Inedo Community Forums Forums
    • Recent
    • Tags
    • Popular
    • Login

    Welcome to the Inedo Forums! Check out the Forums Guide for help getting started.

    If you are experiencing any issues with the forum software, please visit the Contact Form on our website and let us know!

    ProGet on Windows ignores intermediate CA certificate in PFX file

    Scheduled Pinned Locked Moved Support
    4 Posts 2 Posters 7 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C Offline
      clsa
      last edited by

      Impact: Clients cannot verify the certificate chain, because the server should always send the intermediate certificates as well based on RFC 8446.

      PFX content has been verified with OpenSSL and contains the full chain.

      Version: 2026.12, installed through InedoHub.

      Known bug?

      stevedennisS 1 Reply Last reply Reply Quote 0
      • stevedennisS Offline
        stevedennis inedo-engineer @clsa
        last edited by

        Hi @clsa ,

        We're not aware of any bugs or issues; SSL and Certificate handling is all done at the Operating System (Windows) or Platform (.NET) level; we just point the system to the file. In my experience there's usually some obscure registry setting that will control stuff like this.

        Thanks,
        Steve

        1 Reply Last reply Reply Quote 0
        • C Offline
          clsa
          last edited by

          Hi Steve,

          thank you for your quick reply and the hint regarding registry.

          However i couldn't identify potentially unsuitable registry settings within reasonable time, so instead i did a counter-check by importing the very same PFX file into Windows' certificate store.

          I had to grant read permissions to "NETWORK SERVICE" for the imported private key, but this way the intermediate CA certificate is served to the clients properly.

          Interestingly when switching back to the PFX file in ProGet's config afterwards (+ service restart), clients still receive the intermediate CA certificate. Only after deleting the intermediate CA certificate from Windows' certificate store, ProGet starts complaining about "Error PartialChain: A certificate chain could not be built to a trusted root authority." (root CA certificate is available in Windows' certificate store all the time).

          This makes me think, that the current implementation doesn't read intermediate CA certificates from PFX files.

          stevedennisS 1 Reply Last reply Reply Quote 0
          • stevedennisS Offline
            stevedennis inedo-engineer @clsa
            last edited by

            Hi @clsa,

            If you're talking about the certificate errors under Admin > HTTPS, I wouldn't worry about those. An application does not need to validate its own certificate; it's only used to encrypt/decrypt the traffic.

            The server transmits a copy of the certificate (without the private key), and the client validates the certificate before transmitting data.

            Without getting into too many technical details, the only thing that really matters is if clients can connect to the application (ProGet) using HTTPS or not. There are a lot of reasons that may prevent the application from self-validation and it's not really worth trying to fix, since it's only used on that page to help catch basic errors.

            Thanks,
            Steve

            1 Reply Last reply Reply Quote 0

            Hello! It looks like you're interested in this conversation, but you don't have an account yet.

            Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

            With your input, this post could be even better 💗

            Register Login
            • 1 / 1
            • First post
              Last post
            Inedo Website Home • Support Home • Code of Conduct • Forums Guide • Documentation