Four Js Development Tools Forum

Discussions by product => Genero BDL => Topic started by: Claudio B. on October 10, 2014, 04:30:06 pm



Title: err 20:unable to get local issuer certificate
Post by: Claudio B. on October 10, 2014, 04:30:06 pm
I have to connect to an endpoint with webserice: https://pteasb.actalis.it/ArubaSignService/ArubaSignService?WSDL

My fglprofile contains Calist with the root certificate provided by your webservice

security.global.ca = "CA_LIST.pem"

I keep getting the error
What's wrong?

Certificate chain
  0 s: / C = IT / O = Actalis SpA / OU = Digital Signature Services / CN = portal.actalis.it
    i: / C = IT / L = Milan / O = Actalis SpA / 03358520967 / CN = CA Actalis Authentication G2
  1 s: / C = IT / L = Milan / O = Actalis SpA / 03358520967 / CN = CA Actalis Authentication G2
    i: / C = IE / O = Baltimore / OU = CyberTrust / CN = Baltimore CyberTrust Root

in my CA_LIST.pem I have two separate certificates.


Title: Re: err 20:unable to get local issuer certificate
Post by: Claudio B. on October 10, 2014, 04:36:21 pm
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            58:9d:aa:1f:35:94:a9:39
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=IT, L=Milan, O=Actalis S.p.A./03358520967, CN=Actalis Authentication Root CA
        Validity
            Not Before: Oct 17 09:40:40 2013 GMT
            Not After : Oct 17 09:40:40 2023 GMT
        Subject: C=IT, L=Milan, O=Actalis S.p.A./03358520967, CN=Actalis Authentication CA G2
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
            RSA Public Key: (2048 bit)
                Modulus (2048 bit):
                    00:da:5d:99:3c:9b:e4:3c:34:02:9f:40:1c:5e:55:
                    90:71:15:64:06:ca:57:d5:43:b1:96:79:2b:4e:b2:
                    d7:0f:93:4c:21:17:78:b2:94:ae:0e:ba:96:73:0f:
                    3c:f3:e7:ac:e9:15:a1:84:08:83:0c:7f:58:76:0f:
                    d9:c0:3c:b3:df:20:a7:28:bf:99:52:1f:d4:f9:99:
                    d6:49:17:04:a4:17:eb:5a:2a:51:be:60:f9:62:cb:
                    9f:69:89:cc:b4:1a:93:d7:da:37:76:13:0a:b1:9b:
                    32:26:13:65:20:7f:86:47:20:26:4c:5e:37:55:c6:
                    43:6f:fd:09:16:b4:7c:5f:48:c7:89:20:be:75:23:
                    86:d7:fc:91:da:df:b9:ba:87:5a:67:90:f8:8f:16:
                    b5:45:11:d7:d4:3d:20:33:ce:25:9c:3d:67:f8:62:
                    bd:5a:23:89:11:8a:0b:b0:77:7e:57:f9:de:6d:8f:
                    a8:8a:e3:d1:9b:18:66:4a:56:55:9c:ae:9f:15:35:
                    2d:74:56:7f:d9:76:b5:bb:b8:1e:ac:58:88:00:34:
                    22:6f:59:b7:c8:a1:9d:92:de:a8:82:db:05:88:89:
                    dd:28:1f:74:ba:8a:81:c8:20:af:4d:87:7e:e6:ef:
                    28:2d:42:ae:f8:c9:ab:2b:4f:fd:e9:4a:1f:b5:57:
                    95:5f
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            Authority Information Access:
                OCSP - URI:http://portal.actalis.it/VA/AUTH-ROOT

            X509v3 Subject Key Identifier:
                DD:44:8A:40:B7:EE:F4:CB:0C:BD:D3:5D:A7:00:28:E0:F3:31:46:A9
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Authority Key Identifier:
                keyid:52:D8:88:3A:C8:9F:78:66:ED:89:F3:7B:38:70:94:C9:02:02:36:D0

            X509v3 Certificate Policies:
                Policy: X509v3 Any Policy
                  CPS: https://portal.actalis.it/Repository/Policy/SSL/CPS

            X509v3 CRL Distribution Points:
                URI:ldap://ldap.actalis.it/cn%3dActalis%20Authentication%20Root%20CA,o%3dActalis%20S.p.A.%2f03358520967,c%3dIT?certificateRevocationList;binary
                URI:http://portal.actalis.it/Repository/AUTH-ROOT/getLastCRL

            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
    Signature Algorithm: sha256WithRSAEncryption
        58:da:2d:78:ca:eb:b3:9e:0f:c6:30:c8:2c:24:ce:ad:e5:00:
        e4:00:8d:e0:91:99:a6:7a:11:44:83:3c:e7:6b:d2:25:c5:d1:
        a6:ea:14:f2:1b:d7:63:6e:2f:a5:05:c2:09:c3:58:0d:08:37:
        0d:2c:10:77:84:3a:e9:e0:d8:c5:e6:ac:5d:38:cd:7d:2e:0b:
        e7:2e:be:54:50:49:bd:0b:06:24:c0:4c:40:9d:06:dc:ef:f7:
        ee:ba:3b:6b:b9:9f:7c:8b:ab:48:79:46:ff:a2:51:22:88:2f:
        13:95:e3:bf:61:da:5d:89:75:48:a6:5b:35:b9:d1:3a:fd:16:
        ac:a5:e0:8a:dd:bf:4d:af:5e:84:ce:38:91:4d:80:13:50:42:
        c1:2d:45:26:8a:8c:56:c1:75:38:55:a0:33:8b:0e:8e:90:1f:
        cb:41:fc:08:7a:b9:a7:61:68:0d:df:8e:80:e4:8a:b1:f7:fb:
        cc:2d:14:9d:8e:f3:85:16:14:8e:78:ba:d8:0b:25:1c:ba:1d:
        9f:85:7c:b8:e5:d3:f9:68:fc:dd:93:52:7d:81:86:9b:ce:33:
        59:e8:92:27:ac:24:93:16:3b:89:4c:06:17:24:21:a3:c0:e3:
        0d:10:0f:11:31:ee:32:b0:1a:04:f5:53:81:60:87:64:30:55:
        2b:2a:91:c4:72:ca:3b:0a:e4:22:b7:04:d9:1a:d3:fe:9f:60:
        9a:4e:08:66:37:bb:63:d1:2d:96:4f:cb:6c:4a:4d:8b:54:0e:
        4f:11:9c:8f:7d:0a:b9:38:2f:28:7c:d6:cb:df:7f:17:96:7f:
        47:a8:13:37:bf:fc:da:ea:62:e6:c8:63:52:f3:16:e4:64:d7:
        35:f0:6b:4d:fe:1c:ca:08:05:9e:ea:95:4c:14:03:f9:09:42:
        fb:e9:84:78:b6:ad:dd:61:41:82:65:ff:af:1f:e9:7c:05:1b:
        12:a5:b2:98:c2:a9:db:08:87:b7:18:44:09:f4:bd:b7:2a:03:
        92:cc:70:da:35:21:00:0e:e3:60:f6:54:97:19:44:bc:a9:cb:
        e2:78:96:4d:3e:3d:f6:21:da:61:47:31:60:24:1f:55:d6:04:
        3e:14:45:97:45:53:8e:23:48:bc:c3:82:03:d8:3f:a9:df:4d:
        a1:36:5c:80:42:d4:7a:04:81:12:9a:1b:a4:29:0b:83:6b:3a:
        2b:6d:b3:c6:38:57:7f:a6:bb:ac:a9:ce:79:f7:c1:f4:5e:8d:
        39:97:3f:fc:0e:f4:84:65:4a:3b:89:20:ca:92:67:0b:02:7e:
        fa:87:e5:1c:a3:93:79:fa:0c:ec:4b:13:a0:de:e0:7e:a0:35:
        cf:32:4f:78:b8:33:92:ac
-----BEGIN CERTIFICATE-----
MIIGOzCCBCOgAwIBAgIIWJ2qHzWUqTkwDQYJKoZIhvcNAQELBQAwazELMAkGA1UE
BhMCSVQxDjAMBgNVBAcMBU1pbGFuMSMwIQYDVQQKDBpBY3RhbGlzIFMucC5BLi8w
MzM1ODUyMDk2NzEnMCUGA1UEAwweQWN0YWxpcyBBdXRoZW50aWNhdGlvbiBSb290
IENBMB4XDTEzMTAxNzA5NDA0MFoXDTIzMTAxNzA5NDA0MFowaTELMAkGA1UEBhMC
SVQxDjAMBgNVBAcMBU1pbGFuMSMwIQYDVQQKDBpBY3RhbGlzIFMucC5BLi8wMzM1
ODUyMDk2NzElMCMGA1UEAwwcQWN0YWxpcyBBdXRoZW50aWNhdGlvbiBDQSBHMjCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANpdmTyb5Dw0Ap9AHF5VkHEV
ZAbKV9VDsZZ5K06y1w+TTCEXeLKUrg66lnMPPPPnrOkVoYQIgwx/WHYP2cA8s98g
pyi/mVIf1PmZ1kkXBKQX61oqUb5g+WLLn2mJzLQak9faN3YTCrGbMiYTZSB/hkcg
JkxeN1XGQ2/9CRa0fF9Ix4kgvnUjhtf8kdrfubqHWmeQ+I8WtUUR19Q9IDPOJZw9
Z/hivVojiRGKC7B3flf53m2PqIrj0ZsYZkpWVZyunxU1LXRWf9l2tbu4HqxYiAA0
Im9Zt8ihnZLeqILbBYiJ3SgfdLqKgcggr02HfubvKC1CrvjJqytP/elKH7VXlV8C
AwEAAaOCAeMwggHfMEEGCCsGAQUFBwEBBDUwMzAxBggrBgEFBQcwAYYlaHR0cDov
L3BvcnRhbC5hY3RhbGlzLml0L1ZBL0FVVEgtUk9PVDAdBgNVHQ4EFgQU3USKQLfu
9MsMvdNdpwAo4PMxRqkwDwYDVR0TAQH/BAUwAwEB/zAfBgNVHSMEGDAWgBRS2Ig6
yJ94Zu2J83s4cJTJAgI20DBUBgNVHSAETTBLMEkGBFUdIAAwQTA/BggrBgEFBQcC
ARYzaHR0cHM6Ly9wb3J0YWwuYWN0YWxpcy5pdC9SZXBvc2l0b3J5L1BvbGljeS9T
U0wvQ1BTMIHiBgNVHR8EgdowgdcwgZSggZGggY6GgYtsZGFwOi8vbGRhcC5hY3Rh
bGlzLml0L2NuJTNkQWN0YWxpcyUyMEF1dGhlbnRpY2F0aW9uJTIwUm9vdCUyMENB
LG8lM2RBY3RhbGlzJTIwUy5wLkEuJTJmMDMzNTg1MjA5NjcsYyUzZElUP2NlcnRp
ZmljYXRlUmV2b2NhdGlvbkxpc3Q7YmluYXJ5MD6gPKA6hjhodHRwOi8vcG9ydGFs
LmFjdGFsaXMuaXQvUmVwb3NpdG9yeS9BVVRILVJPT1QvZ2V0TGFzdENSTDAOBgNV
HQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQELBQADggIBAFjaLXjK67OeD8YwyCwkzq3l
AOQAjeCRmaZ6EUSDPOdr0iXF0abqFPIb12NuL6UFwgnDWA0INw0sEHeEOung2MXm
rF04zX0uC+cuvlRQSb0LBiTATECdBtzv9+66O2u5n3yLq0h5Rv+iUSKILxOV479h
2l2JdUimWzW50Tr9Fqyl4Irdv02vXoTOOJFNgBNQQsEtRSaKjFbBdThVoDOLDo6Q
H8tB/Ah6uadhaA3fjoDkirH3+8wtFJ2O84UWFI54utgLJRy6HZ+FfLjl0/lo/N2T
Un2BhpvOM1nokiesJJMWO4lMBhckIaPA4w0QDxEx7jKwGgT1U4Fgh2QwVSsqkcRy
yjsK5CK3BNka0/6fYJpOCGY3u2PRLZZPy2xKTYtUDk8RnI99Crk4Lyh81svffxeW
f0eoEze//NrqYubIY1LzFuRk1zXwa03+HMoIBZ7qlUwUA/kJQvvphHi2rd1hQYJl
/68f6XwFGxKlspjCqdsIh7cYRAn0vbcqA5LMcNo1IQAO42D2VJcZRLypy+J4lk0+
PfYh2mFHMWAkH1XWBD4URZdFU44jSLzDggPYP6nfTaE2XIBC1HoEgRKaG6QpC4Nr
Oitts8Y4V3+mu6ypznn3wfRejTmXP/wO9IRlSjuJIMqSZwsCfvqH5Ryjk3n6DOxL
E6De4H6gNc8yT3i4M5Ks
-----END CERTIFICATE-----
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            57:0a:11:97:42:c4:e3:cc
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=IT, L=Milan, O=Actalis S.p.A./03358520967, CN=Actalis Authentication Root CA
        Validity
            Not Before: Sep 22 11:22:02 2011 GMT
            Not After : Sep 22 11:22:02 2030 GMT
        Subject: C=IT, L=Milan, O=Actalis S.p.A./03358520967, CN=Actalis Authentication Root CA
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
            RSA Public Key: (4096 bit)
                Modulus (4096 bit):
                    00:a7:c6:c4:a5:29:a4:2c:ef:e5:18:c5:b0:50:a3:
                    6f:51:3b:9f:0a:5a:c9:c2:48:38:0a:c2:1c:a0:18:
                    7f:91:b5:87:b9:40:3f:dd:1d:68:1f:08:83:d5:2d:
                    1e:88:a0:f8:8f:56:8f:6d:99:02:92:90:16:d5:5f:
                    08:6c:89:d7:e1:ac:bc:20:c2:b1:e0:83:51:8a:69:
                    4d:00:96:5a:6f:2f:c0:44:7e:a3:0e:e4:91:cd:58:
                    ee:dc:fb:c7:1e:45:47:dd:27:b9:08:01:9f:a6:21:
                    1d:f5:41:2d:2f:4c:fd:28:ad:e0:8a:ad:22:b4:56:
                    65:8e:86:54:8f:93:43:29:de:39:46:78:a3:30:23:
                    ba:cd:f0:7d:13:57:c0:5d:d2:83:6b:48:4c:c4:ab:
                    9f:80:5a:5b:3a:bd:c9:a7:22:3f:80:27:33:5b:0e:
                    b7:8a:0c:5d:07:37:08:cb:6c:d2:7a:47:22:44:35:
                    c5:cc:cc:2e:8e:dd:2a:ed:b7:7d:66:0d:5f:61:51:
                    22:55:1b:e3:46:e3:e3:3d:d0:35:62:9a:db:af:14:
                    c8:5b:a1:cc:89:1b:e1:30:26:fc:a0:9b:1f:81:a7:
                    47:1f:04:eb:a3:39:92:06:9f:99:d3:bf:d3:ea:4f:
                    50:9c:19:fe:96:87:1e:3c:65:f6:a3:18:24:83:86:
                    10:e7:54:3e:a8:3a:76:24:4f:81:21:c5:e3:0f:02:
                    f8:93:94:47:20:bb:fe:d4:0e:d3:68:b9:dd:c4:7a:
                    84:82:e3:53:54:79:dd:db:9c:d2:f2:07:9b:2e:b6:
                    bc:3e:ed:85:6d:ef:25:11:f2:97:1a:42:61:f7:4a:
                    97:e8:8b:b1:10:07:fa:65:81:b2:a2:39:cf:f7:3c:
                    ff:18:fb:c6:f1:5a:8b:59:e2:02:ac:7b:92:d0:4e:
                    14:4f:59:45:f6:0c:5e:28:5f:b0:e8:3f:45:cf:cf:
                    af:9b:6f:fb:84:d3:77:5a:95:6f:ac:94:84:9e:ee:
                    bc:c0:4a:8f:4a:93:f8:44:21:e2:31:45:61:50:4e:
                    10:d8:e3:35:7c:4c:19:b4:de:05:bf:a3:06:9f:c8:
                    b5:cd:e4:1f:d7:17:06:0d:7a:95:74:55:0d:68:1a:
                    fc:10:1b:62:64:9d:6d:e0:95:a0:c3:94:07:57:0d:
                    14:e6:bd:05:fb:b8:9f:e6:df:8b:e2:c6:e7:7e:96:
                    f6:53:c5:80:34:50:28:58:f0:12:50:71:17:30:ba:
                    e6:78:63:bc:f4:b2:ad:9b:2b:b2:fe:e1:39:8c:5e:
                    ba:0b:20:94:de:7b:83:b8:ff:e3:56:8d:b7:11:e9:
                    3b:8c:f2:b1:c1:5d:9d:a4:0b:4c:2b:d9:b2:18:f5:
                    b5:9f:4b
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier:
                52:D8:88:3A:C8:9F:78:66:ED:89:F3:7B:38:70:94:C9:02:02:36:D0
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Authority Key Identifier:
                keyid:52:D8:88:3A:C8:9F:78:66:ED:89:F3:7B:38:70:94:C9:02:02:36:D0

            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
    Signature Algorithm: sha256WithRSAEncryption
        0b:7b:72:87:c0:60:a6:49:4c:88:58:e6:1d:88:f7:14:64:48:
        a6:d8:58:0a:0e:4f:13:35:df:35:1d:d4:ed:06:31:c8:81:3e:
        6a:d5:dd:3b:1a:32:ee:90:3d:11:d2:2e:f4:8e:c3:63:2e:23:
        66:b0:67:be:6f:b6:c0:13:39:60:aa:a2:34:25:93:75:52:de:
        a7:9d:ad:0e:87:89:52:71:6a:16:3c:19:1d:83:f8:9a:29:65:
        be:f4:3f:9a:d9:f0:f3:5a:87:21:71:80:4d:cb:e0:38:9b:3f:
        bb:fa:e0:30:4d:cf:86:d3:65:10:19:18:d1:97:02:b1:2b:72:
        42:68:ac:a0:bd:4e:5a:da:18:bf:6b:98:81:d0:fd:9a:be:5e:
        15:48:cd:11:15:b9:c0:29:5c:b4:e8:88:f7:3e:36:ae:b7:62:
        fd:1e:62:de:70:78:10:1c:48:5b:da:bc:a4:38:ba:67:ed:55:
        3e:5e:57:df:d4:03:40:4c:81:a4:d2:4f:63:a7:09:42:09:14:
        fc:00:a9:c2:80:73:4f:2e:c0:40:d9:11:7b:48:ea:7a:02:c0:
        d3:eb:28:01:26:58:74:c1:c0:73:22:6d:93:95:fd:39:7d:bb:
        2a:e3:f6:82:e3:2c:97:5f:4e:1f:91:94:fa:fe:2c:a3:d8:76:
        1a:b8:4d:b2:38:4f:9b:fa:1d:48:60:79:26:e2:f3:fd:a9:d0:
        9a:e8:70:8f:49:7a:d6:e5:bd:0a:0e:db:2d:f3:8d:bf:eb:e3:
        a4:7d:cb:c7:95:71:e8:da:a3:7c:c5:c2:f8:74:92:04:1b:86:
        ac:a4:22:53:40:b6:ac:fe:4c:76:cf:fb:94:32:c0:35:9f:76:
        3f:6e:e5:90:6e:a0:a6:26:a2:b8:2c:be:d1:2b:85:fd:a7:68:
        c8:ba:01:2b:b1:6c:74:1d:b8:73:95:e7:ee:b7:c7:25:f0:00:
        4c:00:b2:7e:b6:0b:8b:1c:f3:c0:50:9e:25:b9:e0:08:de:36:
        66:ff:37:a5:d1:bb:54:64:2c:c9:27:b5:4b:92:7e:65:ff:d3:
        2d:e1:b9:4e:bc:7f:a4:41:21:90:41:77:a6:39:1f:ea:9e:e3:
        9f:d0:66:6f:05:ec:aa:76:7e:bf:6b:16:a0:eb:b5:c7:fc:92:
        54:2f:2b:11:27:25:37:78:4c:51:6a:b0:f3:cc:58:5d:14:f1:
        6a:48:15:ff:c2:07:b6:b1:8d:0f:8e:5c:50:46:b3:3d:bf:01:
        98:4f:b2:59:54:47:3e:34:7b:78:6d:56:93:2e:73:ea:66:28:
        78:cd:1d:14:bf:a0:8f:2f:2e:b8:2e:8e:f2:14:8a:cc:e9:b5:
        7c:fb:6c:9d:0c:a5:e1:96
-----BEGIN CERTIFICATE-----
MIIFuzCCA6OgAwIBAgIIVwoRl0LE48wwDQYJKoZIhvcNAQELBQAwazELMAkGA1UE
BhMCSVQxDjAMBgNVBAcMBU1pbGFuMSMwIQYDVQQKDBpBY3RhbGlzIFMucC5BLi8w
MzM1ODUyMDk2NzEnMCUGA1UEAwweQWN0YWxpcyBBdXRoZW50aWNhdGlvbiBSb290
IENBMB4XDTExMDkyMjExMjIwMloXDTMwMDkyMjExMjIwMlowazELMAkGA1UEBhMC
SVQxDjAMBgNVBAcMBU1pbGFuMSMwIQYDVQQKDBpBY3RhbGlzIFMucC5BLi8wMzM1
ODUyMDk2NzEnMCUGA1UEAwweQWN0YWxpcyBBdXRoZW50aWNhdGlvbiBSb290IENB
MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAp8bEpSmkLO/lGMWwUKNv
UTufClrJwkg4CsIcoBh/kbWHuUA/3R1oHwiD1S0eiKD4j1aPbZkCkpAW1V8IbInX
4ay8IMKx4INRimlNAJZaby/ARH6jDuSRzVju3PvHHkVH3Se5CAGfpiEd9UEtL0z9
KK3giq0itFZljoZUj5NDKd45RnijMCO6zfB9E1fAXdKDa0hMxKufgFpbOr3JpyI/
gCczWw63igxdBzcIy2zSekciRDXFzMwujt0q7bd9Zg1fYVEiVRvjRuPjPdA1Yprb
rxTIW6HMiRvhMCb8oJsfgadHHwTrozmSBp+Z07/T6k9QnBn+locePGX2oxgkg4YQ
51Q+qDp2JE+BIcXjDwL4k5RHILv+1A7TaLndxHqEguNTVHnd25zS8gebLra8Pu2F
be8lEfKXGkJh90qX6IuxEAf6ZYGyojnP9zz/GPvG8VqLWeICrHuS0E4UT1lF9gxe
KF+w6D9Fz8+vm2/7hNN3WpVvrJSEnu68wEqPSpP4RCHiMUVhUE4Q2OM1fEwZtN4F
v6MGn8i1zeQf1xcGDXqVdFUNaBr8EBtiZJ1t4JWgw5QHVw0U5r0F+7if5t+L4sbn
fpb2U8WANFAoWPASUHEXMLrmeGO89LKtmyuy/uE5jF66CyCU3nuDuP/jVo23Eek7
jPKxwV2dpAtMK9myGPW1n0sCAwEAAaNjMGEwHQYDVR0OBBYEFFLYiDrIn3hm7Ynz
ezhwlMkCAjbQMA8GA1UdEwEB/wQFMAMBAf8wHwYDVR0jBBgwFoAUUtiIOsifeGbt
ifN7OHCUyQICNtAwDgYDVR0PAQH/BAQDAgEGMA0GCSqGSIb3DQEBCwUAA4ICAQAL
e3KHwGCmSUyIWOYdiPcUZEim2FgKDk8TNd81HdTtBjHIgT5q1d07GjLukD0R0i70
jsNjLiNmsGe+b7bAEzlgqqI0JZN1Ut6nna0Oh4lScWoWPBkdg/iaKWW+9D+a2fDz
WochcYBNy+A4mz+7+uAwTc+G02UQGRjRlwKxK3JCaKygvU5a2hi/a5iB0P2avl4V
SM0RFbnAKVy06Ij3Pjaut2L9HmLecHgQHEhb2rykOLpn7VU+Xlff1ANATIGk0k9j
pwlCCRT8AKnCgHNPLsBA2RF7SOp6AsDT6ygBJlh0wcBzIm2Tlf05fbsq4/aC4yyX
X04fkZT6/iyj2HYauE2yOE+b+h1IYHkm4vP9qdCa6HCPSXrW5b0KDtst842/6+Ok
fcvHlXHo2qN8xcL4dJIEG4aspCJTQLas/kx2z/uUMsA1n3Y/buWQbqCmJqK4LL7R
K4X9p2jIugErsWx0Hbhzlefut8cl8ABMALJ+tguLHPPAUJ4lueAI3jZm/zel0btU
ZCzJJ7VLkn5l/9Mt4blOvH+kQSGQQXemOR/qnuOf0GZvBeyqdn6/axag67XH/JJU
LysRJyU3eExRarDzzFhdFPFqSBX/wge2sY0PjlxQRrM9vwGYT7JZVEc+NHt4bVaT
LnPqZih4zR0Uv6CPLy64Lo7yFIrM6bV8+2ydDKXhlg==
-----END CERTIFICATE-----
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 120021506 (0x7276202)
        Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
        Validity
            Not Before: Nov  7 20:01:35 2011 GMT
            Not After : Nov  7 20:00:27 2018 GMT
        Subject: C=IT, L=Milan, O=Actalis S.p.A./03358520967, CN=Actalis Authentication CA G2
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
            RSA Public Key: (2048 bit)
                Modulus (2048 bit):
                    00:da:5d:99:3c:9b:e4:3c:34:02:9f:40:1c:5e:55:
                    90:71:15:64:06:ca:57:d5:43:b1:96:79:2b:4e:b2:
                    d7:0f:93:4c:21:17:78:b2:94:ae:0e:ba:96:73:0f:
                    3c:f3:e7:ac:e9:15:a1:84:08:83:0c:7f:58:76:0f:
                    d9:c0:3c:b3:df:20:a7:28:bf:99:52:1f:d4:f9:99:
                    d6:49:17:04:a4:17:eb:5a:2a:51:be:60:f9:62:cb:
                    9f:69:89:cc:b4:1a:93:d7:da:37:76:13:0a:b1:9b:
                    32:26:13:65:20:7f:86:47:20:26:4c:5e:37:55:c6:
                    43:6f:fd:09:16:b4:7c:5f:48:c7:89:20:be:75:23:
                    86:d7:fc:91:da:df:b9:ba:87:5a:67:90:f8:8f:16:
                    b5:45:11:d7:d4:3d:20:33:ce:25:9c:3d:67:f8:62:
                    bd:5a:23:89:11:8a:0b:b0:77:7e:57:f9:de:6d:8f:
                    a8:8a:e3:d1:9b:18:66:4a:56:55:9c:ae:9f:15:35:
                    2d:74:56:7f:d9:76:b5:bb:b8:1e:ac:58:88:00:34:
                    22:6f:59:b7:c8:a1:9d:92:de:a8:82:db:05:88:89:
                    dd:28:1f:74:ba:8a:81:c8:20:af:4d:87:7e:e6:ef:
                    28:2d:42:ae:f8:c9:ab:2b:4f:fd:e9:4a:1f:b5:57:
                    95:5f
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Certificate Policies:
                Policy: 1.3.6.1.4.1.6334.1.0
                  CPS: http://cybertrust.omniroot.com/repository.cfm

            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier:
                keyid:E5:9D:59:30:82:47:58:CC:AC:FA:08:54:36:86:7B:3A:B5:04:4D:F0

            X509v3 CRL Distribution Points:
                URI:http://cdp1.public-trust.com/CRL/Omniroot2025.crl

            X509v3 Subject Key Identifier:
                DD:44:8A:40:B7:EE:F4:CB:0C:BD:D3:5D:A7:00:28:E0:F3:31:46:A9
    Signature Algorithm: sha1WithRSAEncryption
        9d:64:1b:a0:78:8c:e4:e6:a5:da:31:02:de:86:94:22:f9:1b:
        0c:ec:7b:ce:a5:8c:1d:48:cc:76:c7:db:9e:85:ef:a7:d7:8b:
        01:4e:f2:51:b7:50:bf:39:84:cf:33:e9:fa:b8:44:b9:f8:81:
        01:30:17:09:f0:0d:b2:f5:af:5a:2d:fd:06:97:f6:d9:fa:b6:
        5b:43:de:78:4f:c6:35:19:c6:d3:78:09:ef:79:18:d5:b6:69:
        16:75:1e:d8:fb:10:b0:28:a1:71:be:73:77:33:be:74:2e:47:
        e3:e4:2c:45:21:c7:36:c1:03:e5:6f:cf:e0:ca:d1:4e:9e:92:
        2a:3c:2a:06:78:18:9b:34:7d:b3:dc:3b:28:f5:a5:88:1f:4d:
        20:e7:89:b9:cc:e1:29:72:e9:46:a9:b8:20:c0:21:35:8b:e3:
        13:b6:36:5f:85:2d:1b:35:fe:77:9c:78:98:5f:13:d7:f5:b6:
        1d:b4:84:1e:5c:0b:d0:3c:01:b6:7c:aa:a9:11:6d:2e:b2:fd:
        c6:2e:e6:b5:f7:e7:23:fc:ab:1c:d2:82:de:1e:9c:e3:ba:0c:
        d8:c7:9d:06:4f:2e:8b:28:fb:60:ce:ed:00:d7:d9:4b:50:41:
        80:be:5b:5c:92:cc:34:4d:16:91:13:04:e1:db:c7:13:1c:31:
        16:97:b3:75
-----BEGIN CERTIFICATE-----
MIIEQzCCAyugAwIBAgIEBydiAjANBgkqhkiG9w0BAQUFADBaMQswCQYDVQQGEwJJ
RTESMBAGA1UEChMJQmFsdGltb3JlMRMwEQYDVQQLEwpDeWJlclRydXN0MSIwIAYD
VQQDExlCYWx0aW1vcmUgQ3liZXJUcnVzdCBSb290MB4XDTExMTEwNzIwMDEzNVoX
DTE4MTEwNzIwMDAyN1owaTELMAkGA1UEBhMCSVQxDjAMBgNVBAcMBU1pbGFuMSMw
IQYDVQQKDBpBY3RhbGlzIFMucC5BLi8wMzM1ODUyMDk2NzElMCMGA1UEAwwcQWN0
YWxpcyBBdXRoZW50aWNhdGlvbiBDQSBHMjCCASIwDQYJKoZIhvcNAQEBBQADggEP
ADCCAQoCggEBANpdmTyb5Dw0Ap9AHF5VkHEVZAbKV9VDsZZ5K06y1w+TTCEXeLKU
rg66lnMPPPPnrOkVoYQIgwx/WHYP2cA8s98gpyi/mVIf1PmZ1kkXBKQX61oqUb5g
+WLLn2mJzLQak9faN3YTCrGbMiYTZSB/hkcgJkxeN1XGQ2/9CRa0fF9Ix4kgvnUj
htf8kdrfubqHWmeQ+I8WtUUR19Q9IDPOJZw9Z/hivVojiRGKC7B3flf53m2PqIrj
0ZsYZkpWVZyunxU1LXRWf9l2tbu4HqxYiAA0Im9Zt8ihnZLeqILbBYiJ3SgfdLqK
gcggr02HfubvKC1CrvjJqytP/elKH7VXlV8CAwEAAaOCAQAwgf0wEgYDVR0TAQH/
BAgwBgEB/wIBADBTBgNVHSAETDBKMEgGCSsGAQQBsT4BADA7MDkGCCsGAQUFBwIB
Fi1odHRwOi8vY3liZXJ0cnVzdC5vbW5pcm9vdC5jb20vcmVwb3NpdG9yeS5jZm0w
DgYDVR0PAQH/BAQDAgEGMB8GA1UdIwQYMBaAFOWdWTCCR1jMrPoIVDaGezq1BE3w
MEIGA1UdHwQ7MDkwN6A1oDOGMWh0dHA6Ly9jZHAxLnB1YmxpYy10cnVzdC5jb20v
Q1JML09tbmlyb290MjAyNS5jcmwwHQYDVR0OBBYEFN1EikC37vTLDL3TXacAKODz
MUapMA0GCSqGSIb3DQEBBQUAA4IBAQCdZBugeIzk5qXaMQLehpQi+RsM7HvOpYwd
SMx2x9uehe+n14sBTvJRt1C/OYTPM+n6uES5+IEBMBcJ8A2y9a9aLf0Gl/bZ+rZb
Q954T8Y1GcbTeAnveRjVtmkWdR7Y+xCwKKFxvnN3M750Lkfj5CxFIcc2wQPlb8/g
ytFOnpIqPCoGeBibNH2z3Dso9aWIH00g54m5zOEpculGqbggwCE1i+MTtjZfhS0b
Nf53nHiYXxPX9bYdtIQeXAvQPAG2fKqpEW0usv3GLua19+cj/Ksc0oLeHpzjugzY
x50GTy6LKPtgzu0A19lLUEGAvltcksw0TRaREwTh28cTHDEWl7N1
-----END CERTIFICATE-----


Title: Re: err 20:unable to get local issuer certificate
Post by: Claudio B. on October 10, 2014, 04:37:15 pm
WS-DEBUG (Connecting)
Host :pteasb.actalis.it\nPort :443\nSecured :no\nVia proxy :no
WS-DEBUG END

WS-DEBUG (Security error)
Error with certificate at depth: 1
 issuer = /C=IE/O=Baltimore/OU=CyberTrust/CN=Baltimore CyberTrust Root
 subject = /C=IT/L=Milan/O=Actalis S.p.A./03358520967/CN=Actalis Authentication
CA G2
 err 20:unable to get local issuer certificate
WS-DEBUG END

WS-DEBUG (IO ERROR)
Class: TCPClientConnection::createSecureConnection()
Msg: Peer certificate is issued by a company not in our CA list
Code: 0
WS-DEBUG END


Title: Re: err 20:unable to get local issuer certificate
Post by: Sisavanh S. on October 10, 2014, 05:04:44 pm
Hi,

With Firefox browser, if you click on the lock in the address bar it will open a window with information about the page:
- select the "Security" tab
- click on "Display the certificate"
- select "Details" tab
You will see the certificates hierarchy (as shown in the attached screenshot).
You are missing 2 parents certificates:
- "Baltimore CyberTrust Root"
- "GTE CyberTrust Global Root"

For such issue, you can review FGLGWS manual:
https://4js.com/online_documentation/fjs-fgl-manual-html/?path=fjs-fgl-manual#c_gws_troubleshooting_003.html

Best regards,
Sisa.