You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Chrome根商店无法读取Windows受信任根存储CA证书问题排查求助

自有CA证书在Chrome根商店启用时的吊销验证异常问题

我们基于smallstep的step-ca搭建了自有证书颁发机构(CA),已启用CRL功能,且根证书与中间证书的公钥证书已导入Windows客户端的受信任根证书存储。

问题现象

  • 未通过Windows注册表禁用ChromeRootStoreEnabled时,Chrome访问受该CA颁发的叶子证书保护的网站,会抛出NET::ERR_CERT_UNABLE_TO_CHECK_REVOCATION错误,标记证书无效
  • 按照Chrome企业政策将ChromeRootStoreEnabled设置为1(禁用Chrome根商店)后,访问恢复正常

已执行的排查动作

  • 使用chrome://net-export工具导出了访问目标网站时的网络日志,证书数据可从日志中提取,通过crt.sh等工具分析
  • 已尝试将公钥证书分别导入计算机级和个人级的受信任根证书存储,问题未解决

疑问与官方依据

根据Chromium官方博客的说明:

The Chrome Certificate Verifier considers locally-managed certificates during the certificate verification process. This means if an enterprise distributes a root CA certificate as trusted to its users (for example, by a Windows Group Policy Object), it will be considered trusted in Chrome.

Chrome理应支持读取Windows受信任根存储中的本地管理证书,但目前推测问题原因可能为以下两者之一:

  • Chrome无法从Windows受信任根证书存储读取公钥证书
  • Chrome不认可导入的证书数据

运行环境

  • Google Chrome v111
  • Windows 10 & 11

内容的提问来源于stack exchange,提问作者Lars Bingchong

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.27 07:33:11