You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法将Comodo SSL证书添加至AWS CloudFront,证书链无效求助

Fixing Invalid Certificate Chain Error for Comodo SSL on AWS CloudFront

Let's break down the issues in your current workflow and fix them step by step:

1. Critical Mistakes in Your Current Process

You’ve got two filename mismatches that are directly causing the invalid chain error:

  • You converted cdn_guillaumemaka_com.crt (from the blog example) instead of your actual server certificate STAR_myapp_com.crt
  • You tried to use COMODORSADomainValidationSecureServerCA.pem in your chain, but you converted COMODORSAOrganizationValidationSecureServerCA.crt (your actual intermediate CA file)

We’ll also make sure we build the chain in the correct order required by CloudFront.

2. Correctly Convert All Certificates to PEM Format

First, re-convert your files using your actual filenames (adjust paths as needed):

# Create a pem directory if you haven’t already
mkdir -p ./pem

# Convert your server certificate
openssl x509 -in ./STAR_myapp_com.crt -outform pem -out ./pem/STAR_myapp_com.pem

# Convert the intermediate CA that signed your server cert
openssl x509 -in ./COMODORSAOrganizationValidationSecureServerCA.crt -outform pem -out ./pem/COMODORSAOrganizationValidationSecureServerCA.pem

# Convert the next-level intermediate CA
openssl x509 -in ./COMODORSAAddTrustCA.crt -outform pem -out ./pem/COMODORSAAddTrustCA.pem

# Convert the root CA (optional but adds full compatibility)
openssl x509 -in ./AddTrustExternalCARoot.crt -outform pem -out ./pem/AddTrustExternalCARoot.pem

# Convert your private key to unencrypted PEM format
openssl rsa -in ./private.key -outform PEM -out ./pem/private.key.pem

3. Build a Valid Certificate Chain

CloudFront requires the certificate chain to be ordered from the intermediate CA that directly signed your server certificate up to the root CA. The chain should only contain CA certificates (not your server cert):

# Start with the intermediate CA that issued your server certificate
cat ./pem/COMODORSAOrganizationValidationSecureServerCA.pem > ./pem/CAChain.pem

# Append the intermediate CA that issued the above CA
cat ./pem/COMODORSAAddTrustCA.pem >> ./pem/CAChain.pem

# Optionally append the root CA (most clients trust it by default, but include it if errors persist)
cat ./pem/AddTrustExternalCARoot.pem >> ./pem/CAChain.pem

4. Verify the Certificate Chain Before Uploading

Validate that your chain works correctly with OpenSSL:

openssl verify -CAfile ./pem/CAChain.pem ./pem/STAR_myapp_com.pem

You should see output like STAR_myapp_com.pem: OK if everything is set up correctly.

5. Upload the Certificate to IAM (us-east-1 Required!)

CloudFront only accepts certificates stored in the us-east-1 (N. Virginia) region, even if your CloudFront distribution is in another region. Use this corrected AWS CLI command:

aws iam upload-server-certificate \
    --server-certificate-name CDNServerCertificate \
    --certificate-body file://./pem/STAR_myapp_com.pem \
    --private-key file://./pem/private.key.pem \
    --certificate-chain file://./pem/CAChain.pem \
    --path /cloudfront/production/

Extra Checks to Avoid Future Issues

  • Ensure your private key has no password protection. If it does, remove it with openssl rsa -in private.key -out private.key.nopass.pem and use the nopass version.
  • Double-check all PEM files: each should start with -----BEGIN CERTIFICATE----- and end with -----END CERTIFICATE----- (or -----BEGIN RSA PRIVATE KEY----- for the key) with no extra characters or formatting errors.

内容的提问来源于stack exchange,提问作者Darshan Chaudhary

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 06:40:32