This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

unable to get local issuer certificate for a lot of sites after update to 9.310

Hi,

I did the update to 9.310 last weekend and now I am facing a "unable to get local issuer certificate" error for a lot of https sites. This could be relatet to the update or not. I am not sure but those sites were working a few days ago.

Some examples for non working sites:
https://www.ing-diba.de/ - Issuer: /C=US/O=Symantec Corporation/OU=Symantec Trust Network/CN=Symantec Class 3 EV SSL CA - G3
https://www.amazon.de/ - Issuer: /C=US/O=VeriSign, Inc./OU=VeriSign Trust Network/OU=Terms of use at https://www.verisign.com/rpa (c)10/CN=VeriSign Class 3 Secure Server CA - G3
https://www.adobe.com/ - Issuer: /C=US/O=VeriSign, Inc./OU=VeriSign Trust Network/OU=Terms of use at https://www.verisign.com/rpa (c)10/CN=VeriSign Class 3 Secure Server CA - G3

Some other sites like eBay are working so maybe thsi is related to the Issuning CA. As far as I can see those are present on the UTM.

Can anybody confirm there is an issue or not.
I will open a support case, too.

Thanks.


This thread was automatically locked due to age.
Parents Reply Children
  • Yes, three Thawte CA certificates were simply removed in the latest update...  These are the ones:

    CN=Thawte Server CA, fingerprint=23:E5:94:94:51:95:F2:41:48:03:B4[[[[[:D]]]]]5:64[[[[[:D]]]]]2:A3:A3:F5[[[[[:D]]]]]8:8B:8C
    CN=Thawte SGC CA, fingerprint=09:54:E2:34:3D[[[[[:D]]]]]5:EF:E0:A7:F0:96:7D:69:CA:F3:3E:5F:89:37:20
    CN=Thawte Premium Server CA, fingerprint=62:7F:8D:78:27:65:63:99[[[[[:D]]]]]2:7D:7F:90:44:C9:FE:B3:F3:3E:FA:9A