:
我已经获得了 certificate.crt、intermediate.crt、root.crt 和私钥。我通过将中间证书和根证书合并在一起创建了一个新的证书文件,并且运行了以下命令将它们转换为似乎有效的 PFX。
openssl pkcs12 -export -out certificate.pfx -inkey private.key -in certificate.crt -certfile rootca.crt
然后我将 PFX 上传到 Azure 应用程序网关。当我尝试转到 URL 时,出现以下错误502错误的网关.
检查网关的运行状况时,出现以下错误:
The root certificate of the server certificated used by the backend does not match the trusted root certificate added to the application gateway. Ensure that you add the correct root certificate to whitelist the backend.
我遇到的问题是我无法访问 Linux 后端服务器,而且我对 Linux 也没有信心,所以我不确定证书是否已在后端正确创建。我的问题是,我是否使用上述 OPENSSL 命令正确创建了证书?
【问题讨论】:
标签:
azure
ssl
openssl
ssl-certificate
certificate
【解决方案1】:
$cert = New-SelfSignedCertificate -Type Custom -KeySpec Signature `
-Subject "CN=P2SRootCert" -KeyExportPolicy Exportable `
-HashAlgorithm sha256 -KeyLength 2048 `
-CertStoreLocation "Cert:CurrentUserMy" -KeyUsageProperty Sign -KeyUsage CertSign
New-SelfSignedCertificate -Type Custom -DnsName P2SChildCert -KeySpec Signature `
-Subject "CN=P2SChildCert" -KeyExportPolicy Exportable `
-HashAlgorithm sha256 -KeyLength 2048 `
-CertStoreLocation "Cert:CurrentUserMy" `
-Signer $cert -TextExtension @("2.5.29.37={text}1.3.6.1.5.5.7.3.2")
- 点击Windows + r并运行以下命令→单击好的
certmgr.msc
- 转到→个人的→证书→ 右键单击要导出的证书并转到所有任务如下
-
我们需要CER & PFX两个证书才能出口
-
单击后获取 CXR 证书出口→下一个→ 选择不→选择Base-64 编码 x.509(CER)点击下一个→选择文件夹位置和文件夹名称 → 单击结束.
-
单击后获取 PFX 证书出口→Next→SelectYes→ SelectExport all extended propertieswith other options by default click onNext→Click onPassword Checkboxand enter the password Click onNext→Selectfolder locationand folder name → Click onfinish
-
I have created the application gateway and I have imported the certificate
-
I am able to access the URL.
Reference taken from MS-Doc