Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Notifications
Login / Register
Community
Community
Notifications
close
  • Forums
  • Knowledge Center
  • Events & Webinars
  • Ideas
  • Blogs
Help
Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Login / Register
Sustainability
Sustainability

We Value Your Feedback!
Could you please spare a few minutes to share your thoughts on Cloud Connected vs On-Premise Services. Your feedback can help us shape the future of services.
Learn more about the survey or Click here to Launch the survey
Schneider Electric Services Innovation Team!

Verify certificates with OpenSSL

Building Automation Knowledge Base

Schneider Electric Building Automation Knowledge Base is a self-service resource to answer all your questions about EcoStruxure Building suite, Andover Continuum, Satchwell, TAC…

cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • Home
  • Schneider Electric Community
  • Knowledge Center
  • Building Automation Knowledge Base
  • Verify certificates with OpenSSL
Options
  • Bookmark
  • Subscribe
  • Email to a Friend
  • Printer Friendly Page
  • Report Inappropriate Content
Invite a Co-worker
Send a co-worker an invite to the portal.Just enter their email address and we'll connect them to register. After joining, they will belong to the same company.
You have entered an invalid email address. Please re-enter the email address.
This co-worker has already been invited to the Exchange portal. Please invite another co-worker.
Please enter email address
Send Invite Cancel
Invitation Sent
Your invitation was sent.Thanks for sharing Exchange with your co-worker.
Send New Invite Close

Related Forums

  • Intelligent Devices Forum

Previous Next
Contributors
  • David_Purser
    David_Purser

Invite a Colleague

Found this content useful? Share it with a Colleague!

Invite a Colleague Invite
Back to Building Automation Knowledge Base
Options
  • Bookmark
  • Subscribe
  • Email to a Friend
  • Printer Friendly Page
  • Report Inappropriate Content
0 Likes
2305 Views

Link copied. Please paste this link to share this article on your social media post.

Trying to translate this page to your language?
Select your language from the translate dropdown in the upper right. arrow
Translate to: English
  • (Français) French
  • (Deutsche) German
  • (Italiano) Italian
  • (Português) Portuguese
  • (Русский) Russian
  • (Español) Spanish

Verify certificates with OpenSSL

Picard David_Purser Picard
‎2024-02-19 01:32 PM

on ‎2024-02-19 01:32 PM

Issue

Check the host and intermediate certificates with a CA certificate to verify the authentication chain before importing them into EBO servers.

Product Line

EcoStruxure Building Operation

Environment

  • Enterprise Central
  • Enterprise Server
  • Automation Server
  • Edge Server

Cause

Certificates are provided and can be assigned incorrectly or to the incorrect server; therefore, they do not function as expected.

Resolution

  1. Verify you have the following:
    1. Host certificate in PEM file format
    2. Intermediate Certificates in one pem file, not including Certificate Authority (CA) cert
    3. CA Certificate where Issuer and Subject Name are the same, indicating it is self-signed.
    4. OpenSSL is installed on the computer with the files. Use OpenSSL installed with EBO or install as mentioned in Ensuring the SSL Host Certificate and key file are a matching pair
  2. Use this command: 
    openssl verify -CAfile ca.pem -untrusted intermediate.pem server.pem​
  3. The explanation of the command is as follows:
    1. openssl verify: This initiates the certificate verification process.
    2. -CAfile ca.pem: Specifies the path to the PEM file containing the trusted CA (Certificate Authority) certificate.
    3. -untrusted intermediate.pem: Indicates the path to the PEM file containing the intermediate certificates. They are marked as untrusted because the system does not directly trust them, but their validity will be checked against the CA certificate.
    4. server.pem: Specifies the path to the PEM file containing the host server certificate you want to verify.
  4. The expected responses are: 
    1. server.pem: OK: Verification successful, indicating the server certificate is valid and its chain of trust is established.
    2. Error messages: If any errors occur during verification, they'll be displayed in the output. Common errors include certificate expiration, invalid signatures, or missing intermediate certificates
  5. Additional information:
    1. Ensure the file paths are correct and the certificates are in PEM format
    2. Ensure the host and intermediate certificates are installed on the server device and the CA Certificate on the client device.
    3. If you encounter issues, double-check the validity of the file permissions and certificates.
    4. For more detailed output, add the -verbose option to the command.
    5. To check expiration dates, use 
      openssl x509 -in server.pem -noout -dates
Labels (1)
Labels:
  • EcoStruxure Building Operation
Tags (1)
  • Find more articles tagged with:
  • DavidPurser24
Was this article helpful? Yes No
No ratings

Link copied. Please paste this link to share this article on your social media post.

To The Top!

Forums

  • APC UPS Data Center Backup Solutions
  • EcoStruxure IT
  • EcoStruxure Geo SCADA Expert
  • Metering & Power Quality
  • Schneider Electric Wiser

Knowledge Center

Events & webinars

Ideas

Blogs

Get Started

  • Ask the Community
  • Community Guidelines
  • Community User Guide
  • How-To & Best Practice
  • Experts Leaderboard
  • Contact Support
Brand-Logo
Subscribing is a smart move!
You can subscribe to this board after you log in or create your free account.
Forum-Icon

Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.

Register today for FREE

Register Now

Already have an account? Login

Terms & Conditions Privacy Notice Change your Cookie Settings © 2025 Schneider Electric

This is a heading

With achievable small steps, users progress and continually feel satisfaction in task accomplishment.

Usetiful Onboarding Checklist remembers the progress of every user, allowing them to take bite-sized journeys and continue where they left.

of