You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows信任自签名证书但Chrome提示NET::ERR_CERT_AUTHORITY_INVALID错误的求助

Windows信任自签名证书但Chrome提示NET::ERR_CERT_AUTHORITY_INVALID错误的求助

各位大佬,我最近搭建自签名证书链时碰到了个头疼的问题:已经按流程生成了根CA、中级CA和服务器证书,还把根CA证书导入到Windows的受信任根证书存储里了,但用Chrome访问服务器时,始终弹出NET::ERR_CERT_AUTHORITY_INVALID的错误提示,Edge等其他Windows程序都能正常信任这个证书链,唯独Chrome不行,清缓存、重启浏览器都试过了还是没用,有没有朋友能帮我排查下问题出在哪?

我的证书创建流程是这样的:

  • 先生成自签名的根CA证书
  • 再用根CA签发中级CA(IA)证书
  • 最后用中级CA签发服务器证书

我用到的批处理命令如下:

@ECHO OFF
ECHO Create Root CA Private key...
openssl ecparam -name secp384r1 -genkey -out "SSL-Bundle/Root-CA.key"
ECHO Create Root CA Private key successfully!

ECHO Create Root CA CSR...
openssl req -new -sha256 -key "SSL-Bundle/Root-CA.key" -config "SSL-Bundle/config_root_ca.cnf" -out "SSL-Bundle/Root-CA.csr"
ECHO Create Root CA CSR successfully!

ECHO Create Root CA...
REM Install Root CA into Trusted Root Certification Authorities store and Third-Party Root Certification Authorities store
certutil -f -addstore AuthRoot "SSL-Bundle/Root-CA.crt"
ECHO Create Root CA successfully!

ECHO Create Intermediate CA Private key...
openssl ecparam -name secp384r1 -genkey -out "SSL-Bundle/Intermediate-CA.key"
# 后续还包含中级CA的CSR生成、根CA签发中级CA证书,以及服务器证书的创建与签发步骤

我确认根CA已经成功导入到Windows的AuthRoot(受信任的根证书颁发机构)存储里了,实在搞不懂Chrome为啥不认这个证书链,求指点!

备注:内容来源于stack exchange,提问作者Tần Quảng

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.17 08:38:18