Different Intermediate Certificates on client/server question
by yvesjv from LinuxQuestions.org on (#5DRVA)
Hi all,
Hope someone can explain the impact as I know a bit but not too much about using certificates.
We use an external CA QV (I think now Digicert) to create certs and install into the web, vpn, wired/wireless dot1x servers.
QV recently revoked an ICA and provided a new intermediate which prompted a scramble toupdate the vpn concentrators, web , etc.
Some mobile phones running iOS and android suddenly stopped connecting to the wireless.
We found out they have a old profile installed which still contains the old revoked QV ICA.
We are going to update the profiles with the new ICA but I'm also trying to search/understand how the whole certificate chain works between clients and servers towards when they both match and when they do not as in our case.
Anyone can please explain, provide links?
Thanks in advance for the great assistance.


Hope someone can explain the impact as I know a bit but not too much about using certificates.
We use an external CA QV (I think now Digicert) to create certs and install into the web, vpn, wired/wireless dot1x servers.
QV recently revoked an ICA and provided a new intermediate which prompted a scramble toupdate the vpn concentrators, web , etc.
Some mobile phones running iOS and android suddenly stopped connecting to the wireless.
We found out they have a old profile installed which still contains the old revoked QV ICA.
We are going to update the profiles with the new ICA but I'm also trying to search/understand how the whole certificate chain works between clients and servers towards when they both match and when they do not as in our case.
Anyone can please explain, provide links?
Thanks in advance for the great assistance.