Wenn ich von dem Windows Server die Abfrage openssl s_client -connect domain.de:443 mache um mir die Zertifikat Chain anzeigen zu lassen, gibt es diese Auflistung:
Certificate chain
0 s:CN=``xxxxxxxxx.de
i:C=US, O=Corporation Service Company, CN=Corporation Service Company RSA DV SSL CA 2
a:PKEY: RSA, 2048 (bit); sigalg: sha256WithRSAEncryption
v:NotBefore: Jul 7 00:00:00 2026 GMT; NotAfter: Jan 21 23:59:59 2027 GMT
1 s:C=US, O=Corporation Service Company, CN=Corporation Service Company RSA DV SSL CA 2
i:C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication Root R46
a:PKEY: RSA, 3072 (bit); sigalg: sha384WithRSAEncryption
v:NotBefore: May 14 00:00:00 2025 GMT; NotAfter: May 13 23:59:59 2035 GMT
2 s:C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication Root R46
i:C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust RSA Certification Authority
a:PKEY: RSA, 4096 (bit); sigalg: sha384WithRSAEncryption
v:NotBefore: Mar 22 00:00:00 2021 GMT; NotAfter: Jan 18 23:59:59 2038 GMT
3 s:C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust RSA Certification Authority
i:C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust RSA Certification Authority
a:PKEY: RSA, 4096 (bit); sigalg: sha384WithRSAEncryption
v:NotBefore: Feb 1 00:00:00 2010 GMT; NotAfter: Jan 18 23:59:59 2038 GMT
Mit der Agent Updater Regel, habe ich schon alle Konstellationen ausprobiert, aber es klappt keine davon:
Nur Nr.2
Nur Nr.3
Beide Nr.2 und Nr.3