VeriSign created at least two intermediate CAs with the same Distinguished Name, both valid on this date but with different serial numbers.

VeriSign created at least two intermediate CAs with the same Distinguished Name, both valid on this date but with different serial numbers.

book

Article ID: KB0085261

calendar_today

Updated On:

Products Versions
TIBCO ActiveMatrix BusinessWorks -
Not Applicable -

Description

Description:
From the log file it appears the issue is related to the certificate. The error is general but cannot be resolved even if you use the correct certificate provided.

Looking in datastore for certificate with DN cn=VeriSign Class 3 Public Primary Certification Authority - G5,ou=(c) 2006 VeriSign, Inc. - For authorized use only,ou=VeriSign Trust Network,o=VeriSign, Inc.,c=US

CA certificate with correct DN, but fingerprint '...' found.  Continuing search.

CA certificate with correct DN, but fingerprint '...' found.  Continuing search.

No match found.

That there are several ways to follow a 'chain'. Web browsers seem to look for the DN of the Issuer, then they look for the DN in the trusted certs, but will find the 'other' one with fingerprint 'CB17 E431 673E E209 FE45 5793 F30A FA1C' and fail in practical use.


Symptoms:
Looking in datastore for certificate with DN cn=VeriSign Class 3 Public Primary Certification Authority - G5,ou=(c) 2006 VeriSign, Inc. - For authorized use only,ou=VeriSign Trust Network,o=VeriSign, Inc.,c=US

CA certificate with correct DN, but fingerprint '...' found.  Continuing search.

CA certificate with correct DN, but fingerprint '...' found.  Continuing search.

No match found


Cause:
The problem is that VeriSign created at least two intermediate CAs with the same Distinguished Name, both valid on this date but with different serial numbers. When we import certificates using web browsers, it seem to look for the DN of the Issuer, then they look for the DN in the trusted certs but it will find the 'other' one with fingerprint 'CB17 E431 673E E209 FE45 5793 F30A FA1C' and fail.

Resolution

Use the attached cert (Filename: one.pem.zip) with

  Serial Number:

           25:0c:e8:e0:30:61:2e:9f:2b:89:f7:05:4d:7c:f8:fd

Issue/Introduction

VeriSign created at least two intermediate CAs with the same Distinguished Name, both valid on this date but with different serial numbers.

Attachments

VeriSign created at least two intermediate CAs with the same Distinguished Name, both valid on this date but with different serial numbers. get_app