无法将Comodo SSL证书添加至AWS CloudFront,证书链无效求助
Let's break down the issues in your current workflow and fix them step by step:
1. Critical Mistakes in Your Current Process
You’ve got two filename mismatches that are directly causing the invalid chain error:
- You converted
cdn_guillaumemaka_com.crt(from the blog example) instead of your actual server certificateSTAR_myapp_com.crt - You tried to use
COMODORSADomainValidationSecureServerCA.pemin your chain, but you convertedCOMODORSAOrganizationValidationSecureServerCA.crt(your actual intermediate CA file)
We’ll also make sure we build the chain in the correct order required by CloudFront.
2. Correctly Convert All Certificates to PEM Format
First, re-convert your files using your actual filenames (adjust paths as needed):
# Create a pem directory if you haven’t already mkdir -p ./pem # Convert your server certificate openssl x509 -in ./STAR_myapp_com.crt -outform pem -out ./pem/STAR_myapp_com.pem # Convert the intermediate CA that signed your server cert openssl x509 -in ./COMODORSAOrganizationValidationSecureServerCA.crt -outform pem -out ./pem/COMODORSAOrganizationValidationSecureServerCA.pem # Convert the next-level intermediate CA openssl x509 -in ./COMODORSAAddTrustCA.crt -outform pem -out ./pem/COMODORSAAddTrustCA.pem # Convert the root CA (optional but adds full compatibility) openssl x509 -in ./AddTrustExternalCARoot.crt -outform pem -out ./pem/AddTrustExternalCARoot.pem # Convert your private key to unencrypted PEM format openssl rsa -in ./private.key -outform PEM -out ./pem/private.key.pem
3. Build a Valid Certificate Chain
CloudFront requires the certificate chain to be ordered from the intermediate CA that directly signed your server certificate up to the root CA. The chain should only contain CA certificates (not your server cert):
# Start with the intermediate CA that issued your server certificate cat ./pem/COMODORSAOrganizationValidationSecureServerCA.pem > ./pem/CAChain.pem # Append the intermediate CA that issued the above CA cat ./pem/COMODORSAAddTrustCA.pem >> ./pem/CAChain.pem # Optionally append the root CA (most clients trust it by default, but include it if errors persist) cat ./pem/AddTrustExternalCARoot.pem >> ./pem/CAChain.pem
4. Verify the Certificate Chain Before Uploading
Validate that your chain works correctly with OpenSSL:
openssl verify -CAfile ./pem/CAChain.pem ./pem/STAR_myapp_com.pem
You should see output like STAR_myapp_com.pem: OK if everything is set up correctly.
5. Upload the Certificate to IAM (us-east-1 Required!)
CloudFront only accepts certificates stored in the us-east-1 (N. Virginia) region, even if your CloudFront distribution is in another region. Use this corrected AWS CLI command:
aws iam upload-server-certificate \ --server-certificate-name CDNServerCertificate \ --certificate-body file://./pem/STAR_myapp_com.pem \ --private-key file://./pem/private.key.pem \ --certificate-chain file://./pem/CAChain.pem \ --path /cloudfront/production/
Extra Checks to Avoid Future Issues
- Ensure your private key has no password protection. If it does, remove it with
openssl rsa -in private.key -out private.key.nopass.pemand use the nopass version. - Double-check all PEM files: each should start with
-----BEGIN CERTIFICATE-----and end with-----END CERTIFICATE-----(or-----BEGIN RSA PRIVATE KEY-----for the key) with no extra characters or formatting errors.
内容的提问来源于stack exchange,提问作者Darshan Chaudhary

