Adding trusted root certificates to the server
If you want to send or receive messages signed by root authorities and these authorities are not installed on the server, you must add a trusted root certificateA certificate issued by a trusted certificate authority (CA). In the SSL, anyone can generate a signing key and sign a new certificate. manually.
Use the following steps to add or remove trusted root certificates to/from a server.
Mac OS X
Function | Method |
Add |
Use command: sudo security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain ~/new-root-certificate.crt |
Remove |
Use command: sudo security delete-certificate -c "<name of existing certificate>" |
Windows
Function | Method |
Add |
Use command: certutil -addstore -f "ROOT" new-root-certificate.crt |
Remove |
Use command: certutil -delstore "ROOT" serial-number-hex |
Linux (Ubuntu, Debian)
Function | Method |
Add |
|
Remove |
|
NOTE
Restart Kerio Connect to reload the certificates in the 32-bit versions or Debian 7.
Linux (CentOs 6)
Function | Method |
Add |
|
NOTE
Restart Kerio Connect to reload the certificates in the 32-bit version.
Linux (CentOs 5)
Function | Method |
Add |
Append your trusted certificate to file /etc/pki/tls/certs/ca-bundle.crt
|
NOTE
Restart Kerio Connect to reload the certificates in the 32-bit version.