How many levels of Sub-CA chaining are supported in Sentry CA 3.x?
Originally Published: 2001-07-24
Last Modified: 2023-10-06
Article Number
Applies To
TechNote 0131
Issue
Have the Sub-CA chaining more than 11 levels.
When starting Sentry CA services, the following error message appears:
The secure directory server does not appear to be reachable. Remember that you must start it before attempting to start the Web server. You will be unable to make client-authenticated connections to this server until you restart it with a running directory server.
test.xxxxx.com: error setting default verify locations:
[unable to contact directory server]
Cause
Resolution
For Netscape browsers to correctly follow this chain, all intermediate CAs must have the appropriate netscape_cert_type extension for the given protocol. So for SSL, intermediate CAs MUST have bit 5 (SSL CA) asserted (similarly, for S/MIME, intermediate CAs would need bit 6 - S/MIME CA - asserted). The Root CA does not need this assertion.
Related Articles
IIS Hangs on Restart with Many Application Pools 38Number of Views Many defunct processes (from AceClient v8.1 in radius) when running ps auxf 18Number of Views How many incorrect password entries are permitted before being locked out of a Luna token? 13Number of Views Change Verification task running after Account Data Collection (ADC) taking many hours to be completed in RSA Via Lifecycl… 174Number of Views Authentication Manager Console Access using CNAME or DNS alias fails with Redirect Logon Loop - ERR_TOO_MANY_REDIRECTS 11Number of Views
Trending Articles
Artifacts to gather in RSA Identity Governance & Lifecycle How to Update the Root (Server) and Client Certificates in RSA Identity Governance & Lifecycle How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Troubleshooting AFX Connector issues in RSA Identity Governance & Lifecycle How to Download and Reinstall the AFX Server Archive in RSA Governance & Lifecycle
Don't see what you're looking for?