标签:tin toc dir ssl inux 文件的 har system 手动
如果要发送或接收由根颁发机构签名的消息,但服务器上未安装这些颁发机构,则必须手动添加受信任的根证书。
使用以下步骤向服务器添加或删除可信根证书。
sudo security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain ~/new-root-certificate.crt
sudo security delete-certificate -c "<name of existing certificate>"
certutil -addstore -f "ROOT" new-root-certificate.crt
certutil -delstore "ROOT" serial-number-hex
/usr/local/share/ca-certificates/
sudo cp foo.crt /usr/local/share/ca-certificates/foo.crt
sudo update-ca-certificates
sudo update-ca-certificates --fresh
cat ca.crt >> /etc/pki/tls/certs/ca-bundle.crt
yum install ca-certificates
update-ca-trust force-enable
cp foo.crt /etc/pki/ca-trust/source/anchors/
update-ca-trust
cat foo.crt >>/etc/pki/tls/certs/ca-bundle.crt
标签:tin toc dir ssl inux 文件的 har system 手动
原文地址:https://www.cnblogs.com/meilong/p/ge-xi-tong-tian-jia-gen-zheng-shu.html