<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[ProGet on Windows ignores intermediate CA certificate in PFX file]]></title><description><![CDATA[<p dir="auto">Impact: Clients cannot verify the certificate chain, because the server should always send the intermediate certificates as well based on RFC 8446.</p>
<p dir="auto">PFX content has been verified with OpenSSL and contains the full chain.</p>
<p dir="auto">Version: 2026.12, installed through InedoHub.</p>
<p dir="auto">Known bug?</p>
]]></description><link>https://forums.inedo.com/topic/5853/proget-on-windows-ignores-intermediate-ca-certificate-in-pfx-file</link><generator>RSS for Node</generator><lastBuildDate>Wed, 07 Oct 2026 23:32:34 GMT</lastBuildDate><atom:link href="https://forums.inedo.com/topic/5853.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 06 Oct 2026 16:51:34 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to ProGet on Windows ignores intermediate CA certificate in PFX file on Wed, 07 Oct 2026 17:51:31 GMT]]></title><description><![CDATA[<p dir="auto">Hi <a class="plugin-mentions-user plugin-mentions-a" href="/user/clsa" aria-label="Profile: clsa">@<bdi>clsa</bdi></a>,</p>
<p dir="auto">If you're talking about the certificate errors under Admin &gt; HTTPS, I wouldn't worry about those. An application does not need to validate its own certificate; it's only used to encrypt/decrypt the traffic.</p>
<p dir="auto">The server transmits a copy of the certificate (without the private key), and the client validates the certificate before transmitting data.</p>
<p dir="auto">Without getting into too many technical details, the only thing that really matters is if clients can connect to the application (ProGet) using HTTPS or not. There are a lot of reasons that may prevent the application from self-validation and it's not really worth trying to fix, since it's only used on that page to help catch basic errors.</p>
<p dir="auto">Thanks,<br />
Steve</p>
]]></description><link>https://forums.inedo.com/post/20130</link><guid isPermaLink="true">https://forums.inedo.com/post/20130</guid><dc:creator><![CDATA[stevedennis]]></dc:creator><pubDate>Wed, 07 Oct 2026 17:51:31 GMT</pubDate></item><item><title><![CDATA[Reply to ProGet on Windows ignores intermediate CA certificate in PFX file on Wed, 07 Oct 2026 10:34:28 GMT]]></title><description><![CDATA[<p dir="auto">Hi Steve,</p>
<p dir="auto">thank you for your quick reply and the hint regarding registry.</p>
<p dir="auto">However i couldn't identify potentially unsuitable registry settings within reasonable time, so instead i did a counter-check by importing the very same PFX file into Windows' certificate store.</p>
<p dir="auto">I had to grant read permissions to "NETWORK SERVICE" for the imported private key, but this way the intermediate CA certificate is served to the clients properly.</p>
<p dir="auto">Interestingly when switching back to the PFX file in ProGet's config afterwards (+ service restart), clients still receive the intermediate CA certificate. Only after deleting the intermediate CA certificate from Windows' certificate store, ProGet starts complaining about "Error PartialChain: A certificate chain could not be built to a trusted root authority." (root CA certificate is available in Windows' certificate store all the time).</p>
<p dir="auto">This makes me think, that the current implementation doesn't read intermediate CA certificates from PFX files.</p>
]]></description><link>https://forums.inedo.com/post/20127</link><guid isPermaLink="true">https://forums.inedo.com/post/20127</guid><dc:creator><![CDATA[clsa]]></dc:creator><pubDate>Wed, 07 Oct 2026 10:34:28 GMT</pubDate></item><item><title><![CDATA[Reply to ProGet on Windows ignores intermediate CA certificate in PFX file on Tue, 06 Oct 2026 17:11:34 GMT]]></title><description><![CDATA[<p dir="auto">Hi <a class="plugin-mentions-user plugin-mentions-a" href="/user/clsa" aria-label="Profile: clsa">@<bdi>clsa</bdi></a> ,</p>
<p dir="auto">We're not aware of any bugs or issues; SSL and Certificate handling is all done at the Operating System (Windows) or Platform (.NET) level; we just point the system to the file. In my experience there's usually some obscure registry setting that will control stuff like this.</p>
<p dir="auto">Thanks,<br />
Steve</p>
]]></description><link>https://forums.inedo.com/post/20121</link><guid isPermaLink="true">https://forums.inedo.com/post/20121</guid><dc:creator><![CDATA[stevedennis]]></dc:creator><pubDate>Tue, 06 Oct 2026 17:11:34 GMT</pubDate></item></channel></rss>